MRI
MRI India Journals Vol. 15 No. 1S (2026): Special Issue: Integration of AI Management Engineering and Technology

HoneyCloud: A Smart Scalable Honeypot Platform with ML-Based Threat Classification and Real-Time Attacker Profiling

Authors

  • Akash Guldagad B.E. Student, Department of Computer Engineering Genba Sopanrao Moze College of Engineering, Pune Savitribai Phule Pune University, Maharashtra, India
  • Anand Bora B.E. Student, Department of Computer Engineering Genba Sopanrao Moze College of Engineering, Pune Savitribai Phule Pune University, Maharashtra, India
  • Ganesh Kambli B.E. Student, Department of Computer Engineering Genba Sopanrao Moze College of Engineering, Pune Savitribai Phule Pune University, Maharashtra, India
  • Aarya Konde Deshmukh B.E. Student, Department of Computer Engineering Genba Sopanrao Moze College of Engineering, Pune Savitribai Phule Pune University, Maharashtra, India
  • Rahul Korke Assistant Professor, Department of Computer Engineering Genba Sopanrao Moze College of Engineering, Pune Savitribai Phule Pune University, Maharashtra, India

DOI:

https://doi.org/10.65521/ijeecs.v15i1S.3016

Keywords:

Honeypot Intrusion Detection Isolation Forest Attacker Profiling Machine Learning Cybersecurity Real-Time Dashboard Docker

Abstract

The rapid proliferation of internet-connected systems has intensified the frequency and sophistication of cyberattacks, making traditional security mechanisms increasingly insufficient. This paper presents HoneyCloud, a smart, scalable honeypot platform designed to capture, classify, and visualize cyberattacks in real time. HoneyCloud deploys multi-protocol honeypots simulating SSH, FTP, and HTTP services to lure and log malicious activity. Captured events are processed through a machine learning pipeline based on the Isolation Forest algorithm, which classifies traffic into benign, anomalous, or malicious categories using ten semantic features including service port encoding, credential length analysis, dangerous pattern detection, and user identity classification. The platform incorporates a real-time attacker profiling engine that assigns dynamic risk scores and detects behavioural patterns such as brute force attacks, credential stuffing, and port scanning. A real-time dashboard powered by WebSockets and Server-Sent Events (SSE) provides security analysts with live visualisation of attack data, including timing heatmaps, service trends, credential intelligence, and attacker profiles. The system is containerised using Docker and designed for horizontal scalability. Evaluation through a structured simulation suite confirms the platform’s effectiveness in detecting and classifying attack behaviour with low-latency response times. HoneyCloud demonstrates a viable, deployable approach to proactive cyber threat intelligence for organisational security infrastructure.

 

Downloads

Published

2026-05-19

How to Cite

Guldagad, A., Bora, A., Kambli, G., Deshmukh, A. K., & Korke, R. (2026). HoneyCloud: A Smart Scalable Honeypot Platform with ML-Based Threat Classification and Real-Time Attacker Profiling. International Journal of Electrical, Electronics and Computer Systems, 15(1S), 112–118. https://doi.org/10.65521/ijeecs.v15i1S.3016

Similar Articles

1 2 3 4 5 6 7 8 9 10 > >> 

You may also start an advanced similarity search for this article.