Host-Based Intrusion Detection System (HIDS).
#project Overview This is a lightweight, signature-based Intrusion Detection System (IDS) built entirely in Python.
It acts as a security camera for your computer's internal logs. It monitors system files in real-time, analyzes traffic patterns using Regular Expressions (Regex), and triggers alerts when it detects malicious activity like brute-force attacks or suspicious command execution.
Key Features:
Real-time Monitoring: Continuously watches log files.
Brute Force Detection: Tracks failed login attempts.
Signature Detection: Identifies known malicious commands (e.g., rm -rf).
Simulation Mode: Includes a built-in attack generator.
- File Stream Handling: Uses pointer-based seeking for efficiency.
- Regex Parsing: Extracts IP addresses and users from logs.
- State Management: Uses a sliding time window for tracking failures.
#How to Run
You need Python 3 installed.
To see the detection in action safely:
python py_hids.py --simulate
To monitor real Linux logs:
- Open py_hids.py
- Change LOG_FILE_TO_WATCH to /var/log/auth.log
- Run with sudo: sudo python py_hids.py
#Disclaimer: This tool is for educational purposes.