Back to C2SI
GSoC 2026

Scalable Multi-Cloud Honeynet & Serverless Threat Intelligence Pipeline

Deploying a honeypot is only half the battle; the real value lies in the intelligence we can extract from it. Currently, standard honeypot deployments leave valuable attacker logs isolated on individual virtual machines. If an instance is terminated, that threat data is gone forever, making it impossible to correlate global attack patterns or build a cohesive defensive strategy. This proposal shifts the C2SI Honeynet from a collection of isolated servers into a centralized, serverless Threat Intelligence Platform. Using Terraform and Ansible, I will build a modular framework to deploy secure, Dockerized sensor nodes across multiple cloud providers (AWS and GCP). Instead of logging locally, these edge nodes will use Fluent Bit to stream attacker telemetry in real-time to a centralized AWS S3 data lake. From there, an event-driven Python Lambda function will automatically enrich attacker IPs with global threat scores and geolocation data, making the raw attacks instantly queryable for researchers via Amazon Athena. I am not starting this project from scratch. To prove this architecture is viable and cost-effective, I have already engineered the core serverless pipeline, secured the remote Terraform state with DynamoDB locking, and built the hardened GCP modules in my preliminary Pull Requests (PR #8, #13, #14, #15, #35). Over the 350-hour GSoC period, my goal is to scale this proven foundation into a production-ready system that allows C2SI security teams to deploy a global honeynet and hunt threats with a single command.

Project details

Contributor

Gowthaboina Trisha

Mentors

Not available

Technologies

Not listed in the archive