Abstract
Honeypots are defensive mechanisms that deceive adversaries by deploying fabricated assets, systems, data, and credentials, as decoys or lures within a network. Existing honeypot frameworks often integrate open-source projects (e.g., Honeyd, Cowrie) to emulate common network services such as SSH and HTTP, which frequently serve as initial vectors of exploitation for adversaries. However, honeypot practical effectiveness remains constrained by the challenge of high-fidelity, i.e., accurately modeling the state space of real services, at reasonable resource cost. In the absence of adversary-centric fidelity evaluations and resource-aware deployment baselines, decoys are easily fingerprinted, thereby degrading the quality of threat intelligence and wasting valuable computational, memory, and address-space resources. We develop a quantitative framework using a honeypot test suite grounded in the MITRE ATT and CK framework and containerized resource benchmarking to address these gaps. Experiments were conducted across 15 honeypots covering the most common network services, including SSH, FTP, SMTP, HTTP, and DNS, with three distinct honeypot implementations evaluated per service. We analyzed the honeypots' responses against real system implementations to derive a quantitative realism score. Furthermore, we compared the realism score of each honeypot with its resource utilization in terms of CPU, memory, and response time. Finally, we identified the common fidelity breaches observed in each honeypot implementation. We further propose a refined honeypot taxonomy that align deception quality with resource-aware operation. To our knowledge, this is the first work to jointly provide a quantitative ATT&CK-mapped realism score, a cross-protocol discriminative test suite, and a containerized resource-deviation analysis to support the selection and deployment of realistic and low-overhead honeypots.
| Original language | English |
|---|---|
| Pages (from-to) | 574-586 |
| Number of pages | 13 |
| Journal | IEEE Open Journal of the Computer Society |
| Volume | 7 |
| DOIs | |
| State | Published - 2026 |
Bibliographical note
Publisher Copyright:© 2020 IEEE.
Keywords
- Fingerprinting
- MITRE ATT and CK
- efficiency
- fidelity
- honeypots
- realism
ASJC Scopus subject areas
- General Computer Science
Fingerprint
Dive into the research topics of 'Toward Realistic and Efficient Cyber Deception'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver