Skip to content
Conference Open access

Honeypot-Based Intrusion Detection with SIEM and Automated Response

Sep 2026 · Engineering & Technology · Vol 2, pp. 272-281 · 0 citations

TL;DR

An architecture for deception-based intrusion detection using a honeypot, a Network Intrusion Detection System (NIDS), centralized logging, Security Information and Event Management (SIEM), threat intelligence enrichment, and automated response mechanisms is presented.

Abstract

Cybercrime is on the rise due to an increase in cyberattacks such as brute-force attacks, network scanning, and malware deployment, leading to a greater need for network security monitoring. Traditional systems rely heavily on signatures and alerts and therefore often do not provide valuable insight into the attacker's behavior. Implementing deception-based security with honeypots enables security professionals to collect data on attacker activity. This paper presents an architecture for deception-based intrusion detection using a honeypot, a Network Intrusion Detection System (NIDS), centralized logging, Security Information and Event Management (SIEM), threat intelligence enrichment, and automated response mechanisms. Using the Cowrie honeypot, Suricata NIDS, syslog, and Wazuh SIEM, the architecture communicates attacker information to one centralized logging repository. A distinct feature is an attacker profiling module that classifies attacker behavior by executed commands and automatically blocks malicious IP addresses. The system uses multiple open-source tools to simulate a small-scale Security Operations Centre (SOC).

Read PDF

Similar papers

Review Open access Aug 2026

Adaptive Defense: Enhancing NIDS with Smart Honeypots and Attack Profiling

The paper examines the integration of the clever honeypots with the attacker behaviour analysis to enhance the network intrusion detection in the contemporary cyberspace environment. Due to the rapid development of cyber threats, the target of traditional intrusion detection systems (that are primarily based on fixed r...

Unknown authors · 0 citations
Open access Sep 2026

Intrusion detection in secure shell using Multilayer Perceptron

As the use of Internet users increases, their inter-connectivity enables malicious users to exploit resources and surge Internet attacks. The increasing Internet attacks pose various difficult challenges to develop flexible, adaptive, reliable security-focused approaches. An Intrusion Detection System (IDS) is the most...

Amit Chapagain · 0 citations
Open access Aug 2026

AI-Based Intrusion Detection System (IDS) for Signature Recognition Using Machine Learning and Network Simulation

The exponential rise in cyber threats has created a critical need for intelligent and adaptive intrusion detection systems (IDS) capable of identifying both known and emerging attack patterns. Traditional rule-based IDS mechanisms, such as Snort, rely heavily on predefined signatures and struggle against sophisticated...

T. Senthil, V. Shanmuganeethi · 0 citations
Open access Sep 2026

Implementation of Ransomware Threat Detection Using Behavior-Based Detection Algorithm

It is suggested that the behavioral identification engine be combined into Endpoint Identification and Response (EDR) platforms to promote intelligent threat containment, increase incident response, and reduce the danger of data loss.

Kazeem O. N., Abdul Kareem Olaitan Mummen, Shamsudeen Sani Saleh · 0 citations
Review Open access Aug 2026

An Integrated Honeypot and LLM-Based Framework for near Real-Time Detection and Behavioral Analysis of Malicious Activities

Integration of deterministic preprocessing with LLM-based reasoning enables the transformation of raw honeypot logs into structured and actionable cybersecurity intelligence, reducing analyst workload while improving the explainability and reliability of intrusion analysis in near-real-time environments.

Rúben Oliveira, Tiago Gomes, D. Pinho et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.