Skip to main content

Securing Network using Honeypot & Detecting Malicious IP Addresses

Page 1

International Research Journal of Engineering and Technology (IRJET)

e-ISSN: 2395-0056

Volume: 12 Issue: 03 | Mar 2025

p-ISSN: 2395-0072

www.irjet.net

Securing Network using Honeypot & Detecting Malicious IP Addresses Aakash Gojare1, Prof. Rajesh Bansode2 1Student, Thakur College of Engineering & Technology, Maharashtra, India

2Professor, Thakur College of Engineering & Technology, Maharashtra, India

---------------------------------------------------------------------***---------------------------------------------------------------------

Abstract - In today's digital landscape, securing networks

challenges by integrating advanced network monitoring and threat prevention mechanisms. By leveraging honeypot intelligence from the honeydb.io API, the application identifies malicious IP addresses and prevents potential attacks. The inclusion of real-time network traffic analysis through the Scapy library ensures early detection of abnormal activity, which is indicative of malicious behavior. Malicious IPs are dynamically blocked using Windows netsh commands, minimizing the attack’s impact and securing the network.

against cyber threats is of paramount importance. The project titled “Securing Network Using Honeypot and Detecting Malicious IP Addresses” presents a comprehensive solution to network security challenges. This Flask-based application integrates multiple features to ensure real-time monitoring, threat detection, and response, making it an essential tool for modern cybersecurity. The application incorporates functionality to retrieve the server’s local IP address, resolve domain names to their corresponding IPs, and fetch geolocation details of IP addresses. By integrating with the honeydb.io API, it leverages honeypot intelligence to check whether a given IP is flagged as malicious. The Scapy library is employed for monitoring network traffic and detecting suspicious activity based on configurable parameters such as packet thresholds. Upon identifying malicious IPs, they are dynamically blocked using Windows netsh commands, and administrators receive realtime email alerts via the yagmail library.

The project’s user-friendly design empowers administrators to customize monitoring parameters and receive timely alerts through email notifications. Static HTML interfaces provide an intuitive and lightweight user experience, making the tool accessible for users with varying levels of technical expertise. Key technologies such as Flask for backend development, Render for deployment, and Anaconda for development environment management further enhance the project’s reliability and scalability.

Designed for ease of use, the application allows users to define monitoring parameters, block durations, and trusted IPs through a simple interface. Key technologies utilized include Flask for backend development, Scapy for traffic analysis, yagmail for email notifications, and netsh for IP blocking. Hosted on GitHub and Render, and developed using Anaconda, the project addresses both current and emerging cybersecurity challenges, offering a robust framework for securing networks.

Through its proactive and multifaceted approach, this project offers a significant advancement in network security. It addresses the limitations of traditional methods, ensuring network integrity and reducing the risk of cyberattacks. The integration of honeypot intelligence and malicious IP detection sets a new standard in cybersecurity, making this project a vital resource for organizations aiming to safeguard their digital assets.

Key Words: Honeypot, Cybersecurity, Flask Application, Malicious IP Detection, Network Security, Real-time Monitoring, Threat.

2. RELATED WORK M. Kharrazi et al., "A Survey of Honeypot Techniques in Cybersecurity,"[1] This paper provides a comprehensive overview of honeypot techniques, including low-interaction, high-interaction, and hybrid honeypots. It highlights their differences in complexity, interaction levels, and use cases. Advantages, such as cost-effectiveness and detailed threat analysis, and limitations, including resource demands and detection risks, are discussed. The authors emphasize selecting honeypot types based on organizational security needs.

1. INTRODUCTION The exponential growth of digital technologies has significantly increased the complexity and scale of network infrastructures. With this growth comes a surge in cyber threats, making network security a top priority for organizations worldwide. Cyberattacks such as malicious IP activities pose severe risks, ranging from data breaches to operational disruptions. Traditional security measures often fall short in providing real-time detection and mitigation of such threats, necessitating innovative and comprehensive solutions.

H. Haslum and T. Fray, "The Use of Honeypots for Intrusion Detection in Industrial Control Systems,"[2] This study examines honeypot deployment in Industrial Control Systems (ICS), addressing challenges such as mimicking ICS protocols and ensuring minimal disruption. Case studies demonstrate honeypots' effectiveness in detecting malware and

This project, “Securing Network Using Honeypot and Detecting Malicious IP Addresses,” addresses these

© 2025, IRJET

|

Impact Factor value: 8.315

|

ISO 9001:2008 Certified Journal

|

Page 1123


Turn static files into dynamic content formats.

Create a flipbook
Securing Network using Honeypot & Detecting Malicious IP Addresses by IRJET Journal - Issuu