EXAMPLE OF A SECURITY LOG ANALYZER
#include <iostream>
#include <fstream>
#include <sstream>
#include <string>
#include <vector>
#include <map>
#include <set>
using namespace std;
struct LogEntry {
string timestamp;
string ipAddress;
string username;
string action;
bool success;
};
class SecurityAnalyzer {
private:
vector logs;
map failedAttempts;
set suspiciousIPs;
public:
void loadLogs(const string& filename) {
ifstream file(filename);
if (!file.is_open()) {
cerr << "Error: Could not open log file.\n";
return;
}
string line;
while (getline(file, line)) {
stringstream ss(line);
string timestamp, ip, username, action, status;
getline(ss, timestamp, ',');
getline(ss, ip, ',');
getline(ss, username, ',');
getline(ss, action, ',');
getline(ss, status, ',');
LogEntry entry;
entry.timestamp = timestamp;
entry.ipAddress = ip;
entry.username = username;
entry.action = action;
entry.success = (status == "SUCCESS");
logs.push_back(entry);
if (!entry.success) {
failedAttempts[ip]++;
}
}
file.close();
}
void detectThreats() {
const int THRESHOLD = 5;
for (const auto& attempt : failedAttempts) {
if (attempt.second >= THRESHOLD) {
suspiciousIPs.insert(attempt.first);
}
}
}
void generateReport() {
cout << "\n========== SECURITY REPORT ==========\n";
cout << "\nTotal log entries: "
<< logs.size() << endl;
cout << "\nFailed Login Attempts:\n";
for (const auto& attempt : failedAttempts) {
cout << "IP: " << attempt.first
<< " | Failed Attempts: "
<< attempt.second;
if (suspiciousIPs.count(attempt.first)) {
cout << " <-- SUSPICIOUS";
}
cout << endl;
}
cout << "\nSuspicious IP Addresses:\n";
if (suspiciousIPs.empty()) {
cout << "None detected.\n";
}
else {
for (const string& ip : suspiciousIPs) {
cout << "- " << ip << endl;
}
}
cout << "\n=====================================\n";
}
};
int main() {
SecurityAnalyzer analyzer;
analyzer.loadLogs("security.log");
analyzer.detectThreats();
analyzer.generateReport();
return 0;
}