Adaptive Defense: Enhancing NIDS with Smart Honeypots and Attack Profiling
Unknown authors
Aug 2026· Journal of Superintelligence and Computing· 0 citations
TL;DR
The research concludes that combining honeypot intelligence with machine learning improves real-time identification, proactive defence, as well as reducing the false alarms.
Abstract
The paper examines the integration of the clever honeypots with the attacker behaviour analysis to enhance the network intrusion detection in the contemporary cyberspace environment. Due to the rapid development of cyber threats, the target of traditional intrusion detection systems (that are primarily based on fixed rules and known signatures) is to identify zero-day exploits, polymorphism, malware, and advanced persistent threats. In an attempt to circumvent these constraints, the study employs a quantitative paradigm that incorporates the survey of experts, simulated honeypot logs, and machine-learning-based behaviour analysis. Honeypot data around the world show trends in the frequency of attacks and ports attacked as well as the geographic origin and time. The 4 machine-learning models, Logistic Regression, KNN, Random Forest and XGBoost, were trained and tested on the feature-engineered datasets. The ensemble techniques performed well as compared to their linear counterparts with XGBoost recording 99.96 0-percent accuracy and Rand. Forest recording a 100 percent accuracy in the dataset. The findings demonstrate that intelligent honeypots do not only collect valuable behavioural indications, but also offer highly predictive attributes to automated detecting mechanisms. The research concludes that combining honeypot intelligence with machine learning improves real-time identification, proactive defence, as well as reducing the false alarms.
An architecture for deception-based intrusion detection using a honeypot, a Network Intrusion Detection System (NIDS), centralized logging, Security Information and Event Management (SIEM), threat intelligence enrichment, and automated response mechanisms is presented.
While integrating the Industrial Internet of Things (IIoT) into smart factories massively boosts efficiency, it also opens the door to severe cyberattacks, such as malware and denial-of-service, that can actually disable physical machinery. To protect these vulnerable systems, researchers developed an edge computing-ba...
Firoz Ahmed Mansuri, Anita Seth· International Conference Com...· 0 citations
The ransomware attack is one of the most prominent forms of cybersecurity risks, as it can cause the crucial information unavailable and cause significant harm to the functioning of critical services within various sectors. The conventional techniques of signature-based detections have been proven highly ineffective wh...
Suvarna P. Bhatsangave, Rajkumar Jain· International Conference on...· 0 citations
A conceptual layered framework for machine-learning-based security operations that integrates detection, adversarial-robustness testing, and human-analyst oversight is proposed by outlining directions for future research.
C. Thilagavathy, Saeed Mudether Saeed Taha, Krithik M. S. et al.· International Scientific Jou...· 0 citations
This proposed framework aims to fortify data protection and ensure user privacy in essential areas like healthcare, financial services, and e-governance, thereby fostering increased trust.
Sai Kiranmai Dornala, S. P.· International Journal of Int...· 0 citations
An intelligent DDoS detection and mitigation framework that combines classical Machine Learning (ML) classifiers with Deep Learning (DL) architectures to achieve high-fidelity, low-latency attack identification across heterogeneous network topologies is presented.
S. Singh, Alok Kumar· International Journal of Com...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.