#!/usr/bin/env python3 import sqlite3, requests, time import matplotlib.pyplot as plt DB = "sshd_failures.db" # get top IPs (limit to avoid API spam) ips = [] db = sqlite3.connect(DB) for ip, count, _ in db.execute(""" SELECT ip, COUNT(*), MAX(ts) FROM failures GROUP BY ip ORDER BY COUNT(*) DESC LIMIT 30 """): ips.append((ip, count)) db.close() lats, lons, sizes = [], [], [] for ip, count in ips: try: r = requests.get(f"http://ip-api.com/json/{ip}", timeout=5).json() if r["status"] == "success": lats.append(r["lat"]) lons.append(r["lon"]) sizes.append(count * 5) print(f"{ip:15} -> {r['country']}") time.sleep(0.5) # be nice to API except: pass # plot plt.figure() plt.scatter(lons, lats, s=sizes) plt.title("SSHD Attack Origins") plt.xlabel("Longitude") plt.ylabel("Latitude") plt.show()