Skip to content

About

Python tool that parses SSH auth logs and flags brute-force source IPs by failed-attempt threshold.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

8 Commits

Folders and files

Repository files navigation

SSH-Log-Analyzer

A Python tool which parses SSH authentication logs, counts the log attempts, correctly formats the results, prints and provides a warning of multiple failed login attempts. It also contains a per-IP tally which has a threshold set at 5 or more failed login attempts. Meant to be used as a simulation for creating a script to notify of brute-force attacks and also parsing through logs.

Purpose & Goal

The primary purpose of this project was two separate goals:

  1. Create a project which would give me an introduction to critical tools within Python
  2. Build something which can give me a starting place for any type of log parsing/log analysis.

Tools learned

This was one of the earlier projects within my Python learning journey which took a step above basic/simple functions (calculator, timer, number guesser, etc.). This was an introduction to .split(), indexing and dictionaries all of which are demonstrated within the project as core components.

Usage

Requires Python 3.6+ (uses f-strings). No external dependencies. Place the log file to be analyzed in the same directory as logchecker.py, named sample_auth.log, then run:

py logchecker.py

Any source IP with 5 or more failed password attempts prints a [WARNING] line to the terminal.

Sample Output

The results are displayed clearly and directly showing source IP addresses which have 5 failed attempts or more. Both the attacking IP in addition to the specific number of failed attempts are displayed with a [WARNING] message. 198.51.100.7 appears in the sample log with 3 failed attempts and is correctly excluded, along with successful logins and [preauth] lines. Sample output

Known limitations

  • Input filename is hardcoded as sample_auth.log; no command-line argument
  • No error handling - a missing file raises FileNotFoundError and exits
  • Threshold is hardcoded at 5 and not configurable
  • Parsing assumes standard OpenSSH syntax. A line containing "Failed password" and "from " but no " port" would produce a malformed key rather than being skipped
  • Only detects "Failed password" events. Other authentication failure types (publickey failures, "Invalid user" preauth lines) are not counted

Note about sample IPs provided

All of the IPs provided in the sample_auth.log come from RFC 5737 documentation ranges. The sample_auth.log included within the project is actually directly generated by a script from the AWS Serverless log parser project which can be found here: Failed-Login_Parser

From script to serverless

This project proved to be the catalyst for what eventually became my AWS Serverless log parser. I realized that through the use of AWS services such as S3, DynamoDB and Lambda I could simulate logs being input into an S3 bucket and displayed as attacking IPs, mimicking an environment and situation which I would encounter as a SOC Analyst.

About

Python tool that parses SSH auth logs and flags brute-force source IPs by failed-attempt threshold.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages