Skip to content
Conference Open access

Honeypot-Based Intrusion Detection with SIEM and Automated Response

Sep 2026 · Engineering & Technology · 0 citations

TL;DR

An architecture for deception-based intrusion detection using a honeypot, a Network Intrusion Detection System (NIDS), centralized logging, Security Information and Event Management (SIEM), threat intelligence enrichment, and automated response mechanisms is presented.

Abstract

Cybercrime is on the rise due to an increase in cyberattacks such as brute-force attacks, network scanning, and malware deployment, leading to a greater need for network security monitoring. Traditional systems rely heavily on signatures and alerts and therefore often do not provide valuable insight into the attacker's behavior. Implementing deception-based security with honeypots enables security professionals to collect data on attacker activity. This paper presents an architecture for deception-based intrusion detection using a honeypot, a Network Intrusion Detection System (NIDS), centralized logging, Security Information and Event Management (SIEM), threat intelligence enrichment, and automated response mechanisms. Using the Cowrie honeypot, Suricata NIDS, syslog, and Wazuh SIEM, the architecture communicates attacker information to one centralized logging repository. A distinct feature is an attacker profiling module that classifies attacker behavior by executed commands and automatically blocks malicious IP addresses. The system uses multiple open-source tools to simulate a small-scale Security Operations Centre (SOC).

Read PDF

Similar papers

Review Open access Aug 2026

Adaptive Defense: Enhancing NIDS with Smart Honeypots and Attack Profiling

The research concludes that combining honeypot intelligence with machine learning improves real-time identification, proactive defence, as well as reducing the false alarms.

Unknown authors · 0 citations
Open access Sep 2026

Intrusion detection in secure shell using Multilayer Perceptron

A predictive model which uses an idea of detecting intrusion in a network is capable of recognizing intrusions or attacks as "1" and normal connections as “0” using Multilayer Perceptron (MLP) classification.

Amit Chapagain · 0 citations
Open access Aug 2026

AI-Based Intrusion Detection System (IDS) for Signature Recognition Using Machine Learning and Network Simulation

This paper presents an AI-based Intrusion Detection System that integrates network simulation, machine learning, and real-time visualization into a unified three-layer framework and demonstrates that combining simulation, machine learning, and visualization can produce a scalable and effective solution for modern netwo...

T. Senthil, V. Shanmuganeethi · 0 citations
Open access Sep 2026

Implementation of Ransomware Threat Detection Using Behavior-Based Detection Algorithm

It is suggested that the behavioral identification engine be combined into Endpoint Identification and Response (EDR) platforms to promote intelligent threat containment, increase incident response, and reduce the danger of data loss.

Kazeem O. N., Abdul Kareem Olaitan Mummen, Shamsudeen Sani Saleh · 0 citations
Review Open access Aug 2026

An Integrated Honeypot and LLM-Based Framework for near Real-Time Detection and Behavioral Analysis of Malicious Activities

Integration of deterministic preprocessing with LLM-based reasoning enables the transformation of raw honeypot logs into structured and actionable cybersecurity intelligence, reducing analyst workload while improving the explainability and reliability of intrusion analysis in near-real-time environments.

Rúben Oliveira, Tiago Gomes, D. Pinho et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.