Electronic and Cyber Defense

Electronic and Cyber Defense

Dalon: Proactive Cyber Defence with a Counter Attack Honypot Framework

Document Type : Original Article

Authors
1 PhD Student, Imam Hossein (AS) University, Tehran, Iran
2 Assistant Professor, Imam Hossein (AS) University, Tehran, Iran
Abstract
Today, detecting, tracking, and taking deterrent action against cyber attackers is one of the main challenges in the field of cybersecurity and cyber defense. Traditional attack detection mechanisms, due to their reactive approach to defense and the high rate of false-positive alerts, have complicated the detection process.Various methods have been proposed to address this challenge, and the use of cyber deception traps is one of the effective approaches currently being developed and utilized for targeted and proactive detection of emerging threats. Existing cyber trap solutions, due to their passive structure and one-directional operation, do not lead to deterrence or identification of the origin of the attack. In this article, an enhanced hybrid trap-network framework called Daloon is proposed. Daloon, through its “Explosive Web Trap” component, enables counterattack and reverse intrusion against trapped attackers and, while identifying and tracking the attacker, provides the capability for punitive action that results in cyber deterrence. Daloon is implemented by designing a fake web trap and simulating the HMI of a SCADA industrial control system and contaminating it with a fake and intentionally crafted code-injection vulnerability as well as several other vulnerabilities. Experimental results show that Daloon performs successfully in detecting and responding to three types of offensive techniques and has successfully carried out reverse intrusion and “counterattack.” The proposed Daloon hybrid trap, with reverse-intrusion capability, leads to the adoption of a proactive cyber defense approach—i.e., defense during the attack—and, in addition to reducing false positives in attack analysis, transforms the one-way process of traditional cyber traps, which are purely defensive and passive, into a two-way process that is offensive and deterrent
Keywords
Subjects

