Journal: IPSI Transactions on Internet Research


The Place and Role of Honeypot Solutions
in Network Intrusion Detection Systems

Author: Čisar, Petar


View PDF Cite this article

Abstract

As cyber threats continue to evolve, organizations increasingly rely on advanced security mechanisms to detect and mitigate malicious activities. Honeypots, as deceptionbased security tools, play a crucial role in Network Intrusion Detection Systems (NIDS) by defrauding attackers and collecting intelligence on their tactics. This survey provides a systematic and comprehensive review of honeypot solutions within modern NIDS, offering an in-depth categorization of different types of honeypots, examining their integration with NIDS, and evaluating their effectiveness in detecting sophisticated cyberattacks. In addition to presenting an overview of existing honeypot technologies, this survey critically analyzes recent advances and identifies key challenges, including deployment complexities, evasion techniques, and resource constraints. By synthesizing findings from a wide range of research studies, this work highlights the current state of honeypot technology and its role in contemporary cybersecurity strategies. Furthermore, emerging trends such as AI-driven honeypots, the integration of large language models (LLMs), deception-based cyber defense, and cloud-based implementations are explored. This survey also synthesizes findings from recent review studies, providing a structured overview of the latest advances in honeypot-based security solutions.


Keywords

cybersecurity, deception, honeypot, intrusion detection system


Published in: IPSI Transaction on Internet Research (Volume: 21, Issue: 2)
Publisher: IPSI, Belgrade

Date of Publication: Julz 1, 2025

Open Access: CC-BY-NC-ND
DOI: 10.58245/ipsi.tir.2503.11

Pages: 107 - 121

ISSN: 1820 - 4503



References

1. Honeyd, Accessed: 20 Feb 2025, Available: https://www.honeyd.org/

2. The Honeynet Project, Accessed: 20 Feb 2025, Available: https://www.honeynet.org/

3. Artail, H., Safa, H., Sraj, M., Kuwatly, I., Al-Masri, Z., “A hybrid honeypot framework for improving intrusion detection systems in protecting organizational networks”, Computers & Security, vol. 25, no. 4, 2006, pp. 274-288. https://doi.org/10.1016/j.cose.2006.02.009

4. Kandanaarachchi, S., Ochiai, H., Rao, A., “Honeyboost: Boosting honeypot performance with data fusion and anomaly detection”, Expert Systems with Applications, vol. 201, 117073, 2022. https://doi.org/10.1016/j.eswa.2022.117073

5. Franco, J., Aris, A., Canberk, B., Uluagac, A. S., “A survey of honeypots and honeynets for Internet of Things, Industrial Internet of Things, and cyber-physical systems”, IEEE Communications Surveys & Tutorials, vol. 23, no. 4, 2021, pp. 2351-2383. https://doi.org/10.1109/COMST.2021.3106669

6. Lin, H., “SDN-based in-network honeypot: Preemptively disrupt and mislead attacks in IoT networks”, 1st International Workshop on Security and Privacy for the Internet-of-Things (IoTSec), Apr. 17-20, 2018. https://arxiv.org/abs/1905.13254

7. Fan, W., Du, Z., Smith-Creasey, M., Fernández, D., “HoneyDOC: An efficient honeypot architecture enabling all-round design”, IEEE Journal on Selected Areas in Communications, vol. 37, no. 3, 2019, pp. 683-697. https://doi.org/10.1109/JSAC.2019.2894307

8. Nawrocki, M., Wählisch, M., Schmidt, T., Keil, C., Schönfelder, J., “A survey on honeypot software and data analysis”, 2016. https://doi.org/10.48550/arXiv.1608.06249

9. Srinivasa, S., Pedersen, J.M., Vasilomanolakis, E., “Gotta catch 'em all: A multistage framework for honeypot fingerprinting”, Digital Threats: Research and Practice, vol. 4, no.3, 2023, pp. 1-28. https://doi.org/10.1145/3584976

10. Hakim, M. A., Aksu, H., Uluagac, A. S., Akkaya, K., “UPoT: A honeypot framework for UPnP-based IoT devices”, IEEE 37th International Performance Computing and Communications Conference (IPCCC), Orlando, FL, USA, 2018, pp. 1-8. https://doi.org/10.1109/PCCC.2018.8711321

...

×

Čisar, Petar

Petar Čisar graduated from the University of Belgrade School of Electrical Engineering and earned a PhD in Information Sciences from the University of Novi Sad. He is a full professor at the University of Criminal Investigation and Police Studies, Belgrade, and an associate professor at John von Neumann University, Kecskemét. A member of the International Society for the Implementation of Fuzzy Theory in Budapest and an external member of the Hungarian Academy of Sciences and Arts, he has authored over 150 scientific papers with more than 400 independent citations. His research focuses on computer and telecommunication networks, network security, digital forensics, and AI implementations.
Emails: petar.cisar@kpu.edu.rs, csiszar.peter@nje.hu, ORCID: 0000-0001-8009-3347

×

Cite this article

Čisar, Petar
"The Place and Role of Honeypot Solutions in Network Intrusion Detection Systems",
IPSI Transactions on Internet Research, vol. 21(2), pp. 107 - 121, 2025. https://doi.org/10.58245/ipsi.tir.2503.11