JITA

JITA Journal of Information Technology and Applications

Vol. 16 No. 1 (2026): JITA - APEIRON

Milan Panić, Nemanja Maček

Implementation of Cowrie Honeypot System and Improvement of Log Analysis

Review paper
DOI: https://doi.org/10.7251/JIT2601069P

Abstract

This paper aims to explain how honeypots work, how they are implemented, and why they have become a key aspect of cybersecurity. Honeypots are capable of doing everything from detecting new attacks never seen before in their environment to tracking programmed credit card fraud and identity theft. The paper implements the Cowrie honeypot system in a controlled environment to simulate attacks on SSH and Telnet services. Special focus is placed on the analysis of generated JSON log records, the complex structure of which makes forensic processing difficult. As a contribution to the paper, a Python helper module has been developed to convert raw log files into a readable and structured text format, thus improving the efficiency of security event analysis.

Keywords: Cowrie, honeypot, SSH, Telnet, log

Paper received: 17.3.2026.
Paper accepted: 30.4.2026.

Downloaded Article PDF: 20 times

Vol. 16 No. 1 (2026): JITA - APEIRON

Milan Panić, Nemanja Maček

Implementation of Cowrie Honeypot System and Improvement of Log Analysis

Review paper

DOI: https://doi.org/10.7251/JIT2601069P

Abstract

This paper aims to explain how honeypots work, how they are implemented, and why they have become a key aspect of cybersecurity. Honeypots are capable of doing everything from detecting new attacks never seen before in their environment to tracking programmed credit card fraud and identity theft. The paper implements the Cowrie honeypot system in a controlled environment to simulate attacks on SSH and Telnet services. Special focus is placed on the analysis of generated JSON log records, the complex structure of which makes forensic processing difficult. As a contribution to the paper, a Python helper module has been developed to convert raw log files into a readable and structured text format, thus improving the efficiency of security event analysis.

Keywords: Cowrie, honeypot, SSH, Telnet, log

Paper received: 17.3.2026.
Paper accepted: 30.4.2026.

Downloaded Article PDF: 20 times

Vol. 16 No. 1 (2026): JITA - APEIRON

Milan Panić, Nemanja Maček

Implementation of Cowrie Honeypot System and Improvement of Log Analysis

Review paper

DOI: https://doi.org/10.7251/JIT2601069P

Abstract

This paper aims to explain how honeypots work, how they are implemented, and why they have become a key aspect of cybersecurity. Honeypots are capable of doing everything from detecting new attacks never seen before in their environment to tracking programmed credit card fraud and identity theft. The paper implements the Cowrie honeypot system in a controlled environment to simulate attacks on SSH and Telnet services. Special focus is placed on the analysis of generated JSON log records, the complex structure of which makes forensic processing difficult. As a contribution to the paper, a Python helper module has been developed to convert raw log files into a readable and structured text format, thus improving the efficiency of security event analysis.

Keywords: Cowrie, honeypot, SSH, Telnet, log

Paper received: 17.3.2026.
Paper accepted: 30.4.2026.

Downloaded Article PDF: 20 times