Jul 2026· International Journal For Multidisciplinary Research· Vol 8· 0 citations· 16 references
TL;DR
Experimental evaluation conducted in a controlled network environment demonstrates that the proposed Deceptive Intrusion Prevention System improves detection accuracy, reduces false positives, and enhances overall system resilience.
Abstract
The rapid expansion of networked systems has led to an increase in sophisticated cyber threats that frequently bypass traditional security mechanisms. Conventional defenses largely rely on signature-based or rule-based techniques, which are limited in their ability to detect unknown or advanced attacks. To address these challenges, this paper proposes a Deceptive Intrusion Prevention System (DIPS) that transitions network security from a reactive model to a proactive, intelligence-driven approach. The proposed architecture employs strategically deployed decoy resources and deceptive information to divert attackers away from critical assets while monitoring their behavior within a controlled environment. The framework combines deception, behavioral analysis, and automated mitigation within a unified intrusion prevention architecture. By analyzing attacker interactions with deceptive components, the system accurately identifies malicious activity and enables real-time response actions such as isolation and blocking. Experimental evaluation conducted in a controlled network environment demonstrates that the proposed approach improves detection accuracy, reduces false positives, and enhances overall system resilience. The results further show that deception-based intrusion prevention effectively delays attackers and generates actionable threat intelligence, strengthening proactive network defense.
The rapid growth of interconnected digital infrastructures, cloud computing environments, Internet of Things devices, and enterprise networking systems has significantly increased the frequency, complexity, and sophistication of cyberattacks targeting organizational information assets. Traditional cybersecurity mechanisms based primarily on signature detection and static rule-based monitoring are becoming increasingly ineffective against modern attack strategies such as zero-day exploits, advanced persistent threats, insider attacks, ransomware campaigns, and polymorphic malware. In this context, adaptive threat intelligence frameworks integrated with behavior-based analytics have emerged as a promising approach for enhancing real-time cyberattack detection and proactive security response capabilities. This research investigates the design and implementation of an adaptive threat intelligence framework capable of identifying malicious activities through continuous behavioral analysis, anomaly detection, and dynamic threat assessment techniques. The study focuses on how behavioral analytics can improve cybersecurity resilience by monitoring user activities, network communication patterns, system interactions, application behavior, and endpoint activities to identify deviations from established normal operational baselines. Unlike traditional detection approaches that depend heavily on predefined signatures, behavior-based analytics enables the identification of previously unknown threats and evolving attack vectors through machine learning algorithms, predictive analytics, and intelligent pattern recognition models. The proposed framework integrates adaptive learning mechanisms that continuously update threat intelligence repositories based on real-time attack behaviors, thereby improving detection accuracy and minimizing response delays. The research further examines the role of artificial intelligence, big data analytics, and automated incident response systems in strengthening cyber defense infrastructures across enterprise environments. In addition to operational advantages, the study critically evaluates challenges associated with implementing adaptive threat intelligence systems, including false-positive generation, data privacy concerns, computational complexity, adversarial machine learning attacks, scalability limitations, and integration difficulties within heterogeneous network architectures. The research methodology incorporates quantitative analysis, simulated attack scenarios, case study evaluations, and expert assessments to measure the effectiveness of behavior-based threat detection techniques in identifying malicious activities across dynamic cybersecurity environments. Findings from the study indicate that adaptive threat intelligence frameworks significantly enhance threat visibility, accelerate incident response, reduce detection latency, and improve organizational preparedness against sophisticated cyber threats when compared to conventional security monitoring systems. The research also emphasizes the importance of continuous learning models, human oversight, ethical cybersecurity governance, and secure data management practices to ensure sustainable and reliable implementation of intelligent threat detection systems. The study concludes that behavior-based adaptive cybersecurity frameworks represent a critical advancement in modern cyber defense strategies by enabling organizations to detect, analyze, and respond to emerging cyber threats in real time while maintaining operational continuity, information security, and digital infrastructure resilience in increasingly hostile cyber environments.
