Matcheswala, Mohammed Shaad Mehboob and Javed, Amir ORCID: https://orcid.org/0000-0001-9761-0945
2024.
Creating an adaptive defense architecture using an adaptive honeypot algorithm and network traffic classifier.
Presented at: ICCS 2023,
Cardiff, Uk,
11-12 December 2023.
Published in: Hewage, Chaminda, Nawaf, Liqaa and Kesswani, Nishtha eds.
Proceedings of Ninth International Conference on Cyber Security, Privacy in Communication Networks (ICCS 2023).
ICCS 2023.
Lecture Notes in Networks and Systems
, vol.1032
Singapore:
Springer Singapore,
pp. 269-293.
10.1007/978-981-97-3973-8_17
|
Abstract
In this age of digital transformation, more and more businesses rely on technology, making it the heart of most businesses. The rapid development of digital technologies has significantly changed security perspectives and increased the risk of cyberthreats. The nature of cyberthreats and attacks has changed, and cyberattacks are now more frequent, complex, and target-orientated. At the same time, many busi-nesses still lack the necessary knowledge to defend against them. Researchers are examining attackers’ strategies for compromising devices to address the knowledge gap between cybercriminals and the average person. Honeypots offer a solution by tracking attackers’ activities. These cybersecurity tools attract and monitor unautho-rized access attempts and reveal attackers’ methods and motives. Despite their value, honeypots are eventually identified by the attackers, leading to this study’s focus on presenting an architecture that contains an adaptive honeypot algorithm and network traffic classifier. The network classifier model is trained through machine learning algorithms to classify inbound network traffic as malicious or benign. Furthermore, if the network traffic is benign it is aimed to be redirected to the organization’s network and if it is classified as malicious it will be redirected to the honeypot. Additionally, this research also involves creating an algorithm for developing adaptive honey-pots algorithm using reinforcement learning approaches such as Q-learning, which would aid the honeypot to become adaptable, while explaining the whole process in detail. Lastly, this study seeks to train the algorithm and validate the reinforced learning algorithm’s efficiency based on rewards, offering a comprehensive strategy to enhance honeypot functionality and cybersecurity measures.
| Item Type: | Conference or Workshop Item - published (Paper) |
|---|---|
| Date Type: | Publication |
| Status: | Published |
| Schools: | Schools > Computer Science & Informatics |
| Subjects: | Q Science > QA Mathematics > QA75 Electronic computers. Computer science |
| Publisher: | Springer Singapore |
| ISBN: | 978-981-97-3972-1 |
| Date of First Compliant Deposit: | 29 July 2026 |
| Date of Acceptance: | 2023 |
| Last Modified: | 30 Jul 2026 09:45 |
| URI: | https://orca.cardiff.ac.uk/id/eprint/188606 |
Actions (repository staff only)
![]() |
Edit Item |





Dimensions
Dimensions