DYNAMIT: K-Medoids-Based Machine Learning for Scalable Honeynet Deception and Intelligent Threat Profiling

Yan Maraden, Zaki Ananda, I Gde Dharma Nugraha, Riri Fitri Sari · Electronics · 2026

As the internet and complex network infrastructures continue to expand, so does the threat of sophisticated cyberattacks, compelling organizations to adopt advanced proactive defenses. A cornerstone of these defensive strategies is the honeypot. However, existing dynamic solutions often rely on reactive deployment or centroid-based clustering (e.g., K-Means), which mathematically yields invalid, unrealistic host profiles. Because intelligent threat detection increasingly relies on high-fidelity honeypot data to analyze adversary tactics, deploying easily fingerprinted decoys fundamentally undermines downstream AI-driven defense mechanisms. To overcome this limitation, we propose DYNAMIT, an intelligent honeynet deployment system that resolves the centroid validity problem by utilizing the unsupervised K-Medoids algorithm. By combining K-Medoids with a novel hybrid Manhattan-Jaccard distance metric, DYNAMIT selects valid, existing hosts as templates based on categorical hardware and binary software similarities. The system then leverages containerization and network virtualization to simulate multiple realistic, internet-facing honeypot profiles from a single physical host, ensuring the decoys remain indistinguishable from legitimate targets. Our evaluation demonstrates that DYNAMIT accurately captures the intended number of clusters with a low relative error (18.75% for 40 hosts and 6.625% for 1000 hosts) while maintaining minimal resource overhead, establishing it as a highly scalable and robust data-generation prerequisite for modern intelligent network security.

Read the paper · More papers on PaperTik