Abstract
Cybercrime is on the rise due to an increase in cyberattacks such as brute-force attacks, network scanning, and malware deployment, leading to a greater need for network security monitoring. Traditional systems rely heavily on signatures and alerts and therefore often do not provide valuable insight into the attacker's behavior. Implementing deception-based security with honeypots enables securityprofessionals to collect data on attacker activity. This paper presents an architecture for deception-based intrusion detection using a honeypot, a Network Intrusion Detection System (NIDS), centralized logging, Security Information and Event Management (SIEM), threat intelligence enrichment, and automated response mechanisms. Using the Cowrie honeypot, Suricata NIDS, syslog, and Wazuh SIEM, the architecture communicates attacker information to one centralized logging repository. A distinct feature is an attacker profiling module that classifies attacker behavior by executed commands and automatically blocks malicious IP addresses. The system uses multiple open-source tools to simulate a small-scale Security Operations Centre (SOC).