Developing a Local Network Security Alert System for Specific Intrusion Attempts Based on Honeypot Technology
Ghaith Shaqra, Wassim Aljuneidi · 2025
The escalating sophistication and volume of cyberattacks targeting local networks present a formidable challenge to organizational cybersecurity. Traditional security mechanisms, often reliant on signature-based detection, struggle to identify novel or evasive threats, leading to detection gaps and high false-positive rates. This research addresses these critical vulnerabilities by proposing, designing, implementing, and rigorously evaluating a novel, comprehensive Security Alert System for Local Area Networks (LANs). The system meticulously integrates a multi-layered deception framework utilizing diverse honeypot technologies (Cowrie for high-interaction SSH, OpenCanary for multi-protocol low-interaction, Pi-hole sinkhole for DNS-based deception, and Snort for real-time intrusion detection/prevention). Centralized log aggregation, analysis, and visualization are achieved through the Elastic Stack (Elasticsearch, Logstash, Kibana), while network segmentation and policy enforcement are managed by a robust PfSense firewall. A custom-developed C# management console, TrapMonitor, serves as the operational nexus, ensuring live connectivity, continuous log processing, automated alerting (via Telegram and email), and real-time firewall integration for dynamic response. Empirical validation through diverse simulated attack scenarios, including brute-force, phishing, port-scanning, and command injection, consistently demonstrated a high detection rate exceeding 90% and an exceptionally low false-positive rate below 2%. Furthermore, performance analysis revealed a minimal network bandwidth overhead of approximately 16.7%, affirming its practical viability for real-time deployment. This system provides a proactive, adaptable, and resource-efficient model for enhancing local network cybersecurity posture, contributing significantly to the fields of intrusion detection, deception technology, and real-time security operations.