1].   Kott, A., Intelligent autonomous agents are key to cyber defense of the future army networks. The Cyber Defense Review, 2018. 3(3): p. 57-70.
[2].  Fan, W., et al., Enabling an anatomic view to investigate honeypot systems: A survey. IEEE Systems Journal, 2017. 12(4): p. 3906-3919.
[3].  Dewar, R.S., Active cyber defense. CSS Cyberdefense Trend Analyses, 2017. 1.
[4].  Company, r.c. Overview of Distributed Deception Platforms (DDP) 2019; Available from: https://en.blog.roi4cio.com/2019/01/overview-of-distributed-deception.html.
[5].  Dewar, R., ‘The “triptych of cyber security”: a classification of active cyber defence.’6th Intl conference on cyber conflict. 2014, NATO CCD COE Publications Tallinn.
[6].  Flowers, A. and S. Zeadally, US policy on active cyber defense. Journal of Homeland Security and Emergency Management, 2014. 11(2): p. 289-308.
[8].  Rehman, Z., et al., Proactive defense mechanism: Enhancing IoT security through diversity-based moving target defense and cyber deception. Computers & Security, 2024. 139: p. 103685.
[9].  DEFENSE, P.C., Active Cyber Defense: Applying Air Defense to the Cyber Domain1. Cyber Analogies, 2014.
[10].David Poarch, D.O.L., Jason Nelson, Anne Grahn, 6 Ways to Deceive Cyber Attackers. 2017.
[11].Almeshekah, M.H. and E.H. Spafford, Cyber security deception, in Cyber deception. 2016, Springer. p. 23-50.
[14].Rowe, N.C. and J. Rrushi, Introduction to Cyberdeception. 2016: Springer.
[15].Couillard, M., J. Lindsay, and J.J. Arquilla, The Role of Deceptive Defense in Cyber Strategy. 2023.
[16].Chinn, R., Botnet Detection: Honeypots and the Internet of Things. Unpublished doctoral dissertation. University of Arizona, 2015.
[17].Chesney, R., Hackback is Back: Assessing the Active Cyber Defense Certainty Act. Lawfare (14 June 2019): https://www. lawfareblog. com/hackback-back-assessing-active-cyber-defense-certainty-act. (21 February 2021, date last accessed), 2019.
[18].Couzigou, I., Hacking-Back by Non-State Actors and the Rule of Law. Heidelberg Journal of International Law, 2020.
[19].Prakash, H.O., Monitoring and Tracking Hackers’ Activities Using Honeynets. 2015. https://electronicsforu.com.
[20].Grudziecki, T., et al., Proactive detection of security incidents. Honeypots. ENISA, 2012.
[21].Soóky, P., Design of new honeypot implementing basic concept of HoneyD honeypot. Masaryk University Faculty of Informatics, Brno, Spring 2017.
[22].Jain, A. and D.B. Buksh, Advance Trends in Network Security with Honeypot and its Comparative Study with other Techniques. International Journal of Engineering Trends and Technology, 2015. 29: p. 304-312.
[23].Almeshekah, M.H., CERIAS Tech Report 2015-11 Using Deception to Enhance Security: A Taxonomy, Model, and Novel Uses. 2015.
[25].Knudsen, M., J. Løvbråten, and A. Dalmo, Deploying a Virtualised High-Interaction Honeynet. 2014.
[26].Sokol, P., P. Pekarčík, and T. Bajtoš, Data collection and data analysis in honeypots and honeynets. Proceedings of the Security and Protection of Information. University of Defence, 2015.
[27].Harikrishnan, V. and G. Kumar, Advanced Persistent Threat Analysis using Splunk. International Journal of Pure and Applied Mathematics, 2018. 118(20): p. 3761-3768.
[28].team, S.  Suricata Open Source IDS / IPS / NSM engine 2019; Available from: https://suricata-ids.org/.
[29].Sanders, C. and J. Smith, Applied network security monitoring: collection, detection, and analysis. 2013: Elsevier.
[30].Wang, B., K. Lu, and P. Chang. Design and implementation of Linux firewall based on the frame of Netfilter/IPtable. in 2016 11th International Conference on Computer Science & Education (ICCSE). 2016. IEEE.
[31].ROBERTSON, W., Using Web Honeypots to Study the Attackers Behavior. 2017, TELECOM ParisTech.
[32].Fan, W., D. Fernández, and Z. Du. Adaptive and flexible virtual honeynet. in International Conference on Mobile, Secure and Programmable Networking. 2015. Springer.
[33].Abbasi, F.H. and R. Harris. Experiences with a generation iii virtual honeynet. in Telecommunication Networks and Applications Conference (ATNAC), 2009 Australasian. 2009. IEEE.
[34].Aliyev, V., Using honeypots to study skill level of attackers based on the exploited vulnerabilities in the network. 2010.
[35].T-Pot 17.10 - Multi-Honeypot Platform rEvolution. 2017; Available from: https://dtag-dev-sec.github.io/mediator/feature/2017/11/07/t-pot-17.10.html.
[36].Wahono, S. and S. Alif Subardono, Analisis dan Implementasi Honeypot Terdistribusi sebagai Deteksi Aktivitas Blackhat pada Jaringan. 2017, Universitas Gadjah Mada.
[37].Koniaris, I. HoneyDrive  Honeypot Bundle Linux. 2014; Available from: https://bruteforce.gr/honeydrive/.
[38].Jigneshkumar, S.M., Modern Honey Network. International Journal of Research in Advent Technology (E-ISSN: 2321-9637) Special Issue, 2016. E-ISSN: 2321-9637(National Conference “NCPCI-2016”, 19 March 2016).
[39].Oosterhof, M., Cowrie honeypot. Security Intelligence, 2014.
[40].Müter, M., et al., A generic toolkit for converting web applications into high-interaction honeypots. University of Mannheim, 2008. 280: p. 6.1.
[41].Crane, S., et al. Booby trapping software. in Proceedings of the 2013 New Security Paradigms Workshop. 2013. ACM.
[42].Itkin, E. Reverse RDP Attack: Code Execution on RDP Clients. 2019; Available from: https://research.checkpoint.com/reverse-rdp-attack-code-execution-on-rdp-clients/.
[43].Sintsov, A. Honeypot that can bite: Reverse penetration. in Black Hat Europe Conference. 2013.
[44]  (@debasishm89), D.M., Browser Exploits. MCAFEE 2017.
[45].Singh, E.G. and M. Kaur, Armitage: A Penetration testing tool to evaluate Destructive Vulnerabilities.
[46].Brandis, R.A.S., Luke. Threat Modelling Adobe Pdf. Edinburgh South Australia : Dsto Defence Science And Technology Organisation 2012.
[47].Ramirez-Silva, E., and Marc Dacier. "Empirical study of the impact of metasploit-related attacks in 4 years of attack traces." Annual Asian Computing Science Conference. Springer Berlin Heidelberg, 2007.
[48].O'Leary, M., Cyber operations: building, defending, and attacking modern computer networks. 2015: Apress.
[49].Choudhary, R. and M. Khurana, Exploitation of PDF Reader Vulnerabilities using Metasploit Tool. 2017.
[50].Zarghoon, A., et al., Evaluation of AV Systems Against Modern Malware.
[51].kyREcon. Shellter 2017  cited 2017; Available from: https://www.shellterproject.com/introducing-shellter/.
[52].D, D., Anti-Virus Bypass with Shellter 5.1 on Kali Linux. 2015.
[53].Ge, M., et al., Proactive defense for internet-of-things: moving target defense with cyberdeception. ACM Transactions on Internet Technology (TOIT), 2021. 22(1): p. 1-31.
[54].Reworr and D. Volkov, LLM Agent Honeypot: Monitoring AI Hacking Agents in the Wild. ArXiv, 2024. abs/2410.13919.
[55].Zeltser, L., Experimenting with Honeypots Using The Modern Honey Network 20 Feb 2015. Electron Resource. Access mode: https://zeltser. com/modern-honey-network-experiments.
[56].Lin, K. and L. Kyaw, Hybrid Honeypot System for Network Security. 2008.
Volume 13, Issue 4 - Serial Number 52
Winter
Winter 2026
Pages 125-144

  • Receive Date 08 October 2025
  • Revise Date 24 November 2025
  • Accept Date 19 December 2025
  • Publish Date 22 December 2025