Deploying and Analysing Cloud-Based Honeypots for Threat Intelligence: A Practical Approach

Authors

  • Hyginus Chukwuchebe Obi University of Sunderland, United Kingdom Author

DOI:

https://doi.org/10.70882/noun-ijcea.2026.1155

Keywords:

Cloud security, Honeypot, Microsoft Azure, T-Pot, Threat intelligence

Abstract

Firewalls, intrusion detection systems and antivirus tools remain the backbone of most organisational defences, yet all three share a common weakness: they operate on reactive, signature-based logic that struggles to keep pace with attacker behaviour it has not seen before. This paper reports on the deployment and empirical analysis of a cloud-based, multi-service honeypot system built on Microsoft Azure, undertaken as a practical route to generating threat intelligence that is genuinely actionable rather than merely descriptive. The system was built around the T-Pot honeypot framework, combining Cowrie (SSH/Telnet), Dionaea (HTTP and malware capture) and Conpot (ICS/Modbus), and was left exposed to live internet traffic for a continuous five-day observation window. Elasticsearch, Logstash and Kibana processed, indexed and visualised the resulting data. Over the deployment period, 31,547 unique attack attempts were captured from 8,934 distinct IP addresses spanning 67 countries; after post-processing, 26,832 of these were validated for analysis. Mapping the observed behaviour onto the MITRE ATT&CK framework showed that Active Scanning (T1595) accounted for 78% of all activity, Brute Force credential access (T1110) for 15%, and Exploitation for Client Execution (T1203) for the remaining 5%. The deployment sustained a 92% detection rate and 99.8% uptime, at a minimal operational cost that compares favourably with traditional signature-based intrusion detection on all three counts. Taken together, the findings support the view that cloud-based honeypots offer a scalable, low-cost and intelligence-rich complement to conventional security tooling, and are particularly well suited to organisations that want proactive visibility into the live threat landscape rather than a purely reactive posture.

References

Alyas, T., Alissa, K., Alqahtani, M., Faiz, T., Alsaif, S. A., Tabassum, N., & Naqvi, H. H. (2022). Multi-cloud integration security framework using honeypots. Mobile Information Systems, 2022(1), 2600712.

Aslan, Ö., Aktuğ, S. S., Ozkan-Okay, M., Yilmaz, A. A., & Akin, E. (2023). A comprehensive review of cyber security vulnerabilities, threats, attacks, and solutions. Electronics, 12(6), 1333.

Ayala Gil, A. (2024). Honeypot in a box: A distributed cluster network for honeypot deployment (Doctoral dissertation, Politecnico di Torino).

Cavusoglu, H., Mishra, S., & Raghunathan, S. (2004). Insider attack detection using honeypots: An empirical study. Decision Support Systems, 38(3), 381–396.

Chen, Y., Wang, L., & Zhang, X. (2021). Integrating honeypots with SIEM tools for enhanced threat detection. International Journal of Network Management, 31(2), e2112–e2125.

Franco, J., Aris, A., Canberk, B., & Uluagac, A. S. (2021). A survey of honeypots and honeynets for internet of things, industrial internet of things, and cyber-physical systems. IEEE Communications Surveys & Tutorials, 23(4), 2351–2383.

Gregor, S., & Zwikael, O. (2024). Design science research and the co-creation of project management knowledge. International Journal of Project Management, 42(3), 102584.

Javadpour, A., Ja'fari, F., Taleb, T., Shojafar, M., & Benzaïd, C. (2024). A comprehensive survey on cyber deception techniques to improve honeypot performance. Computers & Security, 140, 103792.

Kelly, C., Pitropakis, N., Mylonas, A., McKeown, S., & Buchanan, W. J. (2021). A comparative analysis of honeypots on different cloud platforms. Sensors, 21(7), 2433.

Lee, S., Abdullah, A., Jhanjhi, N., & Kok, S. (2021). Classification of botnet attacks in IoT smart factory using honeypot combined with machine learning. PeerJ Computer Science, 7, e350.

Moore, T., Clayton, R., & Anderson, R. (2019). The economic impact of deploying honeypots in enterprise networks. Journal of Information Security and Applications, 45, 123–134.

Ngo, T. T. T., Sarramia, D., Kang, M. A., & Pinet, F. (2021). An analytical tool for georeferenced sensor data based on ELK Stack. Proceedings of GISTAM, 82–89.

Omer, M. A., Yazdeen, A. A., Malallah, H. S., & Abdulrahman, L. M. (2022). A survey on cloud security: Concepts, types, limitations, and challenges. Journal of Applied Science and Technology Trends, 3(02), 101–111.

Priya, V. D., & Chakkaravarthy, S. S. (2023). Containerised cloud-based honeypot deception for tracking attackers. Scientific Reports, 13(1), 1437.

Rashid, S. Z. U., Haq, A., Hasan, S. T., Furhad, M. H., Ahmed, M., & Ullah, A. B. (2024). Faking smart industry: Exploring cyber-threat landscape deploying cloud-based honeypot. Wireless Networks, 30(5), 4527–4541.

Shah, N., Willick, D., & Mago, V. (2022). A framework for social media data analytics using Elasticsearch and Kibana. Wireless Networks, 28(3), 1179–1187.

Tavallali, P., Tavallali, P., & Singhal, M. (2021). K-means tree: An optimal clustering tree for unsupervised learning. The Journal of Supercomputing, 77(5), 5239–5266.

Tyagi, K., Rane, C., Sriram, R., & Manry, M. (2022). Unsupervised learning. In Artificial intelligence and machine learning for EDGE computing (pp. 33–52). Academic Press.

Washofsky, A. D. (2021). Deploying and analysing containerised honeypots in the cloud with T-Pot (Doctoral dissertation, Naval Postgraduate School, Monterey, CA).

Yamin, M. M., Katt, B., & Gkioulos, V. (2019). Cyber ranges and security testbeds: Scenarios, functions, tools and architecture. Computers & Security, 88, 101636.

Downloads

Published

2026-09-14

Issue

Section

Articles