The Role of Honeypots in Enhancing Network Intrusion Detection Against Emerging Cyber Threats
Al Muselhi, Abdelaziz · KTH Publication Database DiVA (KTH Royal Institute of Technology) · 2025
Background. Conventional NIDS struggle with the detection of zero-day attacks and Advanced Persistent Threats (APTs). The detection methods based on signatures cannot identify new attacks, and the majority of the detection schemes based on the concept of anomalies have too many false positives. There may be an interesting possibility of improving the detection of threats with the help of honeypots that deceive cyber attackers. Objectives. The study will analyze how honeypots may be incorporated with NIDS to better identify zero-day attack activity and APT activity. Additionally, the study will examine the performance of hybrid systems relative to the performance of NIDS on its own. Methods. A stepwise approach based on the construction of the search string, inclusion and exclusion criteria, and a qualitative approach of synthesizing the results of various informative articles published between the years of 2015 and 2025 regarding the performance of integrating designs was used. Results. The results reveal that honeypot systems contribute behavioral and context knowledge that strengthens the detection functions of the NIDS system. Consequently, NIDS/honeypot hybrid networks have reported improved detection rates and shorter times of detection of attack events compared with conventional NIDS systems. Conclusions. The results conclude that the incorporation of the deception technology component into the network intrusion detection system results in the formulation of a stronger and more active defense system. Incorporation of the component brings about an issue; nonetheless, the hybrid system exhibits certain advantages.