[ES] Un analizador correlacional de logs web (IDS) y sistema de prevención de intrusos (IPS) desarrollado en Python para la detección y mitigación activa de ataques de Fuerza Bruta y Escaneo de Directorios basados en telemetría temporal.
[EN] A Python-based log analysis engine (IDS) and Intrusion Prevention System (IPS) designed for behavioral and time-driven detection and active mitigation of Brute Force and Directory Scanning attacks.
Este proyecto simula las funciones principales de un analista de SOC y un sistema IPS en un entorno corporativo. El script analiza logs web crudos (formato Nginx/Apache), extrae telemetría crítica mediante Expresiones Regulares (Regex) y aplica reglas de correlación avanzadas con inspección de estado (Stateful) para detectar anomalías de comportamiento en ventanas de tiempo específicas.
- Análisis Correlacional Temporal: Diferencia atacantes automatizados de humanos despistados calculando el delta de tiempo (Delta t) entre eventos.
- Mitigación Activa en Caliente (IPS): Modifica las reglas de un "Firewall" local simulado bloqueando la IP maliciosa en el milisegundo exacto en el que cruza el umbral de riesgo.
- Optimización de Memoria: Utiliza estructuras
defaultdictpara procesar archivos de log masivos con un impacto mínimo en la CPU.
- Asegúrate de tener los archivos
access.log,analyzer_v3.pyy.gitignoreen la misma carpeta. - Ejecuta el script desde tu terminal: python analyzer_v3.py
- El script limpiará el historial previo, analizará el log y generará el archivo
firewall_blacklist.txtcon las IPs neutralizadas.
This project replicates the core operations of a SOC Analyst tool and an IPS engine within a corporate infrastructure. The script parses raw web server logs (Nginx/Apache format), extracts critical security telemetry using Regular Expressions (Regex), and implements stateful correlation rules to catch behavioral anomalies within distinct time windows.
- Time-Driven Correlation Engine: Distinguishes automated bots from benign human errors by calculating the exact time delta (Delta t) between malicious requests.
- Inline Active Mitigation (IPS): Updates a simulated network Firewall architecture by blacklisting the threat actor's IP the exact millisecond it violates the risk thresholds.
- Performance Optimization: Leverages
defaultdictstructures to stream and parse massive log payloads with minimum CPU overhead.
- Verify that
access.log,analyzer_v3.py, and.gitignoreare located in the same root directory. - Fire up the script from your terminal: python analyzer_v3.py
- The engine will clear previous baselines, evaluate the telemetry, and output the isolated attacker targets into
firewall_blacklist.txt.