Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
The Role of Honeypots in Enhancing Network Intrusion Detection Against Emerging Cyber  Threats
Blekinge Institute of Technology, Faculty of Computing, Department of Computer Science.
2025 (English)Independent thesis Basic level (professional degree), 12 credits / 18 HE creditsStudent thesis
Abstract [en]

Background. Conventional NIDS struggle with the detection of zero-day attacks and Advanced Persistent Threats (APTs). The detection methods based on signatures cannot identify new attacks, and the majority of the detection schemes based on the concept of anomalies have too many false positives. There may be an interesting possibility of improving the detection of threats with the help of honeypots that deceive cyber attackers.

Objectives. The study will analyze how honeypots may be incorporated with NIDS to better identify zero-day attack activity and APT activity. Additionally, the study will examine the performance of hybrid systems relative to the performance of NIDS on its own.

Methods. A stepwise approach based on the construction of the search string, inclusion and exclusion criteria, and a qualitative approach of synthesizing the results of various informative articles published between the years of 2015 and 2025 regarding the performance of integrating designs was used.

Results. The results reveal that honeypot systems contribute behavioral and context knowledge that strengthens the detection functions of the NIDS system. Consequently, NIDS/honeypot hybrid networks have reported improved detection rates and shorter times of detection of attack events compared with conventional NIDS systems.

Conclusions. The results conclude that the incorporation of the deception technology component into the network intrusion detection system results in the formulation of a stronger and more active defense system. Incorporation of the component brings about an issue; nonetheless, the hybrid system exhibits certain advantages.

Place, publisher, year, edition, pages
2025. , p. 32
Keywords [en]
Honeypots, NIDS, APTs, Zero-day, Network security
National Category
Computer and Information Sciences
Identifiers
URN: urn:nbn:se:bth-28981OAI: oai:DiVA.org:bth-28981DiVA, id: diva2:2020616
Subject / course
DV1583 Degree Project for Bachelor of Science in Engineering Computer Science
Educational program
Bachelor of Science in Engineering: Computer Security
Supervisors
Examiners
Available from: 2025-12-15 Created: 2025-12-11 Last updated: 2025-12-16Bibliographically approved

Open Access in DiVA

fulltext(592 kB)183 downloads
File information
File name FULLTEXT01.pdfFile size 592 kBChecksum SHA-512
5f3aa952b05428d628c4462cebc17b33254d4212103d8588c206544c75b2c68e5a8ff7952f05bd7df94046711f024864b217df9d03657371fbc2b99daa2d8881
Type fulltextMimetype application/pdf

By organisation
Department of Computer Science
Computer and Information Sciences

Search outside of DiVA

GoogleGoogle Scholar
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 908 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf