Secure Tea Project

The OWASP SecureTea Project provides a one-stop security solution for various devices (personal computers / servers / IoT devices)

Cybersecurity & Ethical HackingJavaScriptMIT

Abstract

Secure Tea Project is an open-source Cybersecurity & Ethical Hacking project. The OWASP SecureTea Project provides a one-stop security solution for various devices (personal computers / servers / IoT devices). [![Build Status][Travis-badge]][Travis] [![Codacy Badge][Codacy-badge]][Codacy] [![PyPI][PyPi-badge]][PyPi] [![GitHub][License-badge]][License] [![Telegram][Telegram-badge]][Telegram] [![Version][Version-badge]][Version] [![Tag][Tag-badge]][Tag] [![GitHub issues][Issues-badge]][Issues] [![GitHub pull requests][PR-badge]][PRs] [![GSOC 2019][GSOC-2019-badge]][GSOC-OWASP] [](https://twitter.com/secureteatool) [](#contributors) [![Heroku][Heroku]](https://secure-tea.herokuapp.com/). It is built using JavaScript. Key capabilities include: Intrusion Detection System; Firewall; Web Application Firewall. The complete source code is publicly available on GitHub under the MIT License, making it a useful reference for students building a Cybersecurity & Ethical Hacking mini project or final-year project.

1. Introduction

[![Build Status][Travis-badge]][Travis] [![Codacy Badge][Codacy-badge]][Codacy] [![PyPI][PyPi-badge]][PyPi] [![GitHub][License-badge]][License] [![Telegram][Telegram-badge]][Telegram] [![Version][Version-badge]][Version] [![Tag][Tag-badge]][Tag] [![GitHub issues][Issues-badge]][Issues] [![GitHub pull requests][PR-badge]][PRs] [![GSOC 2019][GSOC-2019-badge]][GSOC-OWASP] [](https://twitter.com/secureteatool) [](#contributors) [![Heroku][Heroku]](https://secure-tea.herokuapp.com/)

For example, running Intrusion Detection System only: $ sudo securetea --ids

For more detailed information, refer to the usage guide.

2. Objective

The OWASP SecureTea Project provides a one-stop security solution for various devices (personal computers / servers / IoT devices)

This project demonstrates how JavaScript can be applied to a real-world Cybersecurity & Ethical Hacking problem.

3. Key Features / Modules

  • Intrusion Detection System
  • Firewall
  • Web Application Firewall
  • AntiVirus
  • Malware Analysis
  • Server Log Monitor
  • System Log Monitor
  • Local Web Deface Detection & Prevention System
  • Auto Web Server Patcher
  • Insecure Headers Detection

4. Technology Stack

JavaScript

5. System Requirements

General requirements for this technology stack — check the README for exact versions.

  • Node.js (LTS) and npm
  • A modern web browser
  • VS Code or any code editor
  • Git (to clone the repository)

6. Installation & Setup

git clone https://github.com/OWASP/SecureTea-Project.git
cd SecureTea-Project
  1. Start SecureTea using one or more integrations:
  2. Start SecureTea in server mode:
  3. Start SecureTea in system mode:
  4. Start SecureTea in IoT mode:
$ sudo bash install_dependencies_apt.sh
$ sudo bash install_dependencies_yum.sh
git clone https://github.com/OWASP/SecureTea-Project.git
cd SecureTea-Project/
sudo python3 setup.py install

Full setup instructions are in the project README.

7. Future Enhancements

Suggested extensions you can add to make this your own project.

  • Add logging and alert notifications (email / Telegram)
  • Write a threat model document for the tool
  • Package it with Docker for safe lab testing

8. Viva / Review Questions

Common questions examiners ask for projects in this domain.

  1. Which threat or attack does this project defend against?
  2. What detection or protection technique is used and what are its limits?
  3. How are false positives and false negatives handled?
  4. Which cryptographic algorithms or security standards are involved?
  5. What legal and ethical rules apply when testing a tool like this?

9. Source Code & License

This project is developed by OWASP and published on GitHub under the MIT License. Please follow the license terms and credit the original author when you use or modify this code.

Want to build this as your internship project?

Work on a Cybersecurity & Ethical Hacking project like this with mentor guidance, weekly reviews and an internship certificate from Training Trains, Erode — online or offline.

Apply for Cybersecurity & Ethical Hacking Internship