Skip to main navigation Skip to search Skip to main content

Toward Realistic and Efficient Cyber Deception

  • Hind Alrubaish
  • , Walid Aljoby*
  • , Ahmed Aldeek
  • , Mohammed Alkubaish
  • , Daisuke Mashima
  • *Corresponding author for this work

Research output: Contribution to journalArticlepeer-review

Abstract

Honeypots are defensive mechanisms that deceive adversaries by deploying fabricated assets, systems, data, and credentials, as decoys or lures within a network. Existing honeypot frameworks often integrate open-source projects (e.g., Honeyd, Cowrie) to emulate common network services such as SSH and HTTP, which frequently serve as initial vectors of exploitation for adversaries. However, honeypot practical effectiveness remains constrained by the challenge of high-fidelity, i.e., accurately modeling the state space of real services, at reasonable resource cost. In the absence of adversary-centric fidelity evaluations and resource-aware deployment baselines, decoys are easily fingerprinted, thereby degrading the quality of threat intelligence and wasting valuable computational, memory, and address-space resources. We develop a quantitative framework using a honeypot test suite grounded in the MITRE ATT and CK framework and containerized resource benchmarking to address these gaps. Experiments were conducted across 15 honeypots covering the most common network services, including SSH, FTP, SMTP, HTTP, and DNS, with three distinct honeypot implementations evaluated per service. We analyzed the honeypots' responses against real system implementations to derive a quantitative realism score. Furthermore, we compared the realism score of each honeypot with its resource utilization in terms of CPU, memory, and response time. Finally, we identified the common fidelity breaches observed in each honeypot implementation. We further propose a refined honeypot taxonomy that align deception quality with resource-aware operation. To our knowledge, this is the first work to jointly provide a quantitative ATT&CK-mapped realism score, a cross-protocol discriminative test suite, and a containerized resource-deviation analysis to support the selection and deployment of realistic and low-overhead honeypots.

Original languageEnglish
Pages (from-to)574-586
Number of pages13
JournalIEEE Open Journal of the Computer Society
Volume7
DOIs
StatePublished - 2026

Bibliographical note

Publisher Copyright:
© 2020 IEEE.

Keywords

  • Fingerprinting
  • MITRE ATT and CK
  • efficiency
  • fidelity
  • honeypots
  • realism

ASJC Scopus subject areas

  • General Computer Science

Fingerprint

Dive into the research topics of 'Toward Realistic and Efficient Cyber Deception'. Together they form a unique fingerprint.

Cite this