DDQN-BASED ADAPTIVE LIGHTWEIGHT HONEYPOT FRAMEWORK FOR INTELLIGENT CYBER THREAT DETECTION IN SMALL AND MEDIUM ENTERPRISES

Fuente: Zenodo
Gespeichert in:
Bibliographische Detailangaben
1. Verfasser: Arshit Rawat
Format: Recurso digital
Sprache:Englisch
Veröffentlicht: Zenodo 2025
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866901387377377280
author Arshit Rawat
author_facet Arshit Rawat
contents <p><em><span>Honeypots serve as deceptive cybersecurity systems that attract and engage attackers, providing valuable insights into their methods within controlled environments. However, traditional honeypots are largely static and passive, making them easily identifiable and ineffective against modern, adaptive cyber threats. Existing adaptive models offer incremental improvements but remain limited by predefined rules or simplified learning mechanisms, restricting their responsiveness to complex and evolving attacks. This paper introduces an RL-Enhanced Adaptive Honeypot that integrates a Dueling Double Deep Q-Network (DDQN)-based decision engine to enable autonomous behavioural adaptation. The system dynamically adjusts its defence posture by analysing attacker activity and environmental metrics represented in a structured state model. Through continuous learning and policy optimization, the honeypot transitions between observation, deception, and mitigation strategies, maintaining an average accuracy of approximately 96% across behavioural prediction and threat intelligence classification tasks. Future work aims to employ simulated multi-stage attack environments to pre-train reinforcement learning agents, fostering the development of self-evolving honeypots capable of real-time, intelligent cyber defence.</span></em></p>
format Recurso digital
id zenodo_https___doi_org_10_5281_zenodo_17802728
institution Zenodo
language eng
publishDate 2025
publisher Zenodo
record_format zenodo
spellingShingle DDQN-BASED ADAPTIVE LIGHTWEIGHT HONEYPOT FRAMEWORK FOR INTELLIGENT CYBER THREAT DETECTION IN SMALL AND MEDIUM ENTERPRISES
Arshit Rawat
<p><em><span>Honeypots serve as deceptive cybersecurity systems that attract and engage attackers, providing valuable insights into their methods within controlled environments. However, traditional honeypots are largely static and passive, making them easily identifiable and ineffective against modern, adaptive cyber threats. Existing adaptive models offer incremental improvements but remain limited by predefined rules or simplified learning mechanisms, restricting their responsiveness to complex and evolving attacks. This paper introduces an RL-Enhanced Adaptive Honeypot that integrates a Dueling Double Deep Q-Network (DDQN)-based decision engine to enable autonomous behavioural adaptation. The system dynamically adjusts its defence posture by analysing attacker activity and environmental metrics represented in a structured state model. Through continuous learning and policy optimization, the honeypot transitions between observation, deception, and mitigation strategies, maintaining an average accuracy of approximately 96% across behavioural prediction and threat intelligence classification tasks. Future work aims to employ simulated multi-stage attack environments to pre-train reinforcement learning agents, fostering the development of self-evolving honeypots capable of real-time, intelligent cyber defence.</span></em></p>
title DDQN-BASED ADAPTIVE LIGHTWEIGHT HONEYPOT FRAMEWORK FOR INTELLIGENT CYBER THREAT DETECTION IN SMALL AND MEDIUM ENTERPRISES
url https://doi.org/10.5281/zenodo.17802728