Skip to content
Open access

A Deception-Based Intrusion Prevention Framework for Proactive Network Security Using Behavioral Threat Analysis

Jul 2026 · International Journal For Multidisciplinary Research · 0 citations · 16 references

TL;DR

Experimental evaluation conducted in a controlled network environment demonstrates that the proposed Deceptive Intrusion Prevention System improves detection accuracy, reduces false positives, and enhances overall system resilience.

Abstract

The rapid expansion of networked systems has led to an increase in sophisticated cyber threats that frequently bypass traditional security mechanisms. Conventional defenses largely rely on signature-based or rule-based techniques, which are limited in their ability to detect unknown or advanced attacks. To address these challenges, this paper proposes a Deceptive Intrusion Prevention System (DIPS) that transitions network security from a reactive model to a proactive, intelligence-driven approach. The proposed architecture employs strategically deployed decoy resources and deceptive information to divert attackers away from critical assets while monitoring their behavior within a controlled environment. The framework combines deception, behavioral analysis, and automated mitigation within a unified intrusion prevention architecture. By analyzing attacker interactions with deceptive components, the system accurately identifies malicious activity and enables real-time response actions such as isolation and blocking. Experimental evaluation conducted in a controlled network environment demonstrates that the proposed approach improves detection accuracy, reduces false positives, and enhances overall system resilience. The results further show that deception-based intrusion prevention effectively delays attackers and generates actionable threat intelligence, strengthening proactive network defense.

Read PDF

Similar papers

Open access Aug 2026

Adaptive Threat Intelligence Framework for Real-Time Cyberattack Detection Using Behavior-Based Analytics

The rapid growth of interconnected digital infrastructures, cloud computing environments, Internet of Things devices, and enterprise networking systems has significantly increased the frequency, complexity, and sophistication of cyberattacks targeting organizational information assets. Traditional cybersecurity mechanisms based primarily on signature detection and static rule-based monitoring are becoming increasingly ineffective against modern attack strategies such as zero-day exploits, advanced persistent threats, insider attacks, ransomware campaigns, and polymorphic malware. In this context, adaptive threat intelligence frameworks integrated with behavior-based analytics have emerged as a promising approach for enhancing real-time cyberattack detection and proactive security response capabilities. This research investigates the design and implementation of an adaptive threat intelligence framework capable of identifying malicious activities through continuous behavioral analysis, anomaly detection, and dynamic threat assessment techniques. The study focuses on how behavioral analytics can improve cybersecurity resilience by monitoring user activities, network communication patterns, system interactions, application behavior, and endpoint activities to identify deviations from established normal operational baselines. Unlike traditional detection approaches that depend heavily on predefined signatures, behavior-based analytics enables the identification of previously unknown threats and evolving attack vectors through machine learning algorithms, predictive analytics, and intelligent pattern recognition models. The proposed framework integrates adaptive learning mechanisms that continuously update threat intelligence repositories based on real-time attack behaviors, thereby improving detection accuracy and minimizing response delays. The research further examines the role of artificial intelligence, big data analytics, and automated incident response systems in strengthening cyber defense infrastructures across enterprise environments. In addition to operational advantages, the study critically evaluates challenges associated with implementing adaptive threat intelligence systems, including false-positive generation, data privacy concerns, computational complexity, adversarial machine learning attacks, scalability limitations, and integration difficulties within heterogeneous network architectures. The research methodology incorporates quantitative analysis, simulated attack scenarios, case study evaluations, and expert assessments to measure the effectiveness of behavior-based threat detection techniques in identifying malicious activities across dynamic cybersecurity environments. Findings from the study indicate that adaptive threat intelligence frameworks significantly enhance threat visibility, accelerate incident response, reduce detection latency, and improve organizational preparedness against sophisticated cyber threats when compared to conventional security monitoring systems. The research also emphasizes the importance of continuous learning models, human oversight, ethical cybersecurity governance, and secure data management practices to ensure sustainable and reliable implementation of intelligent threat detection systems. The study concludes that behavior-based adaptive cybersecurity frameworks represent a critical advancement in modern cyber defense strategies by enabling organizations to detect, analyze, and respond to emerging cyber threats in real time while maintaining operational continuity, information security, and digital infrastructure resilience in increasingly hostile cyber environments.

S. Tamilselvi · 0 citations
Conference Jul 2026

Chameleon: A Deception Defense Strategy Against LLM-Assisted Attacker in New Power Systems

As new power systems become increasingly dependent on cloud-supported cyber-physical systems, their openness and interconnectivity continue to increase, thereby exposing risk points for advanced persistent threats (APTs). Deception defense has been widely regarded as an effective proactive approach for mitigating APT threats. However, the remarkable reasoning capabilities of large language models (LLMs) have enabled APT attackers to leverage LLM-based semantic understanding and task-planning capabilities to conduct automated, intelligent penetration attacks, while also bringing new challenges for traditional deception defense mechanisms. To address this issue, we propose a Chameleon service mechanism that constructs multiple types of LLM-oriented deceptive services based on the shared characteristics that LLMs exhibit during environment reconnaissance and target screening, and further incorporates an attack-defense game model with Minimax Q-learning for deployment. In this way, the proposed method increases the likelihood of trapping attackers while minimizing interference with normal power operations. The experimental results show that the proposed Chameleon service mechanism can effectively enhance the trapping effect of deceptive services on LLM-assisted attackers and demonstrate good effectiveness and stability across different candidate scales and LLM evaluation conditions. Our method can provide a feasible solution for proactive deception defense against intelligent attackers in new power systems.

Ying Yao, Yiji Lin, Qinglin Yang et al. · 0 citations
Open access Aug 2026

Explainability-driven adaptive cyber deception control system for autonomous network defense

The presented framework manages to incorporate explainable scoring, convergence of behavior analysis, adaptive control, environment mutation, and reinforcement learning into one cyber deception framework and manages to incorporate all of these features while still preserving transparency and adaptability during the whole process of deception.

S. Roy, G. Khekare, Sejal Chhajed · 0 citations
Preprint Aug 2026

Towards Model-based Run-time Cybersecurity: On Control-Flow Anomaly Detection, Attack Identification, and Hardware Monitoring

The proposed combination of control-flow anomaly detection, attack-tree based intrusion identification, and hardware-based monitoring can improve not only anomaly detection, but also the diagnostic precision of attack-tree-based cyber-attack identification.

M. Sachenbacher, Martin Leucker, Alexander Weiss et al. · 0 citations
Conference Open access 2026

Research on Cybersecurity Risks and Protection Strategies Derived from Intelligent Algorithms

The study argues that, facing the constantly evolving attack patterns driven by intelligent algorithms, network security governance cannot rely solely on static rules and post-incident handling, and should further strengthen the capabilities of real-time threat identification, trusted identity verification, cross-entity collaborative response, and dynamic updates of security policies.

Ai-Hao Luo, Bao-Ze Xu · 0 citations