Security

Honeypot Network with Attack Telemetry Dashboard

Deploy deliberately exposed decoy services, collect what attacks them, and analyse the traffic to characterise what automated internet-wide scanning actually looks like. Real data from a live internet-facing deployment, which very few student projects have.

Difficulty

Intermediate

A small team, or one strong student willing to learn something new.
Effort

1 semester, 2 to 3 students

Deliverables

5 to ship

3 optional extras

Suggested stack

PythonDockerElasticsearchKibanaPostgreSQL
A suggestion, not a requirement. Swap anything for what you already know.

What you should ship

  • At least 3 emulated services deployed in isolated containers with no path to any real system
  • Full interaction logging including credentials attempted, commands issued and payloads uploaded
  • Enrichment adding geolocation and network ownership to source addresses
  • Dashboard showing attack volume, targeted services, credential patterns and top payloads over time
  • Written analysis of at least 30 days of collected data with quantified findings

If you have time left

  • Automated malware sample capture with static analysis in an isolated environment
  • Correlating scanning activity against public vulnerability disclosure dates
  • Comparing attack profiles across two geographic regions

The problem

Security teaching is mostly theoretical because real attack data is not available to students. A honeypot generates it, because anything exposed on the public internet is scanned continuously within minutes.

What you build

Isolated emulated services, comprehensive interaction logging, enrichment and a dashboard, then a written analysis of what you observed.

Why the analysis is the project

The infrastructure is a means to an end. The deliverable that matters is thirty days of data and what you can say about it: which credentials are attempted most, how quickly a new host is discovered, whether scanning volume responds to disclosure events, which regions dominate. Those are quantified findings from data you collected.

The safety requirements, which are absolute

The honeypot must be genuinely isolated with no route to any real system, must not be usable to attack third parties, and must never be a real vulnerable service. Emulated interactions only. Get written approval from your supervisor and your institution's network administrators before anything is exposed, and check your provider's acceptable use policy.

Timing

Deploy in the first three weeks. You need a month of data minimum, and this is the deadline that will bite if you leave the infrastructure until the middle of the semester.

Scope warning

Do not build intrusion prevention or an attack attribution system. Collection, presentation and analysis is a full project.

Ideas and guidance, not finished projects

These are project ideas and scoping guidance, published free for students to use as a starting point. I do not build, write, or sell final-year projects, and I do not complete coursework for anyone. Take an idea, make it yours, and build it.

Not sure this one fits you?

I help students pick an idea that matches their skills and their deadline, then scope it down until it is finishable. Guidance only, never done for you.

Get guidance
Work with me

Stuck on something specific?

Writing only gets you so far. If you want an answer to your situation rather than the general case, book a session and we will work through it together. Every session is free; a few slots open each week.

Follow along

New writing, resources and project ideas land here first.