AI-Powered Threat Intelligence and Cyber Deception: Integrating Honeypot Networks with Machine Learning for Early Detection of Advanced Persistent Threat Campaigns

Rahul K Sinha, Neha P Kumari

Abstract


Advanced Persistent Threat (APT) campaigns — sophisticated, multi-stagecyber intrusion operations conducted by well-resourced threat actors (nation-state groups, organised cybercrime syndicates) over extended periods with specific intelligence, sabotage, or financial objectives — represent the highest-impact category of cyber threats facing government and critical infrastructure organisations. APT operations are specifically designed to evade conventional signature-based and rule-based detection mechanisms by using novel tools, living-off-the-land techniques that leverage legitimate system utilities, low-and-slow reconnaissance that generates sub-threshold traffic volumes, and encrypted command-and-control communications that bypass deep packet inspection. Traditional SIEM (Security Information and Event Management) deployments typically detect APT campaigns after a mean dwell time of 204 days (Mandiant M-Trends 2023), by which point the threat actor has already completed their primary objectives. This study proposes and evaluates a hybrid cyber defense framework combining distributed honeypot networks — simulated high-fidelity target systems designed to attract and record attacker interactions — with a supervised machine learning classifier trained on honeypot interaction telemetry to detect APT-characteristic behavioural patterns across five APT campaign types. In 30 simulated APT campaign scenarios per type conducted in an isolated Jharkhand cybersecurity research testbed, the AI+Honeypot hybrid system reduced mean detection time by 84.8–96.5% versus a traditional SIEM baseline: C2 beaconing detection dropped from 96.8 to 3.4 hours (96.5% reduction), credential harvesting from 72.4 to 4.2 hours (94.2%), and lateral movement from 124.6 to 8.6 hours (93.1%). Random Forest was the best-performing classification algorithm on honeypot interaction features (F1 94.2%), significantly outperforming rule-based detection (F1 62.4%) on novel APT variant scenarios. KEYWORDS: Honeypot, Advanced persistent threat, APT detection, Cyberdeception, Threat intelligence, Machine learning, SIEM, Cyber defense,Jharkhand, Random Forest, Lateral movement, C2 detection

Full Text:

PDF 1-11

Refbacks

  • There are currently no refbacks.