An architecture for deception-based intrusion detection using a honeypot, a Network Intrusion Detection System (NIDS), centralized logging, Security Information and Event Management (SIEM), threat intelligence enrichment, and automated response mechanisms is presented.
Abstract
Cybercrime is on the rise due to an increase in cyberattacks such as brute-force attacks, network scanning, and malware deployment, leading to a greater need for network security monitoring. Traditional systems rely heavily on signatures and alerts and therefore often do not provide valuable insight into the attacker's behavior. Implementing deception-based security with honeypots enables security professionals to collect data on attacker activity. This paper presents an architecture for deception-based intrusion detection using a honeypot, a Network Intrusion Detection System (NIDS), centralized logging, Security Information and Event Management (SIEM), threat intelligence enrichment, and automated response mechanisms. Using the Cowrie honeypot, Suricata NIDS, syslog, and Wazuh SIEM, the architecture communicates attacker information to one centralized logging repository. A distinct feature is an attacker profiling module that classifies attacker behavior by executed commands and automatically blocks malicious IP addresses. The system uses multiple open-source tools to simulate a small-scale Security Operations Centre (SOC).
The research concludes that combining honeypot intelligence with machine learning improves real-time identification, proactive defence, as well as reducing the false alarms.
Unknown authors· Journal of Superintelligence...· 0 citations
A predictive model which uses an idea of detecting intrusion in a network is capable of recognizing intrusions or attacks as "1" and normal connections as “0” using Multilayer Perceptron (MLP) classification.
Amit Chapagain· Academia Journal of Research...· 0 citations
This proposed framework aims to fortify data protection and ensure user privacy in essential areas like healthcare, financial services, and e-governance, thereby fostering increased trust.
Sai Kiranmai Dornala, S. P.· International Journal of Int...· 0 citations
This paper presents an AI-based Intrusion Detection System that integrates network simulation, machine learning, and real-time visualization into a unified three-layer framework and demonstrates that combining simulation, machine learning, and visualization can produce a scalable and effective solution for modern netwo...
T. Senthil, V. Shanmuganeethi· International Journal for Re...· 0 citations
It is suggested that the behavioral identification engine be combined into Endpoint Identification and Response (EDR) platforms to promote intelligent threat containment, increase incident response, and reduce the danger of data loss.
Kazeem O. N., Abdul Kareem Olaitan Mummen, Shamsudeen Sani Saleh· International Journal of Inn...· 0 citations
Integration of deterministic preprocessing with LLM-based reasoning enables the transformation of raw honeypot logs into structured and actionable cybersecurity intelligence, reducing analyst workload while improving the explainability and reliability of intrusion analysis in near-real-time environments.
Rúben Oliveira, Tiago Gomes, D. Pinho et al.· Journal of Cybersecurity and...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.