Attacker IP Prioritization (AIP) Tool

Python CI TestsCodeQLDocker Hub CIDocker GHCR CI

Docker PullsGitHub issuesGitHub issues-closedGitHub open-pull-requestsGitHub pull-requests closed

The Attacker IP Prioritization (AIP) is a tool to generate efficient and economic IP blocklists based on network traffic captured from honeypot networks.

With the advent of 5G, IoT devices are directly connected often without firewall protection. Therefore we need blocklists that are small, efficient and economic. The AIP structure is shown below.

Description of the AIP pipeline

AIP Models

Each AIP model generates its own blocklist based on a specific criteria. The main models are:

  1. Prioritize New (PN)
    • Focuses on IPs that are new or have not been seen frequently in previous data.
    • Useful to identify emerging attackers that are starting to target a network.
  2. Prioritize Consistent (PC)
    • Focuses on IPs that have consistently attacked over time in previous data.
    • Useful to identify persistent attackers that continuously target a network.
  3. Alpha
    • Provides a baseline identifying all attackers seen in the last 24 hours.
    • Useful to compare the effectiveness of other models.
  4. Alpha7
    • Provides a baseline identifying all attackers seen in the last 7 days.
    • Useful to further compare the effectiveness of other models.
  5. Random Forest
    • Focuses on IPs that are more likely to attack in the future.
    • A more experimental approach to increase blocklist efficiency.

AIP Docker

The best way to run AIP right now is using Docker.

Usage

AIP will automatically attempt to run all the models using the available data. Assuming the Zeek data is located in its usual location:

:~$ cd AIP
:~$ docker run --rm -v /opt/zeek/logs/:/home/aip/AIP/data/raw:ro -v ${PWD}/data/:/home/aip/AIP/data/:rw --name aip stratosphereips/aip:latest bin/aip

To run AIP for a specific day:

:~$ cd AIP
:~$ docker run --rm -v /opt/zeek/logs/:/home/aip/AIP/data/raw:ro -v ${PWD}/data/:/home/aip/AIP/data/:rw --name aip stratosphereips/aip:latest bin/aip YYYY-MM-DD

License

The Stratosphere AIP tool is licensed under GNU General Public License v3.0.

About

This tool was developed at the Stratosphere Laboratory at the Czech Technical University in Prague. This is part of the Stratosphere blocklist generation project.

This tool was originally born from the bachelor thesis of Thomas O'Hara, The Attacker IP Prioritizer: An IoT Optimized Blacklisting Algorithm (2021).

About

The Attacker IP Prioritizer(AIP) dynamically generates resource-friendly IPv4 blocklists from Zeek network flows.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

32 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Attacker IP Prioritization (AIP) Tool

Python CI TestsCodeQLDocker Hub CIDocker GHCR CI

Docker PullsGitHub issuesGitHub issues-closedGitHub open-pull-requestsGitHub pull-requests closed

The Attacker IP Prioritization (AIP) is a tool to generate efficient and economic IP blocklists based on network traffic captured from honeypot networks.

With the advent of 5G, IoT devices are directly connected often without firewall protection. Therefore we need blocklists that are small, efficient and economic. The AIP structure is shown below.

Description of the AIP pipeline

AIP Models

Each AIP model generates its own blocklist based on a specific criteria. The main models are:

  1. Prioritize New (PN)
    • Focuses on IPs that are new or have not been seen frequently in previous data.
    • Useful to identify emerging attackers that are starting to target a network.
  2. Prioritize Consistent (PC)
    • Focuses on IPs that have consistently attacked over time in previous data.
    • Useful to identify persistent attackers that continuously target a network.
  3. Alpha
    • Provides a baseline identifying all attackers seen in the last 24 hours.
    • Useful to compare the effectiveness of other models.
  4. Alpha7
    • Provides a baseline identifying all attackers seen in the last 7 days.
    • Useful to further compare the effectiveness of other models.
  5. Random Forest
    • Focuses on IPs that are more likely to attack in the future.
    • A more experimental approach to increase blocklist efficiency.

AIP Docker

The best way to run AIP right now is using Docker.

