Javascript must be enabled to continue!
AEGIS-AI: Autonomous Threat Deception and Detection Using Honeypot Networks
View through CrossRef
The development of adaptive and intelligent defense mechanisms will require new approaches to defending against
sophisticated cyber threats that can't be fully supported by existing intrusion detection (ID) systems. AEGIS-AI: A Framework
for Autonomous Threat Deception and Detection is an autonomous framework based on both honeypots and reinforcement
learning (RL) combined with deep neural networks (DNNs) to automate the way honeypots are employed as a deception
technique for detecting and responding to malicious activity. The ability to change deception strategies in real time according to
the attacker's behaviour is a key feature of AEGIS-AI. The dynamic deception strategy can be generated from an analysis of
attacker's behaviour at any point in time using a Markov Decision Process (MDP) approach to provide optimal responses. The
honeypots are subdivided into multi-service honeypots having different interactive capabilities, and the AI engine automatically
coordinates the application of the deception techniques being employed as well as continuously improving them using Qlearning and anomaly detection-based models. The performance of the AEGIS-AI framework was evaluated against the
CICIDS-2017 and Honeypot Datasets Customized for Your Organization Indicate an Accuracy Of 97.8% In Identifying
Intrusions with A 1.4% Chance of False Positives and An Average Time Spent Engaging an Attacker with The System Of 520
Seconds. Thus, Custom Honeypot Datasets Outperform Previous (Static & Semi-Adaptive) Honeypot Baseline Performance by A
Large Margin. The Use of Federated Learning to Share Threat Intelligence Across Multiple Geographically Dispersed
Deployments While Maintaining Data Privacy Has Also Been Incorporated into The Framework. Additionally, The Paper
Provides Mathematical Formulas for Evaluating the Effectiveness of Deception-Based Approaches to Honeypots, For Placing
Game Theoretic Honeypots, And for Optimizing Resources Used in Maintaining a Honeypot System.
International Journal for Research in Applied Science and Engineering Technology
Title: AEGIS-AI: Autonomous Threat Deception and Detection Using Honeypot Networks
Description:
The development of adaptive and intelligent defense mechanisms will require new approaches to defending against
sophisticated cyber threats that can't be fully supported by existing intrusion detection (ID) systems.
AEGIS-AI: A Framework
for Autonomous Threat Deception and Detection is an autonomous framework based on both honeypots and reinforcement
learning (RL) combined with deep neural networks (DNNs) to automate the way honeypots are employed as a deception
technique for detecting and responding to malicious activity.
The ability to change deception strategies in real time according to
the attacker's behaviour is a key feature of AEGIS-AI.
The dynamic deception strategy can be generated from an analysis of
attacker's behaviour at any point in time using a Markov Decision Process (MDP) approach to provide optimal responses.
The
honeypots are subdivided into multi-service honeypots having different interactive capabilities, and the AI engine automatically
coordinates the application of the deception techniques being employed as well as continuously improving them using Qlearning and anomaly detection-based models.
The performance of the AEGIS-AI framework was evaluated against the
CICIDS-2017 and Honeypot Datasets Customized for Your Organization Indicate an Accuracy Of 97.
8% In Identifying
Intrusions with A 1.
4% Chance of False Positives and An Average Time Spent Engaging an Attacker with The System Of 520
Seconds.
Thus, Custom Honeypot Datasets Outperform Previous (Static & Semi-Adaptive) Honeypot Baseline Performance by A
Large Margin.
The Use of Federated Learning to Share Threat Intelligence Across Multiple Geographically Dispersed
Deployments While Maintaining Data Privacy Has Also Been Incorporated into The Framework.
Additionally, The Paper
Provides Mathematical Formulas for Evaluating the Effectiveness of Deception-Based Approaches to Honeypots, For Placing
Game Theoretic Honeypots, And for Optimizing Resources Used in Maintaining a Honeypot System.
Related Results
Modeling the effects of different honeypot proportions in a deception-based security game
Modeling the effects of different honeypot proportions in a deception-based security game
Cyber-attacks, an intentional effort to steal information or interrupt the network, are growing dramatically. It is of great importance to understand how an adversary’s behavior mi...
Implementasi Ansible pada Otomasi Honeypot Deployment Berbasis Web
Implementasi Ansible pada Otomasi Honeypot Deployment Berbasis Web
Dalam era digital yang semakin kompleks ini, keamanan sistem informasi menjadi masalah penting bagi organisasi di berbagai industri. Peningkatan serangan siber serta polanya yang s...
Self-deception
Self-deception
Philosophical work on self-deception revolves around a trio of questions. What is self-deception? Is self-deception possible? How are cases of self-deception to be explained? The e...
Self-deception
Self-deception
Philosophical work on self-deception revolves around a trio of questions. What is self-deception? Is self-deception possible? How are instances of self-deception to be explained? T...
Deception-Based Security Framework for IoT: An Empirical Study
Deception-Based Security Framework for IoT: An Empirical Study
<p><b>A large number of Internet of Things (IoT) devices in use has provided a vast attack surface. The security in IoT devices is a significant challenge considering c...
Studi Deskriptif Perilaku Online Deception pada Mahasiswa Pengguna Instagram
Studi Deskriptif Perilaku Online Deception pada Mahasiswa Pengguna Instagram
Abstract. The development of information and communication technology has changed the social interaction patterns of Indonesian society. Instagram as one of the dominant platforms ...
Honeypot in the Cyber Space
Honeypot in the Cyber Space
In today’s world a large number of devices are connected to the network, which indicates that there could exist more access nodes than before from where an intruder can try to atta...
SCV-AEGIS Mk-II: Autonomous Orbital Debris Remediation and In-Situ Manufacturing Vehicle
SCV-AEGIS Mk-II: Autonomous Orbital Debris Remediation and In-Situ Manufacturing Vehicle
Introduction: Low Earth Orbit (LEO) is currently overcrowded with over 130 million pieces of orbital debris, ranging from defunct spacecraft to shattered upper rocket stages. At or...

