The Application of Cowrie Honeypot to Analyze Attacks on SSH and Telnet Protocols

Muhammad Naufal Azzahri, Restu Alsyafiq Selian, Sayed Muchallil, Yudha Nurdin, Razief Perucha Fauzie Afidh, Khairul Umam, Rahmad Dawood · 2024

The advancement of Internet technologies has led to growing security threats due to vulnerabilities in information systems. Various security solutions have been developed to counter these threats, but they often struggle to keep pace with increasingly sophisticated attack strategies. This study examines the effectiveness of a Cowrie honeypot system for analyzing SSH protocol attacks. By deploying Cowrie on a Raspberry Pi over 30 days, detailed data on attacker behavior was gathered. Key findings reveal the predominance of SSH over Telnet attacks, frequent targeting of weak passwords, and a geographic concentration of attacks from China, India, and Australia. This study underscores the need for robust password policies and user education to reduce vulnerabilities. Cowrie proved valuable in capturing comprehensive logs and providing critical insights into attacker strategies, highlighting the importance of incorporating honeypots into cybersecurity infrastructure.

Read the paper · More papers on PaperTik