Honeypot-Based Intrusion Detection with SIEM and Automated Response
DOI:
https://doi.org/10.63503/acset.148Keywords:
Honeypot, IDS, SIEM, Wazuh, Suricata, Cowrie, Deception Security, Threat Intelligence, SOC, Log CorrelationAbstract
Cybercrime is on the rise due to an increase in cyberattacks such as brute-force attacks, network scanning, and malware deployment, leading to a greater need for network security monitoring. Traditional systems rely heavily on signatures and alerts and therefore often do not provide valuable insight into the attacker's behavior. Implementing deception-based security with honeypots enables securityprofessionals to collect data on attacker activity. This paper presents an architecture for deception-based intrusion detection using a honeypot, a Network Intrusion Detection System (NIDS), centralized logging, Security Information and Event Management (SIEM), threat intelligence enrichment, and automated response mechanisms. Using the
Cowrie honeypot, Suricata NIDS, syslog, and Wazuh SIEM, the architecture communicates attacker information to one centralized logging repository. A distinct feature is an attacker profiling module that classifies attacker behavior by executed commands and automatically blocks malicious IP addresses. The system uses multiple open-source tools to simulate a small-scale Security Operations Centre (SOC).
References
[1] Wazuh, Inc., “Wazuh Open Source Security Platform Documentation,” 2026.
[2] Open Information Security Foundation, “Suricata NIDS Documentation,” 2026.
[3] M. Oosterhof, “Cowrie SSH/Telnet Honeypot,” 2026.
[4] AbuseIPDB, “AbuseIPDB Threat Intelligence API,” 2026.
[5] The MITRE Corporation, “MITRE ATT&CK Framework,” 2026.
[6] P. Kapatel et al., “AI-Powered Intrusion Detection System with Honeypot Integration,” Int. J. Intelligent Information Systems, vol. 14, no. 4, Sep. 2025.
[7] R. Pratama, D. Prayama, and F. Nova, “Integration of Wazuh and Suricata with Telegram for Enhanced Threat Detection,” Int. J. Research and Innovation in Social Science, vol. 9, no. 2, 2025.
[8] Z. Morić, V. Dakić, and D. Regvart, “Advancing Cybersecurity with Honeypots and Deception Strategies,” Informatics, vol. 12, no. 1, p. 14, Jan. 2025.
[9] L. Harani et al., “A Practical Honeypot-Based Threat Intelligence Framework for Cyber Defence in the Cloud,” arXiv preprint arXiv:2512.05321, Dec. 2024.
[10] S. Sikdar, P. Basu, and M. Kule, “Honeypot Deception: A Clever Approach of Web Intrusion Detection and Prevention,” in Proc. ICFCS, Springer, 2024, pp. 141–152.
[11] A. Javadpour et al., “A Comprehensive Survey on Cyber Deception Techniques to Improve Honeypot Performance,” Computers & Security, vol. 140, p. 103718, Mar. 2024.
[12] B. Alrashdan et al., “Network Anomaly Detection using Artillery Honeypot and Wazuh SIEM,” ResearchGate, 2024.
[13] I. Balogh et al., “Honeypots in Cybersecurity: Analysis, Evaluation and Importance,” Preprints.org, Aug. 2024.
[14] M. S. Yusof, H. Haron, and N. Omar, “Deployment of Honeypot and SIEM Tools for Cyber Security Education in UiTM,” ResearchGate, Oct. 2022.
[15] H. Hindy et al., “Research Trends in Network-Based Intrusion Detection Systems: A Review,” IEEE Access, vol. 9, pp. 157439–157479, Nov. 2021.
[16] K. Scarfone and P. Mell, “Guide to Intrusion Detection and Prevention Systems (IDPS),” NIST Special Publication 800-94, Feb. 2007.
[17] L. Spitzner, Honeypots: Tracking Hackers. Boston, MA: Addison-Wesley, 2003.
Published
Conference Proceedings Volume
Section
License
Copyright (c) 2026 Adroid Conference Series: Engineering and Technology

This work is licensed under a Creative Commons Attribution 4.0 International License.