Dr. S. Tamilselvi, Simhadri Madhuri, Wong Tze· Journal of Intelligent Decis...· 0 citations
As new power systems become increasingly dependent on cloud-supported cyber-physical systems, their openness and interconnectivity continue to increase, thereby exposing risk points for advanced persistent threats (APTs). Deception defense has been widely regarded as an effective proactive approach for mitigating APT threats. However, the remarkable reasoning capabilities of large language models (LLMs) have enabled APT attackers to leverage LLM-based semantic understanding and task-planning capabilities to conduct automated, intelligent penetration attacks, while also bringing new challenges for traditional deception defense mechanisms. To address this issue, we propose a Chameleon service mechanism that constructs multiple types of LLM-oriented deceptive services based on the shared characteristics that LLMs exhibit during environment reconnaissance and target screening, and further incorporates an attack-defense game model with Minimax Q-learning for deployment. In this way, the proposed method increases the likelihood of trapping attackers while minimizing interference with normal power operations. The experimental results show that the proposed Chameleon service mechanism can effectively enhance the trapping effect of deceptive services on LLM-assisted attackers and demonstrate good effectiveness and stability across different candidate scales and LLM evaluation conditions. Our method can provide a feasible solution for proactive deception defense against intelligent attackers in new power systems.
Ying Yao, Yiji Lin, Qinglin Yang et al.· Fall Joint Computer Conferen...· 0 citations
The increasing sophistication of cyber threats has led to the identification of some major shortcomings associated with honeypots, which include staticness, inflexibility, and vulnerability to fingerprinting. The proposed work aims at overcoming the aforementioned shortcomings by creating an Explainability-Driven Adaptive Cyber Deception Control System capable of engaging in intelligent, interactive interactions with cyber attackers. The key goal of the proposed solution is to improve threat intelligence gathering and deception efficiency by leveraging the benefits of adaptability and explainability. Machine learning, XAI, behavioral profiling, and environment mutation are the four key components that form the backbone of the proposed pipeline system. A Random Forest classifier is used for classification of normal and malicious sessions based on behavioral features at the level of commands. An explainability-driven metric known as the Feature Dominance Deception Index (FDDI) is developed to guide deception approaches, whereas Behavioral Convergence Score (BCS) is considered to assess behavioral convergence of attackers. Intent recognition using kill chain methodology allows generating responses in context-dependent fashion, while the mutation engine creates unique environments in each session to prevent fingerprinting attacks. Furthermore, Reinforcement Learning (RL) layer based on Q-learning is added to the framework to adaptively make decisions by learning the best possible deception tactics over multiple sessions. The Deception Quality Score (DQS) metric is used to measure the quality of deception within each session. Moreover, the UNSW-NB15 network intrusion data set is employed for validating the proposed model. Through benchmarking based on the generated behavioral dataset, the Random Forest-based behavioral profiler yielded a classification accuracy of 90.0%, recall of 85.7%, and an F1-score of 92.3%. Thereafter, the end-to-end deployment of the proposed framework through Cowrie honeypot sessions yielded better deception effectiveness, giving a framework-level attack classification accuracy of 90.0% and a 77.0% improvement in threat intelligence extraction per session than baseline Cowrie deployment. Kill chain stages were identified for the evaluated cases, deception goals were accomplished for all sessions under testing, fingerprinting efforts by the attacker were unsuccessful, and high-quality deception was maintained. The reward per session for the RL agent ranges from + 0 to + 14.0 for different session types, resulting in the formation of a converged Q-table containing values of 21 out of 90 possible states. Additionally, the technique ensures the resistance against honeypot fingerprinting, and demonstrates resistance against evaluated fingerprinting attempts. As far as it is currently known, few previous works can be found which have managed to include explainable scoring, convergence of behavior analysis, adaptive control, environment mutation, and reinforcement learning into one cyber deception framework. The presented framework manages to incorporate all of these features while still preserving transparency and adaptability during the whole process of deception. The research makes advances in the current state-of-the-art research by enabling passive honeypots to become intelligent autonomous systems for detecting cyber threats.
S. Roy, G. Khekare, Sejal Chhajed· Scientific Reports· 0 citations
Methods to increase the resilience of systems to cyber-attacks become increasingly important. Control-flow monitoring provides a principled basis to ensure integrity and detect possible anomalies at run-time. Once anomalies have been detected, so-called attack trees can be used to identify possible types of attacks. However, this approach is vulnerable to camouflage, by which attackers try to evade detection (and correct identification) by deliberately manipulating also the system's observed control flow. In this paper, we outline a model-based approach that provides more robust intrusion detection and attack identification through an architecture that combines software- with hardware-based monitoring. In this approach, software-level observation indicates suspicious activities, while hardware-level monitoring checks them separately in more detail, making it much harder for attacks to camouflage themselves and go undetected. We illustrate the approach with an authentication-service example that captures a realistic failure mode: a software-level observer sees an anomalous but apparently harmless control-flow deviation, maps it to a benign root cause in an attack tree, but misses the true intrusion. A second, independent hardware control-flow monitor observes the actual transition sequence and thereby changes the attack-tree diagnosis from a low-severity configuration or maintenance issue to a high-confidence code-injection or control-flow hijack. In this scenario, the proposed combination of control-flow anomaly detection, attack-tree based intrusion identification, and hardware-based monitoring can improve not only anomaly detection, but also the diagnostic precision of attack-tree-based cyber-attack identification.
M. Sachenbacher, Martin Leucker, Alexander Weiss et al.· 0 citations
As cyber threats continue to grow in sophistication, the need for intelligent and adaptive defense mechanisms becomes increasingly more critical. This research investigates the integration of Artificial Intelligence (AI) into a honeypot system to distract, mislead through deception, and engage potential cyber attackers. The primary research question to answer was: “How can AI-driven adaptive deception improve the effectiveness of honeypots in cybersecurity?” To address this, a high-interaction honeypot was developed on a HTML website to be perceived as a reverse shell, with the implementation of OpenAI’s GPT-4o model to respond, impersonating a Linux terminal, while silently tracking and logging the attacker, and classifying all commands into three sub-categories – Safe, Suspicious and Malicious. The core methods included command logging, AI-driven risk classification, dynamic fake filesystem manipulation, and the escalation of behavior based on the attacker's actions. Attack simulations were performed by highly credible third-party cybersecurity experts to evaluate the honeypots effectiveness in engaging and tracking the attacker for as long as possible. The findings suggest that AI integration significantly improved the realism and engagement level of the honeypot, both in terms of enhancing intelligence gathering and the improvements from traditional static honeypots. However, full automation of behavioral escalation tuning remains an area to further explore. Overall, this study demonstrates that the integration of AI within traditional honeypot strategies can significantly enhance cyber defense systems.
D. Corbett, S. Zargari· Latin American Journal of Co...· 0 citations
While intelligent algorithms improve the efficiency of network system operation and maintenance, they also lower the technical threshold for malicious attacks, leading to new network threats exhibiting high concealment, automation, and precision. This study focuses on the network security risks derived from intelligent algorithms, deeply analyzing the evolution mechanisms of three core vulnerabilities: intelligent identity forgery, algorithm-driven vulnerability mining, and automated traffic attacks. The study points out that traditional feature-matching-based defense models lag significantly in dealing with such dynamic threats. Based on this, this paper proposes solutions from three dimensions: dynamic perception, proactive verification, and collaborative governance, aiming to build a more adaptive, interconnected, and forward-looking network security protection system. The study argues that, facing the constantly evolving attack patterns driven by intelligent algorithms, network security governance cannot rely solely on static rules and post-incident handling. Instead, it should further strengthen the capabilities of real-time threat identification, trusted identity verification, cross-entity collaborative response, and dynamic updates of security policies, thereby providing new practical references for the iterative upgrade of network security protection systems.
Ai-Hao Luo, Bao-Ze Xu· SHS Web of Conferences· 0 citations