{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,25]],"date-time":"2026-03-25T15:57:03Z","timestamp":1774454223925,"version":"3.50.1"},"reference-count":34,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2023,2,14]],"date-time":"2023-02-14T00:00:00Z","timestamp":1676332800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2023,2,14]],"date-time":"2023-02-14T00:00:00Z","timestamp":1676332800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Cloud Comp"],"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Honeypot is an active defense mechanism, which attracts attackers to interact with virtual resources in the honeypot mainly by simulating real working scenarios and deploying decoy targets, so as to prevent real resources from being damaged and collect attackers\u2019 attack processes and analyze potential system vulnerabilities to proactively respond to similar attacks. Because of the existing honeypot system has defects such as the inability to deploy specific honeypots to induce attacks based on complex attacks, the inability to select the best honeypot for dynamic response based on honeypot deployment and maintenance costs during attack interactions, and insufficient ability to identify variants of known attack methods. Although hybrid honeypots can solve some of these problems by deploying low-interaction honeypots and high-interaction honeypots, they cannot really be applied to real production scenarios because of their slow TCP connection switching speed and inability to efficiently identify encrypted malicious traffic. In this paper, we propose a new dynamic security defense system based on the combination of TCP_REPAIR-based dynamic honeypot selection architecture and a deep learning-based intelligent firewall. The system accurately distributes encrypted or non-encrypted attack traffic and its variants through the intelligent firewall. The normal traffic is sent to the actual system, and the marked malicious traffic dynamically selects honeypots to respond according to the attack process.The experimental result indicated that the system can select honeypots for targeted responses according to the actual network situation quickly and dynamically and covertly, effectively improving the utilization rate of honeypot clusters as well as the ability to decoy.<\/jats:p>","DOI":"10.1186\/s13677-022-00379-2","type":"journal-article","created":{"date-parts":[[2023,2,20]],"date-time":"2023-02-20T16:15:00Z","timestamp":1676909700000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":6,"title":["A new dynamic security defense system based on TCP_REPAIR and deep learning"],"prefix":"10.1186","volume":"12","author":[{"given":"Jianxun","family":"Tang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mingsong","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Haoyu","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shenqi","family":"Zhao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yu","family":"Huang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,2,14]]},"reference":[{"key":"379_CR1","volume-title":"Artificial intelligence and security. ICAIS 2022. Lecture notes in computer science","author":"J Shi","year":"2022","unstructured":"Shi J, Chen M, Jiao J (2022) Thoughts on the application of low-interactive honeypot based on raspberry pi in public security actual combat, LIHRP. In: Sun X, Zhang X, Xia Z, Bertino E (eds) Artificial intelligence and security. ICAIS 2022. Lecture notes in computer science, vol 13340. Springer, Cham"},{"key":"379_CR2","doi-asserted-by":"publisher","first-page":"1005","DOI":"10.1109\/MILCOM52596.2021.9652927","volume-title":"MILCOM 2021\u20132021 IEEE military communications conference (MILCOM)","author":"AH Anwar","year":"2021","unstructured":"Anwar AH, Leslie NO, Kamhoua CA (2021) Honeypot allocation for cyber deception in internet of battlefield things systems. In: MILCOM 2021\u20132021 IEEE military communications conference (MILCOM), pp 1005\u20131010"},{"key":"379_CR3","doi-asserted-by":"publisher","first-page":"765","DOI":"10.1109\/CISAI54367.2021.00155","volume-title":"2021 International Conference on Computer Information Science and Artificial Intelligence (CISAI)","author":"J Tang","year":"2021","unstructured":"Tang