Usage

AIP will automatically attempt to run all the models using the available data. Assuming the Zeek data is located in its usual location:

:~$ cd AIP
:~$ docker run --rm -v /opt/zeek/logs/:/home/aip/AIP/data/raw:ro -v ${PWD}/data/:/home/aip/AIP/data/:rw --name aip stratosphereips/aip:latest bin/aip

To run AIP for a specific day:

:~$ cd AIP
:~$ docker run --rm -v /opt/zeek/logs/:/home/aip/AIP/data/raw:ro -v ${PWD}/data/:/home/aip/AIP/data/:rw --name aip stratosphereips/aip:latest bin/aip YYYY-MM-DD

License

The Stratosphere AIP tool is licensed under GNU General Public License v3.0.

About

This tool was developed at the Stratosphere Laboratory at the Czech Technical University in Prague. This is part of the Stratosphere blocklist generation project.

This tool was originally born from the bachelor thesis of Thomas O'Hara, The Attacker IP Prioritizer: An IoT Optimized Blacklisting Algorithm (2021).

About

The Attacker IP Prioritizer(AIP) dynamically generates resource-friendly IPv4 blocklists from Zeek network flows.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

32 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Attacker IP Prioritization (AIP) Tool

Python CI TestsCodeQLDocker Hub CIDocker GHCR CI

Docker PullsGitHub issuesGitHub issues-closedGitHub open-pull-requestsGitHub pull-requests closed

The Attacker IP Prioritization (AIP) is a tool to generate efficient and economic IP blocklists based on network traffic captured from honeypot networks.

With the advent of 5G, IoT devices are directly connected often without firewall protection. Therefore we need blocklists that are small, efficient and economic. The AIP structure is shown below.

Description of the AIP pipeline

AIP Models

Each AIP model generates its own blocklist based on a specific criteria. The main models are:

  1. Prioritize New (PN)
    • Focuses on IPs that are new or have not been seen frequently in previous data.
    • Useful to identify emerging attackers that are starting to target a network.
  2. Prioritize Consistent (PC)
    • Focuses on IPs that have consistently attacked over time in previous data.
    • Useful to identify persistent attackers that continuously target a network.
  3. Alpha
    • Provides a baseline identifying all attackers seen in the last 24 hours.
    • Useful to compare the effectiveness of other models.
  4. Alpha7
    • Provides a baseline identifying all attackers seen in the last 7 days.
    • Useful to further compare the effectiveness of other models.
  5. Random Forest
    • Focuses on IPs that are more likely to attack in the future.
    • A more experimental approach to increase blocklist efficiency.

AIP Docker

The best way to run AIP right now is using Docker.

Usage

AIP will automatically attempt to run all the models using the available data. Assuming the Zeek data is located in its usual location:

:~$ cd AIP
:~$ docker run --rm -v /opt/zeek/logs/:/home/aip/AIP/data/raw:ro -v ${PWD}/data/:/home/aip/AIP/data/:rw --name aip stratosphereips/aip:latest bin/aip

To run AIP for a specific day:

:~$ cd AIP
:~$ docker run --rm -v /opt/zeek/logs/:/home/aip/AIP/data/raw:ro -v ${PWD}/data/:/home/aip/AIP/data/:rw --name aip stratosphereips/aip:latest bin/aip YYYY-MM-DD

License

The Stratosphere AIP tool is licensed under GNU General Public License v3.0.

About

This tool was developed at the Stratosphere Laboratory at the Czech Technical University in Prague. This is part of the Stratosphere blocklist generation project.

This tool was originally born from the bachelor thesis of Thomas O'Hara, The Attacker IP Prioritizer: An IoT Optimized Blacklisting Algorithm (2021).

About

The Attacker IP Prioritizer(AIP) dynamically generates resource-friendly IPv4 blocklists from Zeek network flows.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

32 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Attacker IP Prioritization (AIP) Tool

Python CI TestsCodeQLDocker Hub CIDocker GHCR CI

Docker PullsGitHub issuesGitHub issues-closedGitHub open-pull-requestsGitHub pull-requests closed

The Attacker IP Prioritization (AIP) is a tool to generate efficient and economic IP blocklists based on network traffic captured from honeypot networks.

With the advent of 5G, IoT devices are directly connected often without firewall protection. Therefore we need blocklists that are small, efficient and economic. The AIP structure is shown below.

