Simulated Attacks, Results, and Analysis
Akshay Mudgal · 2026
This chapter presents an empirical examination of the machine learning intrusion detection system based on a hybrid honeypot model via simulated adversarial situations. Four typical attack categories—denial of service (DoS), SQL injection, phishing, and ransomware—were implemented in controlled environments to assess detection capability, response time, and robustness. In-depth examination reveals the system’s capability to identify volumetric anomalies, semantic inconsistencies in database queries, behavioral anomalies in phishing messages, and encryption-based ransomware trends. Findings show uniformly strong detection performance, with accuracy levels between 94.6% for phishing and 98.1% for ransomware, while maintaining false-positive rates under 3% in every category. Precision, recall, and F1 scores validate resilience, with typical detection latency below 15 seconds for the majority of attack vectors. The research emphasizes the importance of multimodal telemetry and Big Data analysis in providing context for alerts, facilitating forensic reconstruction, and decreasing the workload for analysts. Through the analysis of results against established IDS benchmarks, the chapter finds that hybrid architectures greatly surpass conventional rule-based systems, providing predictive, adaptive, and explainable threat identification. The results provide substantial support for the practical implementation of honeypot-enhanced, AI-powered IDSs as a fundamental element of contemporary cybersecurity practices.