J, Zhou F (2021) Design and implementation of high-performance web vulnerability scanner based on Python intelligent crawler. In: 2021 International Conference on Computer Information Science and Artificial Intelligence (CISAI), pp 765\u2013769"},{"issue":"1","key":"379_CR4","doi-asserted-by":"publisher","first-page":"35","DOI":"10.1109\/MNET.2012.6135854","volume":"26","author":"A Dainotti","year":"2012","unstructured":"Dainotti A, Pescape A, Claffy KC (2012) Issues and future directions in traffic classification. IEEE Netw 26(1):35\u201340","journal-title":"IEEE Netw"},{"key":"379_CR5","volume-title":"2010 IEEE global telecommunications conference","author":"GL Sun","year":"2010","unstructured":"Sun GL, Xue Y, Dong Y et al (2010) A novel hybrid method for effectively classifying encrypted traffic. In: 2010 IEEE global telecommunications conference"},{"issue":"5","key":"379_CR6","doi-asserted-by":"publisher","first-page":"355","DOI":"10.1002\/nem.1901","volume":"25","author":"P Velan","year":"2015","unstructured":"Velan P, \u010cerm\u00e1k M, \u010celeda P et al (2015) A survey of methods for encrypted traffic classification and analysis. Int J Netw Manag 25(5):355\u2013374","journal-title":"Int J Netw Manag"},{"key":"379_CR7","volume-title":"2011 IEEE symposium on computational intelligence for security and defense applications (CISDA)","author":"DJ Arndt","year":"2011","unstructured":"Arndt DJ, Zincir-Heywood AN (2011) A comparison of three machine learning techniques for encrypted network traffic analysis. In: 2011 IEEE symposium on computational intelligence for security and defense applications (CISDA)"},{"key":"379_CR8","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2020.102711","volume":"166","author":"Z Yao","year":"2020","unstructured":"Yao Z, Ge J, Wu Y et al (2020) Encrypted traffic classification based on Gaussian mixture models and hidden Markov models. J Netw Comput Appl 166:102711","journal-title":"J Netw Comput Appl"},{"key":"379_CR9","first-page":"16000","volume-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","author":"K He","year":"2022","unstructured":"He K, Chen X, Xie S et al (2022) Masked autoencoders are scalable vision learners. In: Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition, pp 16000\u201316009"},{"key":"379_CR10","doi-asserted-by":"publisher","first-page":"59","DOI":"10.1109\/MLISE54096.2021.00019","volume-title":"2021 International Conference on Machine Learning and Intelligent Systems Engineering (MLISE)","author":"R Li","year":"2021","unstructured":"Li R, Zheng M, Bai D, Chen Z (2021) SDN based intelligent Honeynet network model design and verification. In: 2021 International Conference on Machine Learning and Intelligent Systems Engineering (MLISE), pp 59\u201364. https:\/\/doi.org\/10.1109\/MLISE54096.2021.00019"},{"issue":"15","key":"379_CR11","doi-asserted-by":"publisher","first-page":"6999","DOI":"10.3390\/app11156999","volume":"11","author":"R Wazirali","year":"2021","unstructured":"Wazirali R, Ahmad R, Alhiyari S (2021) SDN-openflow topology discovery: an overview of performance issues. Appl Sci 11(15):6999","journal-title":"Appl Sci"},{"key":"379_CR12","doi-asserted-by":"publisher","first-page":"129","DOI":"10.1016\/j.comcom.2021.01.018","volume":"169","author":"PP Ray","year":"2021","unstructured":"Ray PP, Kumar N (2021) SDN\/NFV architectures for edge-cloud oriented IoT: a systematic review. Comput Commun 169:129\u2013153","journal-title":"Comput Commun"},{"key":"379_CR13","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2021.107981","volume":"192","author":"S Khorsandroo","year":"2021","unstructured":"Khorsandroo S, S\u00e1nchez AG, Tosun AS et al (2021) Hybrid SDN evolution: a comprehensive survey of the state-of-the-art. Comput Netw 192:107981","journal-title":"Comput Netw"},{"key":"379_CR14","first-page":"818","volume-title":"2021 IFIP\/IEEE international symposium on integrated network management (IM)","author":"JL Vieira","year":"2021","unstructured":"Vieira JL, Ferreira VC, Bastos IV et al (2021) THANOS: Teleprotection holistic application for ONOS controller. In: 2021 IFIP\/IEEE international symposium on integrated network management (IM). IEEE, pp 818\u2013823"},{"key":"379_CR15","doi-asserted-by":"publisher","unstructured":"Babbar H, Rani S (2021) \"Performance evaluation of qos metrics in software defined networking using ryu controller.\" IOP conference series: materials science and engineering, vol 1022. No. 1. IOP Publishing. https:\/\/doi.org\/10.1088\/1757-899X\/1022\/1\/012024","DOI":"10.1088\/1757-899X\/1022\/1\/012024"},{"key":"379_CR16","doi-asserted-by":"publisher","first-page":"66","DOI":"10.1109\/IoTaIS50849.2021.9359696","volume-title":"2020 IEEE international conference on internet of things and intelligence system (IoTaIS)","author":"N Parhandhito","year":"2021","unstructured":"Parhandhito N, Negara RM, Dewanta F (2021) \"Comparison of High Availability Performance on OpenDaylight with Corosync Pacemaker and OpenDaylight SDN Controller Platform Clustering,\" 2020 IEEE International Conference on Internet of Things and Intelligence System (IoTaIS), pp 66\u201371. https:\/\/doi.org\/10.1109\/IoTaIS50849.2021.9359696"},{"key":"379_CR17","doi-asserted-by":"publisher","first-page":"140","DOI":"10.1016\/j.future.2022.04.006","volume":"134","author":"B Yan","year":"2022","unstructured":"Yan B, Liu Q, Shen JL et al (2022) Flowlet-level multipath routing based on graph neural network in OpenFlow-based SDN. Futur Gener Comput Syst 134:140\u2013153","journal-title":"Futur Gener Comput Syst"},{"issue":"1","key":"379_CR18","first-page":"27","volume":"21","author":"J Wang","year":"2021","unstructured":"Wang J, Yang H, Fan C (2021) A SDN dynamic honeypot with multi-phase attack response. Netinfo Security 21(1):27\u201340","journal-title":"Netinfo Security"},{"issue":"2","key":"379_CR19","first-page":"444","volume":"54","author":"L Jiahui","year":"2021","unstructured":"Jiahui L, Yijun W, Zhi X (2021) TCP connection handover mechanism for hybrid Honeynet based on connection state and SDN. Commun Technol 54(2):444\u2013450","journal-title":"Commun Technol"},{"issue":"4","key":"379_CR20","first-page":"274","volume":"25","author":"H Artail","year":"2006","unstructured":"Artail H, Safa H, Sraj M, Kuwatly I, Al-Masri Z (2006) A hybrid honeypot framework for improving intrusion detection systems in protecting organizational networks. Comput. 25(4):274\u2013288","journal-title":"Comput."},{"key":"379_CR21","volume-title":"IEEE journal on selected areas in communications","author":"W Fan","year":"2019","unstructured":"Fan W, Du Z, Smith-Creasey M, Fernandez D (2019) HoneyDOC: an efficient honeypot architecture enabling all-round design. In: IEEE journal on selected areas in communications"},{"key":"379_CR22","volume-title":"USENIX security symposium","author":"R Berthier","year":"2008","unstructured":"Berthier R, Cukier M (2008) Honeybrid: a hybrid honeypot architecture. In: USENIX security symposium, vol 2008"},{"key":"379_CR23","doi-asserted-by":"publisher","first-page":"188","DOI":"10.1109\/ICCES.2017.8275301","volume-title":"2017 12th international conference on computer engineering and systems (ICCES)","author":"RT El-Maghraby","year":"2017","unstructured":"El-Maghraby RT, Abd Elazim NM, Bahaa-Eldin AM (2017) \"A survey on deep packet inspection,\" 2017 12th International Conference on Computer Engineering and Systems (ICCES), pp 188\u2013197. https:\/\/doi.org\/10.1109\/ICCES.2017.8275301"},{"issue":"10","key":"379_CR24","doi-asserted-by":"publisher","first-page":"4910","DOI":"10.1007\/s11227-018-2268-y","volume":"74","author":"MHM Soleimani","year":"2018","unstructured":"Soleimani MHM, Mansoorizadeh M, Nassiri M (2018) Real-time identification of three Tor pluggable transports using machine learning techniques. J Supercomput 74(10):4910\u20134927","journal-title":"J Supercomput"},{"issue":"2","key":"379_CR25","doi-asserted-by":"publisher","first-page":"445","DOI":"10.1109\/TNSM.2019.2899085","volume":"16","author":"G Aceto","year":"2019","unstructured":"Aceto G, Ciuonzo D, Montieri A et al (2019) Mobile encrypted traffic classification using deep learning:experimental evaluation, lessons learned, and challenges. IEEE Trans Netw Serv Manag 16(2):445\u2013458","journal-title":"IEEE Trans Netw Serv Manag"},{"issue":"4","key":"379_CR26","doi-asserted-by":"publisher","first-page":"4103","DOI":"10.1109\/TNSM.2021.3122940","volume":"18","author":"L Yang","year":"2021","unstructured":"Yang