Cardiff University | Prifysgol Caerdydd ORCA
Online Research @ Cardiff 
WelshClear Cookie - decide language by browser settings

Creating an adaptive defense architecture using an adaptive honeypot algorithm and network traffic classifier

Matcheswala, Mohammed Shaad Mehboob and Javed, Amir ORCID: https://orcid.org/0000-0001-9761-0945 2024. Creating an adaptive defense architecture using an adaptive honeypot algorithm and network traffic classifier. Presented at: ICCS 2023, Cardiff, Uk, 11-12 December 2023. Published in: Hewage, Chaminda, Nawaf, Liqaa and Kesswani, Nishtha eds. Proceedings of Ninth International Conference on Cyber Security, Privacy in Communication Networks (ICCS 2023). ICCS 2023. Lecture Notes in Networks and Systems , vol.1032 Singapore: Springer Singapore, pp. 269-293. 10.1007/978-981-97-3973-8_17

Full text not available from this repository.

Abstract

In this age of digital transformation, more and more businesses rely on technology, making it the heart of most businesses. The rapid development of digital technologies has significantly changed security perspectives and increased the risk of cyberthreats. The nature of cyberthreats and attacks has changed, and cyberattacks are now more frequent, complex, and target-orientated. At the same time, many busi-nesses still lack the necessary knowledge to defend against them. Researchers are examining attackers’ strategies for compromising devices to address the knowledge gap between cybercriminals and the average person. Honeypots offer a solution by tracking attackers’ activities. These cybersecurity tools attract and monitor unautho-rized access attempts and reveal attackers’ methods and motives. Despite their value, honeypots are eventually identified by the attackers, leading to this study’s focus on presenting an architecture that contains an adaptive honeypot algorithm and network traffic classifier. The network classifier model is trained through machine learning algorithms to classify inbound network traffic as malicious or benign. Furthermore, if the network traffic is benign it is aimed to be redirected to the organization’s network and if it is classified as malicious it will be redirected to the honeypot. Additionally, this research also involves creating an algorithm for developing adaptive honey-pots algorithm using reinforcement learning approaches such as Q-learning, which would aid the honeypot to become adaptable, while explaining the whole process in detail. Lastly, this study seeks to train the algorithm and validate the reinforced learning algorithm’s efficiency based on rewards, offering a comprehensive strategy to enhance honeypot functionality and cybersecurity measures.

Item Type: Conference or Workshop Item - published (Paper)
Date Type: Publication
Status: Published
Schools: Schools > Computer Science & Informatics
Subjects: Q Science > QA Mathematics > QA75 Electronic computers. Computer science
Publisher: Springer Singapore
ISBN: 978-981-97-3972-1
Date of First Compliant Deposit: 29 July 2026
Date of Acceptance: 2023
Last Modified: 30 Jul 2026 09:45
URI: https://orca.cardiff.ac.uk/id/eprint/188606

Actions (repository staff only)

Edit Item Edit Item