Skip to content

About

**[ES]** Analizador de logs web (IDS) e IPS en Python con inspección de estado temporal para mitigar Fuerza Bruta y Escaneo de Directorios. **[EN]** Python-based Stateful Log Analyzer & IPS for real-time behavioral detection and automated Firewall mitigation of Brute Force and Directory Scanning.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

1 Commit

Folders and files

Repository files navigation

Log Analyzer & Automated Mitigation IPS 🛡️

[ES] Un analizador correlacional de logs web (IDS) y sistema de prevención de intrusos (IPS) desarrollado en Python para la detección y mitigación activa de ataques de Fuerza Bruta y Escaneo de Directorios basados en telemetría temporal.

[EN] A Python-based log analysis engine (IDS) and Intrusion Prevention System (IPS) designed for behavioral and time-driven detection and active mitigation of Brute Force and Directory Scanning attacks.


🇪🇸 Versión en Español

Descripción

Este proyecto simula las funciones principales de un analista de SOC y un sistema IPS en un entorno corporativo. El script analiza logs web crudos (formato Nginx/Apache), extrae telemetría crítica mediante Expresiones Regulares (Regex) y aplica reglas de correlación avanzadas con inspección de estado (Stateful) para detectar anomalías de comportamiento en ventanas de tiempo específicas.

Características Técnicas

  • Análisis Correlacional Temporal: Diferencia atacantes automatizados de humanos despistados calculando el delta de tiempo (Delta t) entre eventos.
  • Mitigación Activa en Caliente (IPS): Modifica las reglas de un "Firewall" local simulado bloqueando la IP maliciosa en el milisegundo exacto en el que cruza el umbral de riesgo.
  • Optimización de Memoria: Utiliza estructuras defaultdict para procesar archivos de log masivos con un impacto mínimo en la CPU.

Cómo Ejecutarlo

  1. Asegúrate de tener los archivos access.log, analyzer_v3.py y .gitignore en la misma carpeta.
  2. Ejecuta el script desde tu terminal: python analyzer_v3.py
  3. El script limpiará el historial previo, analizará el log y generará el archivo firewall_blacklist.txt con las IPs neutralizadas.

🇬🇧 English Version

Description

This project replicates the core operations of a SOC Analyst tool and an IPS engine within a corporate infrastructure. The script parses raw web server logs (Nginx/Apache format), extracts critical security telemetry using Regular Expressions (Regex), and implements stateful correlation rules to catch behavioral anomalies within distinct time windows.

Technical Highlights

  • Time-Driven Correlation Engine: Distinguishes automated bots from benign human errors by calculating the exact time delta (Delta t) between malicious requests.
  • Inline Active Mitigation (IPS): Updates a simulated network Firewall architecture by blacklisting the threat actor's IP the exact millisecond it violates the risk thresholds.
  • Performance Optimization: Leverages defaultdict structures to stream and parse massive log payloads with minimum CPU overhead.

How to Run

  1. Verify that access.log, analyzer_v3.py, and .gitignore are located in the same root directory.
  2. Fire up the script from your terminal: python analyzer_v3.py
  3. The engine will clear previous baselines, evaluate the telemetry, and output the isolated attacker targets into firewall_blacklist.txt.

About

**[ES]** Analizador de logs web (IDS) e IPS en Python con inspección de estado temporal para mitigar Fuerza Bruta y Escaneo de Directorios. **[EN]** Python-based Stateful Log Analyzer & IPS for real-time behavioral detection and automated Firewall mitigation of Brute Force and Directory Scanning.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages