A Bash-based security utility designed for Blue Team automation. This tool monitors system authentication logs, identifies high-frequency failure patterns, and prepares dynamic firewall responses to mitigate brute-force attacks.
This project was developed as a final portfolio piece for IT 135 (Introduction to Linux) at North Seattle College. It demonstrates proficiency in Bash scripting, log analysis, and security automation.
- Automated Log Analysis: Uses
grepandawkto parsesshdlogs for malicious patterns. - Smart Throttling: Blocks IPs only after crossing a user-defined failure threshold.
- Safety First: Includes a Whitelist feature to prevent administrative lockout.
- Audit Logging: Maintains a forensic trail of all identified threats and actions taken.
- Interactive Setup: Includes a first-time configuration wizard for easy deployment.
In a standard production environment, a server exposed to the internet can face thousands of unauthorized SSH connection attempts per hour. Manual monitoring of /var/log/auth.log is impossible for a human operator, and leaving these attempts unmitigated risks a successful brute-force compromise.
The administration team needed an automated "Blue Team" utility to:
-
Identify high-frequency failure patterns across massive log files.
-
Filter out legitimate administrative traffic (Whitelisting).
-
Audit and Execute defensive actions (Firewall blocking) without manual intervention.
The ssh_guard.sh script implements a modular security pipeline. It extracts "Failed" and "Invalid" login attempts into a persistent failure log for analysis, uses awk to aggregate hit counts by IP address, and compares those counts against a user-defined threshold. By separating the Analysis Engine from the Setup Configuration, the script can be deployed across various Linux environments with zero code modification.
- Language: Bash (Shell Scripting)
- Tools:
awk,grep,sed,nftables(planned integration) - Environment: Developed and tested in GitHub Codespaces (Ubuntu Linux)
/src: Contains the coressh_guard.shlogic andlog_gen.sh, a custom testing utility to simulate SSH attacks./resources: Directory for log processing (contains.gitkeep).ssh_guard.conf: Local configuration (user-defined).
- Clone the repo:
git clone <your-repo-link> - Set Permissions:
chmod ug+x src/*.sh - Run the Generator:
bash src/log_gen.sh(Creates 20 simulated failed logins). - Run SSH Guard:
bash src/ssh_guard.sh
A Linux environment (Bash shell) with standard utilities (grep, awk, sort, uniq, tee).
First, ensure your scripts are executable, then run the guard:
chmod ug+x src/*.sh
./src/ssh_guard.shThe script utilizes a piped sequence to transform raw log data into actionable security intelligence:
# 1. Isolate IP addresses from failure logs
# 2. Sort and count unique occurrences
# 3. Pass data to the decision-making loop
awk '{print $11}' "$FAIL" | sort | uniq -c | while read COUNT IP; do
if [[ "$COUNT" -ge "$THRESHOLD" ]]; then
# Check against Whitelist and Audit Log before acting
grep -q "$IP" "$WHITELIST" || log_msg "ACTION: Blocking $IP"
fi
doneThe use of uniq -c provides an immediate tally of attempts per IP, allowing for precise threshold enforcement.
The resulting audit_log.txt provides a forensic timeline of actions taken, ensuring the security team has a clear record of blocked threats:
[2026-03-25 14:10:01] ACTION: Blocking 172.16.0.45 (12 failures detected)
[2026-03-25 14:10:05] NOTICE: 192.168.1.20 is whitelisted. Skipping.
[2026-03-25 14:12:30] ACTION: Blocking 10.10.5.122 (8 failures detected)
While the core analysis engine is functional, the following features are planned for future releases to improve system hygiene and performance:
- Environment Decoupling: Separating the "Lab" testing logic from the "Production" utility to allow for seamless, plug-and-play deployment on live Linux systems.
- Log Rotation & Cleanup: Implementing a "Cleanup" routine to compress or archive
master_fail_log.txtafter processing to prevent disk space exhaustion. - Active Firewall Integration: Transitioning from "Logging-only" mode to active mitigation using
nftablesoriptablesAPI calls. - Discord/Slack Webhooks: Adding real-time notifications to alert administrators when a high-priority block occurs.
- Config Validation: Adding a pre-flight check to ensure the user-provided paths in
ssh_guard.confhave the correct read/write permissions.
This project was based on initial concepts and structures derived from the "Linux Text Processing Tools" module at North Seattle College (IT135).
In line with academic integrity and modern development practices, I utilized Google's Gemini large language model (LLM) for the following purposes:
- Syntax Debugging: Correcting missed punctuation and variables.
- Code Review: Verifying best practices for shell variable usage and quoting.
- Documentation Drafting: Structuring and refining the language used in this
README.mdand the initial project overview.
No copyrighted code was used, and the final script logic was engineered and tested independently.
- Siona Larsen
- **https://www.linkedin.com/in/sionalarsen/
- Educational Context: Created for IT 135, North Seattle College.