AUTOMATED SYSTEM OF ISOLATED EMULATION ENVIRONMENTS FOR CYBER THREAT RESEARCH
DOI:
https://doi.org/10.17721/2519-481X/2026/90-06Keywords:
cybersecurity, information security, Cyber Deception, honeypot, cyber threats, attack analysis, emulation environmentAbstract
The article examines the application of Cyber Deception technologies for the investigation of modern cyber threats and the analysis of the behavior of potential cyber attackers. The relevance of using honeypot systems as an effective tool for collecting information on unauthorized access attempts, studying contemporary cyberattack techniques, and improving cybersecurity mechanisms is substantiated. It is demonstrated that Cyber Deception technologies enable the creation of controlled emulation environments in which the behavior of potential attackers can be investigated without compromising real information infrastructure.
The purpose of this study is to analyze technologies for constructing isolated emulation environments and to develop a laboratory system for cyber threat research based on honeypot technologies. The paper presents an analysis of current approaches to the development of Cyber Deception systems, the classification of honeypots according to the level of attacker interaction, the specific features of their application in cybersecurity systems, and their potential use in research and educational activities. An architecture of a laboratory environment based on a virtual infrastructure using the Cowrie honeypot system is proposed. The developed solution provides automated event log collection and enables continuous monitoring of unauthorized access attempts, authentication processes, executed commands, and subsequent analysis of attacker activities.
Experimental evaluation demonstrated that the vast majority of recorded attacks were automated and followed common compromise scenarios, including dictionary-based password guessing, the use of default user accounts, and command execution after successful authentication. The results confirm that the proposed honeypot environment effectively accumulates experimental data on contemporary cyberattack techniques, facilitates the investigation of attacker tactics and tools, and improves the efficiency of security event log analysis. The collected data provide valuable information for understanding attacker behavior and identifying emerging attack patterns that can be used to enhance cybersecurity strategies.
The practical significance of the proposed approach lies in the development of a laboratory environment suitable for cybersecurity research, evaluation of attack detection mechanisms, accumulation of experimental datasets for improving security monitoring and incident response processes, and practical training of cybersecurity specialists. Furthermore, the proposed solution can serve as a foundation for future integration with Security Information and Event Management (SIEM) platforms, expansion of laboratory cyber ranges, and further development of proactive information security technologies.
References
1. Stallings W. Network Security Essentials: Applications and Standards. 6th ed. New York : Pearson, 2017. 456 p.
2. Bishop M. Computer Security: Art and Science. 2nd ed. Boston : Addison-Wesley, 2019. 1312 p.
3. Anderson R. Security Engineering: A Guide to Building Dependable Distributed Systems. 3rd ed. Indianapolis : John Wiley & Sons, 2020. 1200 p.
4. Security and Privacy Controls for Information Systems and Organizations (NIST Special Publication 800-53, Revision 5): National Institute of Standards and Technology. 2020. 492 р.
5. Scarfone K., Mell P. Guide to Intrusion Detection and Prevention Systems (IDPS): NIST Special Publication 800-94. Gaithersburg: National Institute of Standards and Technology, 2007. 127 p.
6. Skoudis E., Liston T. Counter Hack Reloaded: A Step-by-Step Guide to Computer Attacks and Effective Defenses. 2nd ed. Upper Saddle River: Prentice Hall, 2005. 784 p.
7. Singer P. W., Friedman A. Cybersecurity and Cyberwar: What Everyone Needs to Know. Oxford: Oxford University Press, 2014. 320 p.
8. Spitzner L. Honeypots: Tracking Hackers. Boston: Addison-Wesley, 2002. 480 p.
9. Oracle VM VirtualBox User Manual: official documentation. URL: https://www.virtualbox.org/manual/.
10. Kali Linux Documentation: official website. URL: https://www.kali.org/docs/.
11. Lyon G. Nmap Network Scanning: The Official Nmap Project Guide to Network Discovery and Security Scanning. URL: https://nmap.org.
12. Cowrie Honeypot Documentation: documentation project. URL: https://cowrie.readthedocs.io.
13. OWASP Foundation. Web Security Testing Guide (WSTG): official project page. URL: https://owasp.org/www-project-web-security-testing-guide/







