An architecture for deception-based intrusion detection using a honeypot, a Network Intrusion Detection System (NIDS), centralized logging, Security Information and Event Management (SIEM), threat intelligence enrichment, and automated response mechanisms is presented.
Abstract
Cybercrime is on the rise due to an increase in cyberattacks such as brute-force attacks, network scanning, and malware deployment, leading to a greater need for network security monitoring. Traditional systems rely heavily on signatures and alerts and therefore often do not provide valuable insight into the attacker's behavior. Implementing deception-based security with honeypots enables security professionals to collect data on attacker activity. This paper presents an architecture for deception-based intrusion detection using a honeypot, a Network Intrusion Detection System (NIDS), centralized logging, Security Information and Event Management (SIEM), threat intelligence enrichment, and automated response mechanisms. Using the Cowrie honeypot, Suricata NIDS, syslog, and Wazuh SIEM, the architecture communicates attacker information to one centralized logging repository. A distinct feature is an attacker profiling module that classifies attacker behavior by executed commands and automatically blocks malicious IP addresses. The system uses multiple open-source tools to simulate a small-scale Security Operations Centre (SOC).
The paper examines the integration of the clever honeypots with the attacker behaviour analysis to enhance the network intrusion detection in the contemporary cyberspace environment. Due to the rapid development of cyber threats, the target of traditional intrusion detection systems (that are primarily based on fixed r...
Unknown authors· Journal of Superintelligence...· 0 citations
As the use of Internet users increases, their inter-connectivity enables malicious users to exploit resources and surge Internet attacks. The increasing Internet attacks pose various difficult challenges to develop flexible, adaptive, reliable security-focused approaches. An Intrusion Detection System (IDS) is the most...
Amit Chapagain· Academia Journal of Research...· 0 citations
This proposed framework aims to fortify data protection and ensure user privacy in essential areas like healthcare, financial services, and e-governance, thereby fostering increased trust.
Sai Kiranmai Dornala, S. P.· International Journal of Int...· 0 citations
The exponential rise in cyber threats has created a critical need for intelligent and adaptive intrusion detection systems
(IDS) capable of identifying both known and emerging attack patterns. Traditional rule-based IDS mechanisms, such as Snort,
rely heavily on predefined signatures and struggle against sophisticated...
T. Senthil, V. Shanmuganeethi· International Journal for Re...· 0 citations
It is suggested that the behavioral identification engine be combined into Endpoint Identification and Response (EDR) platforms to promote intelligent threat containment, increase incident response, and reduce the danger of data loss.
Kazeem O. N., Abdul Kareem Olaitan Mummen, Shamsudeen Sani Saleh· International Journal of Inn...· 0 citations
Integration of deterministic preprocessing with LLM-based reasoning enables the transformation of raw honeypot logs into structured and actionable cybersecurity intelligence, reducing analyst workload while improving the explainability and reliability of intrusion analysis in near-real-time environments.
Rúben Oliveira, Tiago Gomes, D. Pinho et al.· Journal of Cybersecurity and...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.