Cybersecurity / Infrastructure

Apache Server Security Monitoring System

Real-time monitor with automatic IP blocking, AbuseIPDB integration and intrusion alerts

In Production

About the project

Security monitoring platform developed for Apache web servers in a Windows environment, with real-time analysis of access and error logs, automatic detection of attack patterns and immediate blocking of malicious IPs via Windows Firewall.

The system continuously analyses Apache's access.log and error.log, identifying over 120 catalogued attack patterns — including SQL Injection, Shell Injection, Path Traversal, XSS, framework attacks (Laravel, WordPress, ThinkPHP), known scanners (Nikto, Nmap, Metasploit) and critical exploits such as Log4Shell and Shellshock.

Integration with the AbuseIPDB API enables automatic blocking of IPs with known abuse history on first contact with the server, regardless of the detected attack pattern. The system includes configurable rate limiting, an authorised IP whitelist, maintenance mode with administrative IP protection and intelligent caching of external API queries.

The Windows Presentation Foundation graphical interface presents real-time activity, alert history with severity filters, management of blocked and unblocked IPs, session statistics and auto-blocks. The entire system is compiled as a Windows executable with automatic privilege elevation.

Results Automatic blocking of hundreds of malicious IPs per day, attack detection and response in under 30 seconds

Technologies

Features

Back to portfolio

More projects

Contact

Have a project in mind?

Tell us what you need and we will put together a proposal, no strings attached.

Get in touch