Abstract
SSH services are frequently targeted by automated and manual attacks, making them useful sources of information for studying attacker behavior. Conventiona SSH honeypots can capture authentication attempts and commands, but the collected information often requires manual analysis to understand the progression and severity of an attack. Existing research has also explored container-based deception, adaptive honeypots, attacker profiling, and automated analysis, but practical systems still face limitations related to deployment complexity, analysis speed, or integration of multiple security functions. This paper presents SSH-HoneyGuard, a container-isolated SSH honeypot designed to capture and analyze attacker interactions using an explainable rule-based detection approach. The system uses a Paramiko-based SSH service, a controlled fake shell, structured session and authentication logging, command categorization, and detection of suspicious and multi-stage activities. Docker isolation is used to separate the honeypot environment from the host system. SQLite provides persistent storage for sessions, authentication attempts, commands, and security alerts. The implemented system was evaluated through a series of controlled experiments covering command classification, multi-stage attack detection, authentication logging, container isolation, and persistence of collected data. The final dataset contained 52 sessions, 50 authentication attempts, 409 recorded commands, and 147 generated alerts. Of the recorded commands, 328 were classified into defined behavioral categories, corresponding to approximately 80.20% classification coverage. The system also generated 11 multi-stage activity alerts, demonstrating its ability to correlate suspicious activities across attack stages.