Creating an Adaptive Defense Architecture Using an Adaptive Honeypot Algorithm and Network Traffic Classifier
摘要
In this age of digital transformation, more and more businesses rely on technology, making it the heart of most businesses. The rapid development of digital technologies has significantly changed security perspectives and increased the risk of cyberthreats. The nature of cyberthreats and attacks has changed, and cyberattacks are now more frequent, complex, and target-orientated. At the same time, many businesses still lack the necessary knowledge to defend against them. Researchers are examining attackers’ strategies for compromising devices to address the knowledge gap between cybercriminals and the average person. Honeypots offer a solution by tracking attackers’ activities. These cybersecurity tools attract and monitor unauthorized access attempts and reveal attackers’ methods and motives. Despite their value, honeypots are eventually identified by the attackers, leading to this study’s focus on presenting an architecture that contains an adaptive honeypot algorithm and network traffic classifier. The network classifier model is trained through machine learning algorithms to classify inbound network traffic as malicious or benign. Furthermore, if the network traffic is benign it is aimed to be redirected to the organization’s network and if it is classified as malicious it will be redirected to the honeypot. Additionally, this research also involves creating an algorithm for developing adaptive honeypots algorithm using reinforcement learning approaches such as Q-learning, which would aid the honeypot to become adaptable, while explaining the whole process in detail. Lastly, this study seeks to train the algorithm and validate the reinforced learning algorithm’s efficiency based on rewards, offering a comprehensive strategy to enhance honeypot functionality and cybersecurity measures.