International Journal of Network Security & Its Applications (IJNSA)
ISSN: 0974 - 9330 (Online); 0975 - 2307 (Print)
Webpage URL: https://airccse.org/journal/ijnsa.html
Empirical Telemetry-based Metrics for Evaluating Honeypot Realism and Deception Effectiveness
Teresita Noelia Nunez Migliorisi, University of Delaware, USA
Abstract
Honeypots remain critical tools for cyber deception, adversarial observation, and proactive threat intelligence. However, despite decades of development, the field still lacks a standardized and empirically validated framework for assessing deception effectiveness. Existing studies rely heavily on raw connection counts or ad hoc indicators, limiting reproducibility, comparability, and operational relevance. This paper presents a telemetry-driven methodology for evaluating honeypot realism and deception effectiveness across measurable behavioral dimensions. Using both a baseline cloud honeynet and an Enhanced Realism-Driven Honeynet (ERDH) modeled on a healthcare research environment, it's empirically demonstrated that domain-consistent realism significantly increases attacker dwell time, interaction depth, behavioral diversity, and malware family richness.
Keywords
Honeypots, Deception, Engagement, Telemetry, Metrics, Evaluation, Standardization, NIST
Original Source URL: https://aircconline.com/ijnsa/V18N1/18126ijnsa01.pdf
Volume URL: https://airccse.org/journal/jnsa26_current.html


