Utvärdering av avvägningen mellan cybersäkerhetsunderrättelsers noggrannhet och dataminimering : En jämförande studie av SSH-honeypotarkitekturer hos olika molnleverantörer
Emre Mengütay, Amer Shikh-Alzor · Diva portal (Dalarna University Library) · 2026
This thesis evaluates the trade-off between cyber threat intelligence fidelity and dataminimization that is compliant with GDPR, in SSH honeypot across two different cloudproviders. In this study two identical Cowrie medium-interaction SSH honeypot weredeployed on Google Cloud Provider and Oracle Cloud Infrastructure over a seven day periodto compare time-to-discovery, attack volume and the analytical impact of different IPminimization strategies. The results show that the Google Cloud honeypot was discoveredfaster while the Oracle Cloud recorded a substantially higher total attack volume. To evaluate the utility trade-off the collected IP addresses were transformed using /24masking, /16 masking and salted-hash pseudonymization. The results show that /24 maskinghad limited loss to distinguishability while /16 masking had substantial utility loss and falsecorrelation due to data collisions. However, salted-hashing pseudonymization preserved100% of distinguishability and recurrence tracking in both datasets. The study concludes that,within the scope of this experiment, a Cowrie-based SSH honeypot architecture combinedwith salted-hash pseudonymization provides the most suitable balance between actionablethreat intelligence and GDPR-aligned data minimization for SME-oriented deployment. Theresults also indicate that cloud providers affect both discovery speed and attack volumemaking choice of deployment environment an important factor to consider.