Back to Projects

Cyber Threat Intelligence Platform

CybersecurityAWSPythonBashSquidThreat Intelligence

Advanced honeypot system for monitoring and analyzing malicious web traffic patterns.

2015
Completed
1.5M+
Requests Logged
85%
Malicious Traffic
50+
Countries Tracked

The Challenge

Understanding malicious web traffic patterns is crucial for cybersecurity, but identifying threats in legitimate traffic is difficult. Existing security systems have limitations in detecting emerging web attacks.

Key Constraints

  • Gathered real-world data on how proxies are exploited for attacks
  • Provided insights for improving network defense strategies
  • Demonstrated low-cost cloud-based honeypots for security research

Our Solution

I deployed a virtual HTTP open proxy honeypot on AWS EC2 using Squid Proxy to attract and study malicious traffic. The system logged all activities, allowing deep analysis of attacker behaviors, geolocation of threats, and identification of emerging attack patterns.

Innovative Approaches

  • AWS EC2
  • Squid Proxy
  • Python
  • Bash

Technologies Used

AWS EC2

Squid Proxy

Python

Bash

ELK Stack

GeoIP

Key Results

Performance Metrics

Requests Logged1.5M+
Malicious Traffic85%
Countries Tracked50+

Project Impact

Gathered real-world data on how proxies are exploited for attacks

Provided insights for improving network defense strategies

Demonstrated low-cost cloud-based honeypots for security research

Tech
Code