Advance Threat Detection Using Machine Learning Techniques With Ssh Honeypot An Integrated Approach

C Manoj Kumar, Alok Kumar, B. S. Kiruthika Devi · 2025

Cybersecurity threats have become increasingly sophisticated, with attackers frequently targeting SSH services to gain unauthorized access to critical systems. Traditional security measures often fall short in identifying and mitigating these advanced attacks. This project's primary goal is to create an SSH honeypot which includes machine learning methods to improve the identification and examination of harmful activity. This issue is crucial to solve because current security solutions cannot adapt to and identify novel attack patterns in real-time dynamically. The gaps in existing work include the limited use of machine learning for real-time analysis of honeypot data and the need for more sophisticated feature extraction methods to improve detection accuracy. To address these gaps, we deploy the Cowrie SSH honeypot to collect detailed logs of attack attempts. In this we are using Kaggle honeypot dataset and then preprocess this data, extract relevant features, and label data into malicious and benign, after that we apply machine learning models to identify among categorize harmful activity, including Random Forest, LightGBM, SVM, XGBoost, Naive Bayes, and decision trees. The enhanced precision along with promptness of attack detection, which offers a proactive defense mechanism against changing cyberthreats, are the project's main contributions. This approach transforms raw security data into actionable intelligence, enhancing the overall cybersecurity posture.

Read the paper · More papers on PaperTik