Unveiling Hidden Patterns in T-Pot Honeypot Logs: A Latent Topic Analysis
Cagri Burak Aslan, Eftun Türkşanlı, R. Emre Erkan, Mustafa Serkan Öztürk, Cüneyt Akdeniz · 2024
This paper uses latent topic analysis in T-Pot honey-pot logs to uncover hidden cyberattack patterns. By meticulously analyzing the data, we identified specific attack types targeting various honeypots, such as spam/phishing on Mailoney and malware execution on Android systems. Our findings advocate for organizing identified attack terms into n-grams for stronger cybersecurity measures. Geographical analysis highlighted distinct attack patterns across countries. Russia and the Netherlands showed spam/phishing tendencies, Romania exhibited malicious downloads and execution-oriented attacks, and Germany indicated mobile-centric threats. Additionally, SSH attacks originated pre-dominantly from Asian countries such as Japan, China, India, and Singapore. Examining IP addresses hinted at potential correlations among attackers, suggesting shared entities behind certain attacks, valuable for comprehensive investigations. In conclusion, leveraging LDA on honeypot logs provided nuanced insights into various attack types, helping to identify phishing, malware, and execution-based threats. These findings offer a more targeted approach for analysts, eliminating the need for extensive manual data sifting and improving threat detection and cybersecurity strategies.