Understanding Honeypots: Observing Malicious Activities Over Telnet

Shereen S. Ismail, Salah Dandan, Mark King · 2025

A honeypot is a security mechanism designed to detect, deflect, or study cyber threats by mimicking real systems and luring attackers into engaging with it. In this paper, we reviewed various honeypot software, summarizing their features and use cases. In addition, we studied a honeypot security system deployed at Merit Network, designed for research purposes to analyze and monitor malicious activities. This setup collects approximately 110MB of network traffic data per hour, enabling continuous monitoring throughout the day. We focused the study on Telnet protocol, which is often targeted by botnets and malware. We customized the collected data based on Telenet service using destination ports 23 and 2323 and packet payload. By analyzing the collected data, we investigated attempts to exploit Telnet services and detect malware activities. Through detailed packet inspection and login attempt analysis, we extracted key observations from the collected traffic events, identifying attack patterns and malicious behaviors.

Read the paper · More papers on PaperTik