Dynamic Honeypot Deployment for Enhanced Cybersecurity: Practical Implementation and Evaluation with Adaptive Address Switching

Ghaith Shaqra, Mohammad Aljuneidi · 2025

This paper presents a dynamic honeypot framework designed to overcome the limitations of static honeypots by automatically altering the honeypot's network identity, including MAC address, IP address, hostname, and cryptographic keys-to evade attacker detection. The proposed system integrates open-source tools such as Snort for intrusion detection, OpenCanary for honeypot emulation, Vector for log forwarding, and the Elastic Stack for real-time analysis and visualization. Operating as a closed-loop system, the framework adapts based on threat intelligence inputs. Evaluation results demonstrate a 239% increase in mean time-to-detection and a 50% reduction in false positives compared to static honeypots. This research offers a scalable, cost-effective, and open-source solution for proactive network defense, advancing the state of adaptive deception techniques.

Read the paper · More papers on PaperTik