HoneyWin: high-interaction windows honeypot in enterprise environment
Conference paper
| Authors | Aung, Y., Khoo, Y., Zheng, D., Duo, B., Chattopadhyay, S., Zhou, J., Lu, L. and Goh, W. |
|---|---|
| Type | Conference paper |
| Abstract | Windows operating systems are often the primary targets of malware and ransomware attacks. With 93% of the ransomware targetingWindows-based systems, there is an urgent need for advanced defensive mechanisms to detect, analyze, and mitigate threats effectively. This paper proposes HoneyWin a high-interaction Windows honeypot that mimics an enterprise IT environment. The HoneyWin consists of three Windows 11 endpoints and an enterprise-grade gateway provisioned with comprehensive network traffic capturing, host-based logging, deceptive tokens, endpoint security and real-time alerts capabilities. The HoneyWin has been deployed live in the wild for 34 days and receives more than 5.79 million unsolicited connections, 1.24 million login attempts, 5 and 354 successful logins via remote desktop protocol (RDP) and secure shell (SSH). The adversary interacted with the deceptive token in one of the RDP sessions and exploited the public-facing endpoint to initiate the Simple Mail Transfer Protocol (SMTP) brute-force bot attack via SSH sessions. The adversary successfully harvested 1,250 SMTP credentials after attempting 151,179 credentials during the attack. |
| Keywords | High-Interaction Windows Honeypot; Deception; Network Traffic Analysis; Host Log Analysis; Attack Attribution |
| Year | 2025 |
| Conference | The 2025 8th IEEE Conference on Dependable and Secure Computing |
| Publisher | IEEE |
| Web address (URL) | https://attend.ieee.org/dsc-2025/ |
| Accepted author manuscript | License File Access Level Restricted |
| File | File Access Level Restricted |
| Output status | In press |
| Publication process dates | |
| Deposited | 31 Oct 2025 |
https://repository.derby.ac.uk/item/v0504/honeywin-high-interaction-windows-honeypot-in-enterprise-environment
10
total views4
total downloads9
views this month0
downloads this month