High-Interaction Honeypots in Cyber Deception: Evolution, Design, Deployment, and Future Trends
Animaw Kerie Aseres, Solomon Zemene Melese, Asrat Mulatu Beyene, Lemlem Kassa · IEEE Access · 2026
The rapid evolution of cyber threats necessitates robust, adaptive mechanisms to detect, analyze and mitigate malicious activities targeting networks and systems. High-interaction honeypots (HIHPs) have emerged as pivotal tools in cyber deception, offering detailed insights into attacker tactics, techniques, and procedures (TTPs). This review employs a mixed-methods approach, combining systematic and non-systematic methodologies to synthesize existing knowledge on the evolution, design, deployment, evaluation, challenges and future directions of HIHPs. It presents a statistical analysis, revealing critical correlations that inform optimal architecture and deployment strategies. The superior capabilities of HIHPs in addressing sophisticated threats, such as Advanced Persistent Threats (APTs), are also highlighted. 163 papers were explored; subsequently, 81 were deeply evaluated using custom criteria across four rounds. The first round evaluated related surveys. The second round conducted a systematic literature review to analyze interdependencies among various design, deployment, and evaluation metrics within the HIHP development lifecycle using the Iterative Surveying Algorithm. The third round examined the evolutionary development of HIHP projects over the past 15 years, while the fourth round studied recent emerging trends in HIHP research. This research introduces two key contributions: the HONEYLIFECYCLE Framework for standardized HIHP lifecycle management, and the Adaptive High-Interaction Honeypot (AHIH) Framework, which leverages machine learning and artificial intelligence to dynamically engage threats. Identifying significant research gaps, the review proposes future directions to enhance the effectiveness and operational efficiency of HIHPs. By closing these gaps and leveraging advanced technologies, HIHPs can significantly improve the detection, analysis, and mitigation of emerging cyber threats, contributing to a more secure digital landscape.