4th task
هذا الالتزام موجود في:
104
miniSIEM/siem.py
Normal file
104
miniSIEM/siem.py
Normal file
@@ -0,0 +1,104 @@
|
||||
import re
|
||||
import json
|
||||
from datetime import datetime
|
||||
|
||||
|
||||
LOG_FILES = [
|
||||
"logs/auth.log",
|
||||
"logs/nginx.log",
|
||||
"logs/app.log"
|
||||
]
|
||||
|
||||
|
||||
alerts = []
|
||||
|
||||
|
||||
def create_alert(ip, attack, severity):
|
||||
|
||||
alert = {
|
||||
"time": str(datetime.now()),
|
||||
"ip": ip,
|
||||
"attack": attack,
|
||||
"severity": severity
|
||||
}
|
||||
|
||||
alerts.append(alert)
|
||||
|
||||
|
||||
|
||||
def analyze_auth(line):
|
||||
|
||||
pattern = r"Failed password.*from ([0-9.]+)"
|
||||
|
||||
result = re.search(pattern,line)
|
||||
|
||||
if result:
|
||||
ip = result.group(1)
|
||||
|
||||
create_alert(
|
||||
ip,
|
||||
"Brute Force Login",
|
||||
"HIGH"
|
||||
)
|
||||
|
||||
|
||||
|
||||
def analyze_web(line):
|
||||
|
||||
if "admin" in line or "sql" in line.lower():
|
||||
|
||||
ip = line.split()[0]
|
||||
|
||||
create_alert(
|
||||
ip,
|
||||
"Web Attack Attempt",
|
||||
"MEDIUM"
|
||||
)
|
||||
|
||||
|
||||
|
||||
def analyze_app(line):
|
||||
|
||||
if "ERROR" in line:
|
||||
|
||||
create_alert(
|
||||
"LOCAL",
|
||||
"Application Error",
|
||||
"LOW"
|
||||
)
|
||||
|
||||
|
||||
|
||||
def collect_logs():
|
||||
|
||||
for file in LOG_FILES:
|
||||
|
||||
with open(file) as f:
|
||||
|
||||
for line in f:
|
||||
|
||||
if "auth" in file:
|
||||
analyze_auth(line)
|
||||
|
||||
elif "nginx" in file:
|
||||
analyze_web(line)
|
||||
|
||||
else:
|
||||
analyze_app(line)
|
||||
|
||||
|
||||
|
||||
collect_logs()
|
||||
|
||||
|
||||
with open("alerts.json","w") as f:
|
||||
|
||||
json.dump(
|
||||
alerts,
|
||||
f,
|
||||
indent=4
|
||||
)
|
||||
|
||||
|
||||
print("SIEM Scan Completed")
|
||||
print(len(alerts),"alerts found")
|
||||
المرجع في مشكلة جديدة
حظر مستخدم