This thesis presents the practical implementation of a honeypot for monitoring and analyzing cyberattacks. Based on passive traffic capture, the most frequently scanned ports were identified and the main sources of traffic were analyzed. Using this information, a medium-interaction honeypot based on the Cowrie project was deployed and customized to provide a realistic environment. The honeypot was integrated with the Splunk system, enabling centralized log collection and data visualization of attacker interactions.
The analysis of interactions and uploaded malware revealed that attackers still commonly rely on methods, such as automated exploitation of outdated or misconfigured services. Nevertheless, the honeypot provided valuable insights into their behavior and confirmed its usefulness as both a research and security tool.
|