Description of the AIP pipeline

AIP Models

Each AIP model generates its own blocklist based on a specific criteria. The main models are:

  1. Prioritize New (PN)
    • Focuses on IPs that are new or have not been seen frequently in previous data.
    • Useful to identify emerging attackers that are starting to target a network.
  2. Prioritize Consistent (PC)
    • Focuses on IPs that have consistently attacked over time in previous data.
    • Useful to identify persistent attackers that continuously target a network.
  3. Alpha
    • Provides a baseline identifying all attackers seen in the last 24 hours.
    • Useful to compare the effectiveness of other models.
  4. Alpha7
    • Provides a baseline identifying all attackers seen in the last 7 days.
    • Useful to further compare the effectiveness of other models.
  5. Random Forest
    • Focuses on IPs that are more likely to attack in the future.
    • A more experimental approach to increase blocklist efficiency.

AIP Docker

The best way to run AIP right now is using Docker.

Usage

AIP will automatically attempt to run all the models using the available data. Assuming the Zeek data is located in its usual location:

:~$ cd AIP
:~$ docker run --rm -v /opt/zeek/logs/:/home/aip/AIP/data/raw:ro -v ${PWD}/data/:/home/aip/AIP/data/:rw --name aip stratosphereips/aip:latest bin/aip

To run AIP for a specific day:

:~$ cd AIP
:~$ docker run --rm -v /opt/zeek/logs/:/home/aip/AIP/data/raw:ro -v ${PWD}/data/:/home/aip/AIP/data/:rw --name aip stratosphereips/aip:latest bin/aip YYYY-MM-DD

License

The Stratosphere AIP tool is licensed under GNU General Public License v3.0.

About

This tool was developed at the Stratosphere Laboratory at the Czech Technical University in Prague. This is part of the Stratosphere blocklist generation project.

This tool was originally born from the bachelor thesis of Thomas O'Hara, The Attacker IP Prioritizer: An IoT Optimized Blacklisting Algorithm (2021).

About

The Attacker IP Prioritizer(AIP) dynamically generates resource-friendly IPv4 blocklists from Zeek network flows.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

32 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Attacker IP Prioritization (AIP) Tool

Python CI TestsCodeQLDocker Hub CIDocker GHCR CI

Docker PullsGitHub issuesGitHub issues-closedGitHub open-pull-requestsGitHub pull-requests closed

The Attacker IP Prioritization (AIP) is a tool to generate efficient and economic IP blocklists based on network traffic captured from honeypot networks.

With the advent of 5G, IoT devices are directly connected often without firewall protection. Therefore we need blocklists that are small, efficient and economic. The AIP structure is shown below.

Description of the AIP pipeline

AIP Models

Each AIP model generates its own blocklist based on a specific criteria. The main models are:

  1. Prioritize New (PN)
    • Focuses on IPs that are new or have not been seen frequently in previous data.
    • Useful to identify emerging attackers that are starting to target a network.
  2. Prioritize Consistent (PC)
    • Focuses on IPs that have consistently attacked over time in previous data.
    • Useful to identify persistent attackers that continuously target a network.
  3. Alpha
    • Provides a baseline identifying all attackers seen in the last 24 hours.
    • Useful to compare the effectiveness of other models.
  4. Alpha7
    • Provides a baseline identifying all attackers seen in the last 7 days.
    • Useful to further compare the effectiveness of other models.
  5. Random Forest
    • Focuses on IPs that are more likely to attack in the future.
    • A more experimental approach to increase blocklist efficiency.

AIP Docker

The best way to run AIP right now is using Docker.

Usage

AIP will automatically attempt to run all the models using the available data. Assuming the Zeek data is located in its usual location:

:~$ cd AIP
:~$ docker run --rm -v /opt/zeek/logs/:/home/aip/AIP/data/raw:ro -v ${PWD}/data/:/home/aip/AIP/data/:rw --name aip stratosphereips/aip:latest bin/aip

To run AIP for a specific day:

:~$ cd AIP
:~$ docker run --rm -v /opt/zeek/logs/:/home/aip/AIP/data/raw:ro -v ${PWD}/data/:/home/aip/AIP/data/:rw --name aip stratosphereips/aip:latest bin/aip YYYY-MM-DD

License

The Stratosphere AIP tool is licensed under GNU General Public License v3.0.

About

This tool was developed at the Stratosphere Laboratory at the Czech Technical University in Prague. This is part of the Stratosphere blocklist generation project.

This tool was originally born from the bachelor thesis of Thomas O'Hara, The Attacker IP Prioritizer: An IoT Optimized Blacklisting Algorithm (2021).

About

The Attacker IP Prioritizer(AIP) dynamically generates resource-friendly IPv4 blocklists from Zeek network flows.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

32 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Attacker IP Prioritization (AIP) Tool

Python CI TestsCodeQLDocker Hub CIDocker GHCR CI

Docker PullsGitHub issuesGitHub issues-closedGitHub open-pull-requestsGitHub pull-requests closed

The Attacker IP Prioritization (AIP) is a tool to generate efficient and economic IP blocklists based on network traffic captured from honeypot networks.

With the advent of 5G, IoT devices are directly connected often without firewall protection. Therefore we need blocklists that are small, efficient and economic. The AIP structure is shown below.

Description of the AIP pipeline

AIP Models

Each AIP model generates its own blocklist based on a specific criteria. The main models are:

  1. Prioritize New (PN)
    • Focuses on IPs that are new or have not been seen frequently in previous data.
    • Useful to identify emerging attackers that are starting to target a network.
  2. Prioritize Consistent (PC)
    • Focuses on IPs that have consistently attacked over time in previous data.
    • Useful to identify persistent attackers that continuously target a network.
  3. Alpha
    • Provides a baseline identifying all attackers seen in the last 24 hours.
    • Useful to compare the effectiveness of other models.
  4. Alpha7
    • Provides a baseline identifying all attackers seen in the last 7 days.
    • Useful to further compare the effectiveness of other models.
  5. Random Forest
    • Focuses on IPs that are more likely to attack in the future.
    • A more experimental approach to increase blocklist efficiency.

AIP Docker

The best way to run AIP right now is using Docker.

Usage

AIP will automatically attempt to run all the models using the available data. Assuming the Zeek data is located in its usual location:

:~$ cd AIP
:~$ docker run --rm -v /opt/zeek/logs/:/home/aip/AIP/data/raw:ro -v ${PWD}/data/:/home/aip/AIP/data/:rw --name aip stratosphereips/aip:latest bin/aip

To run AIP for a specific day:

:~$ cd AIP
:~$ docker run --rm -v /opt/zeek/logs/:/home/aip/AIP/data/raw:ro -v ${PWD}/data/:/home/aip/AIP/data/:rw --name aip stratosphereips/aip:latest bin/aip YYYY-MM-DD

License

The Stratosphere AIP tool is licensed under GNU General Public License v3.0.

About

This tool was developed at the Stratosphere Laboratory at the Czech Technical University in Prague. This is part of the Stratosphere blocklist generation project.

This tool was originally born from the bachelor thesis of Thomas O'Hara, The Attacker IP Prioritizer: An IoT Optimized Blacklisting Algorithm (2021).

About

The Attacker IP Prioritizer(AIP) dynamically generates resource-friendly IPv4 blocklists from Zeek network flows.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

32 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Attacker IP Prioritization (AIP) Tool

Python CI TestsCodeQLDocker Hub CIDocker GHCR CI

Docker PullsGitHub issuesGitHub issues-closedGitHub open-pull-requestsGitHub pull-requests closed

The Attacker IP Prioritization (AIP) is a tool to generate efficient and economic IP blocklists based on network traffic captured from honeypot networks.

With the advent of 5G, IoT devices are directly connected often without firewall protection. Therefore we need blocklists that are small, efficient and economic. The AIP structure is shown below.

Description of the AIP pipeline

AIP Models

Each AIP model generates its own blocklist based on a specific criteria. The main models are:

  1. Prioritize New (PN)
    • Focuses on IPs that are new or have not been seen frequently in previous data.
    • Useful to identify emerging attackers that are starting to target a network.
  2. Prioritize Consistent (PC)
    • Focuses on IPs that have consistently attacked over time in previous data.
    • Useful to identify persistent attackers that continuously target a network.
  3. Alpha
    • Provides a baseline identifying all attackers seen in the last 24 hours.
    • Useful to compare the effectiveness of other models.
  4. Alpha7
    • Provides a baseline identifying all attackers seen in the last 7 days.
    • Useful to further compare the effectiveness of other models.
  5. Random Forest
    • Focuses on IPs that are more likely to attack in the future.
    • A more experimental approach to increase blocklist efficiency.

AIP Docker

The best way to run AIP right now is using Docker.

Usage

AIP will automatically attempt to run all the models using the available data. Assuming the Zeek data is located in its usual location:

:~$ cd AIP
:~$ docker run --rm -v /opt/zeek/logs/:/home/aip/AIP/data/raw:ro -v ${PWD}/data/:/home/aip/AIP/data/:rw --name aip stratosphereips/aip:latest bin/aip

To run AIP for a specific day:

:~$ cd AIP
:~$ docker run --rm -v /opt/zeek/logs/:/home/aip/AIP/data/raw:ro -v ${PWD}/data/:/home/aip/AIP/data/:rw --name aip stratosphereips/aip:latest bin/aip YYYY-MM-DD

License

The Stratosphere AIP tool is licensed under GNU General Public License v3.0.

About

This tool was developed at the Stratosphere Laboratory at the Czech Technical University in Prague. This is part of the Stratosphere blocklist generation project.

This tool was originally born from the bachelor thesis of Thomas O'Hara, The Attacker IP Prioritizer: An IoT Optimized Blacklisting Algorithm (2021).

About

The Attacker IP Prioritizer(AIP) dynamically generates resource-friendly IPv4 blocklists from Zeek network flows.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

32 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Attacker IP Prioritization (AIP) Tool

Python CI TestsCodeQLDocker Hub CIDocker GHCR CI

Docker PullsGitHub issuesGitHub issues-closedGitHub open-pull-requestsGitHub pull-requests closed

The Attacker IP Prioritization (AIP) is a tool to generate efficient and economic IP blocklists based on network traffic captured from honeypot networks.

With the advent of 5G, IoT devices are directly connected often without firewall protection. Therefore we need blocklists that are small, efficient and economic. The AIP structure is shown below.

Description of the AIP pipeline

AIP Models

Each AIP model generates its own blocklist based on a specific criteria. The main models are:

  1. Prioritize New (PN)
    • Focuses on IPs that are new or have not been seen frequently in previous data.
    • Useful to identify emerging attackers that are starting to target a network.
  2. Prioritize Consistent (PC)
    • Focuses on IPs that have consistently attacked over time in previous data.
    • Useful to identify persistent attackers that continuously target a network.
  3. Alpha
    • Provides a baseline identifying all attackers seen in the last 24 hours.
    • Useful to compare the effectiveness of other models.
  4. Alpha7
    • Provides a baseline identifying all attackers seen in the last 7 days.
    • Useful to further compare the effectiveness of other models.
  5. Random Forest
    • Focuses on IPs that are more likely to attack in the future.
    • A more experimental approach to increase blocklist efficiency.

AIP Docker

The best way to run AIP right now is using Docker.

Usage

AIP will automatically attempt to run all the models using the available data. Assuming the Zeek data is located in its usual location:

:~$ cd AIP
:~$ docker run --rm -v /opt/zeek/logs/:/home/aip/AIP/data/raw:ro -v ${PWD}/data/:/home/aip/AIP/data/:rw --name aip stratosphereips/aip:latest bin/aip

To run AIP for a specific day:

:~$ cd AIP
:~$ docker run --rm -v /opt/zeek/logs/:/home/aip/AIP/data/raw:ro -v ${PWD}/data/:/home/aip/AIP/data/:rw --name aip stratosphereips/aip:latest bin/aip YYYY-MM-DD

License

The Stratosphere AIP tool is licensed under GNU General Public License v3.0.

About

This tool was developed at the Stratosphere Laboratory at the Czech Technical University in Prague. This is part of the Stratosphere blocklist generation project.

This tool was originally born from the bachelor thesis of Thomas O'Hara, The Attacker IP Prioritizer: An IoT Optimized Blacklisting Algorithm (2021).

About

The Attacker IP Prioritizer(AIP) dynamically generates resource-friendly IPv4 blocklists from Zeek network flows.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

32 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages