X-POT: Adaptive Observation and Empirical Analysis of Emerging Cyber Attacks Targeting Various IoT Devices

Ryu Kuki, Takayuki Sasaki, Aamir H. Bokhari, Seiya Kato, Rui Tanabe, Katsunari Yoshioka, Tsutomu Matsumoto · IEICE Transactions on Fundamentals of Electronics Communications and Computer Sciences · 2026

Diverse digital devices are being manufactured daily to communicate over the Internet as the Internet of Things (IoT). Though cyber-attacks have been studied using honeypots for several years, they now need to evolve in order to realize interactivity and diversity that is becoming a necessity due to the mass production of IoT. Therefore, this paper proposes an adaptive honeypot (X-POT) framework that can emulate diverse IoT devices while maintaining a certain level of interactivity through an empirical study. Attacks on all TCP ports were observed first and then an internet-wide scan of relevant hosts was conducted to obtain responses from the real devices. These responses were then adapted as honeypot responses for observing attacks on vulnerable IoT devices. The X-POT framework was then operated for 68 months by applying it to an internet-connected HTTP honeypot. Over 327 million HTTP requests were observed on all TCP ports. We performed tagging to the attacks observed by X-POT and confirmed that attacks targeting diverse services were also captured successfully, including 331 types of exploits with Remote Code Execution (RCE) attacks. Compared to a honeypot with a static response, X-POT observed 77 exploits that were not observed by the static response honeypot. The captured malware datasets are available for sharing on request with interested researchers for further use in future studies.

Read the paper · More papers on PaperTik