STUDENT PROJECT
Firewalls, honeypots & proprietary systems
TaraSec should work with the security tools networks already use, not require replacing them.
The integration problem
Firewalls, IDS/IPS, SIEM/SOC platforms and honeypots already generate useful observations. The challenge is to normalize those signals and connect them to the network that owns the originating unit.
Possible work
Integrate one or more products or open-source tools, compare syslog/API/event formats, study Cisco/Fortinet-style proprietary environments, test Cowrie or other honeypots, and define how receiving systems should consume TaraSec risk information.
The output can be code, adapters, protocol recommendations, test results or vendor-integration documentation.
Discuss it with the TaraSec AI
Ask what firewall and honeypot parsers already exist, which logs are currently handled and what is missing for end-to-end reporting.