Multi-Tier Honeypot for Resilient Network Security

Khaled Salama, Nader Atef Sedeek, Ahmed Bendary, Amr Ashry, Ashraf D. Elbayoumy · 2025

The rapid evolution of cyber threats demands advanced defense mechanisms beyond traditional perimeter-based security models. Conventional firewalls and intrusion detection systems struggle to detect zero-day attacks. In this paper, we propose a multi-tier honeypot architecture combining signature-based anomaly detection and Network Access Control Systems to improve network security. The proposed architecture aims to improve the overall security by redirecting suspicious traffic to a multi-tier honeypot structure, disrupting reconnaissance phases, and analyzing adversarial behavior. The proposed architecture effectively acts as a strong security model in both proactive and post-intrusion phases. Experimental validation demonstrates that the proposed architecture effectively neutralizes distributed denial-of-service attacks, reconnaissance attempts, and digital forensics. In addition, it improves IPS detection effectiveness by 49% compared to traditional IPS solutions.

Read the paper · More papers on PaperTik