Security Orchestration, Automation, and Response Engine for Deployment of Behavioural Honeypots
Upendra Bartwal, Subhasis Mukhopadhyay, Rohit Negi, Sandeep Shukla

TL;DR
This paper introduces a SOAR engine that dynamically deploys behavioral honeypots within networks, significantly improving attacker engagement time and detection capabilities compared to static honeypots.
Contribution
The paper presents a novel SOAR engine that automates and orchestrates the deployment of behavioral honeypots based on attacker behavior, enhancing cybersecurity defenses.
Findings
Detected 7823 attacks and 965 DDoS packets in four days
Dynamically orchestrated honeypots 40 times during the experiment
Increased attacker engagement time from 102 to 3148 seconds
Abstract
Cyber Security is a critical topic for organizations with IT/OT networks as they are always susceptible to attack, whether insider or outsider. Since the cyber landscape is an ever-evolving scenario, one must keep upgrading its security systems to enhance the security of the infrastructure. Tools like Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), Threat Intelligence Platform (TIP), Information Technology Service Management (ITSM), along with other defensive techniques like Intrusion Detection System (IDS), Intrusion Protection System (IPS), and many others enhance the cyber security posture of the infrastructure. However, the proposed protection mechanisms have their limitations, they are insufficient to ensure security, and the attacker penetrates the network. Deception technology, along with Honeypots, provides a false sense of vulnerability…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
Methodstravel james
