The Place and Role of Honeypot Solutions in Network Intrusion Detection Systems
Petar Čisar · IPSI Transactions on Internet Research · 2025
As cyber threats continue to evolve, organizations increasingly rely on advanced security mechanisms to detect and mitigate malicious activities. Honeypots, as deceptionbased security tools, play a crucial role in Network Intrusion Detection Systems (NIDS) by defrauding attackers and collecting intelligence on their tactics. This survey provides a systematic and comprehensive review of honeypot solutions within modern NIDS, offering an in-depth categorization of different types of honeypots, examining their integration with NIDS, and evaluating their effectiveness in detecting sophisticated cyberattacks. In addition to presenting an overview of existing honeypot technologies, this survey critically analyzes recent advances and identifies key challenges, including deployment complexities, evasion techniques, and resource constraints. By synthesizing findings from a wide range of research studies, this work highlights the current state of honeypot technology and its role in contemporary cybersecurity strategies. Furthermore, emerging trends such as AI-driven honeypots, the integration of large language models (LLMs), deception-based cyber defense, and cloud-based implementations are explored. This survey also synthesizes findings from recent review studies, providing a structured overview of the latest advances in honeypot-based security solutions.