Metrics-Driven Evaluation and Optimization of Honeypots: Toward Standardized Measures of Deception Effectiveness
Zoltán Aradi, Sándor Bottyán, Eszter Kail, Ernő Rigó, Anna Bánáti · Acta Polytechnica Hungarica · 2025
Honeypots are widely used to study adversary behavior and support enterprise detection, yet their evaluation is fragmented and often qualitative.This paper proposes a unified, metrics-driven framework assessing honeypots across five dimensions-interaction, data quality, resource use, stealth, and fingerprinting resistance-using hard (observable) and soft (context-dependent) indicators.A normalization and weighting pipeline yields composite scores, while methods combining attack automation, anomaly detection, and ATT&CK enrichment enable reproducible comparisons.Case studies span IT, IoT/OT, and ICS/PLC.Benchmarking guidelines and modern datasets are recommended.An integration roadmap positions honeypot telemetry in SIEM-SOAR-CTI with LLM support and ethical guardrails.Standardized metrics and reproducible methods make honeypot studies comparable, operationally useful and fit for continuous improvement.