L, Finamore A, Jun F et al (2021) Deep learning and zero-day traffic classification: lessons learned from a commercial-grade dataset. IEEE Trans Netw Serv Manag 18(4):4103\u20134118","journal-title":"IEEE Trans Netw Serv Manag"},{"key":"379_CR27","volume-title":"2017 IEEE international conference on intelligence and security informatics","author":"W Wang","year":"2017","unstructured":"Wang W, Zhu M, Wang J et al (2017) End-to-end encrypted traffic classification with one-dimensional convolution neural networks. In: 2017 IEEE international conference on intelligence and security informatics"},{"key":"379_CR28","volume-title":"2017 IEEE international conference on big data","author":"Z Chen","year":"2017","unstructured":"Chen Z, He K, Li J et al (2017) Seq2img:a sequence-to-image based approach towards ip traffic classification using convolutional neural networks. In: 2017 IEEE international conference on big data"},{"issue":"11","key":"379_CR29","doi-asserted-by":"publisher","first-page":"16951","DOI":"10.1007\/s11042-020-09459-4","volume":"80","author":"O Salman","year":"2021","unstructured":"Salman O, Elhajj IH, Kayssi A et al (2021) Data representation for CNN based internet traffic classification: a comparative study. Multimed Tools Appl 80(11):16951\u201316977","journal-title":"Multimed Tools Appl"},{"issue":"2","key":"379_CR30","doi-asserted-by":"publisher","first-page":"1962","DOI":"10.1109\/TNSM.2021.3052888","volume":"18","author":"AM Sadeghzadeh","year":"2021","unstructured":"Sadeghzadeh AM, Shiravi S, Jalili R (2021) Adversarial network traffic: towards evaluating the robustness of deep-learning-based network traffic classification. IEEE Trans Netw Serv Manag 18(2):1962\u20131976","journal-title":"IEEE Trans Netw Serv Manag"},{"issue":"5","key":"379_CR31","doi-asserted-by":"publisher","first-page":"1285","DOI":"10.1109\/TMI.2016.2528162","volume":"35","author":"HC Shin","year":"2016","unstructured":"Shin HC, Roth HR, Gao M et al (2016) Deep convolutional neural networks for computer-aided detection: CNN architectures, dataset characteristics and transfer learning. IEEE Trans Med Imaging 35(5):1285\u20131298","journal-title":"IEEE Trans Med Imaging"},{"key":"379_CR32","doi-asserted-by":"publisher","first-page":"43","DOI":"10.1109\/ISI.2017.8004872","volume-title":"2017 IEEE international conference on intelligence and security informatics (ISI)","author":"W Wang","year":"2017","unstructured":"Wang W, Zhu M, Wang J, Zeng X, Yang Z (2017) End-to-end encrypted traffic classification with one-dimensional convolution neural networks. In: 2017 IEEE international conference on intelligence and security informatics (ISI), pp 43\u201348. https:\/\/doi.org\/10.1109\/ISI.2017.8004872"},{"key":"379_CR33","doi-asserted-by":"publisher","first-page":"174","DOI":"10.1109\/NFV-SDN50289.2020.9289898","volume-title":"2020 IEEE conference on network function virtualization and software defined networks (NFV-SDN)","author":"VA Cunha","year":"2020","unstructured":"Cunha VA, Corujo D, Barraca JP, Aguiar RL (2020) Using Linux TCP connection repair for mid-session endpoint handover: a security enhancement use-case. In: 2020 IEEE conference on network function virtualization and software defined networks (NFV-SDN), pp 174\u2013180"},{"key":"379_CR34","first-page":"407","volume-title":"In proceedings of the 2nd international conference on information systems security and privacy (ICISSP)","author":"G Draper-Gil","year":"2016","unstructured":"Draper-Gil G, Lashkari AH, Mamun MSI, Ghorbani AA (2016) Characterization of encrypted and VPN traffic using time-related features. In: In proceedings of the 2nd international conference on information systems security and privacy (ICISSP), pp 407\u2013414"}],"container-title":["Journal of Cloud Computing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s13677-022-00379-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s13677-022-00379-2\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s13677-022-00379-2.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,2,20]],"date-time":"2023-02-20T16:15:14Z","timestamp":1676909714000},"score":1,"resource":{"primary":{"URL":"https:\/\/journalofcloudcomputing.springeropen.com\/articles\/10.1186\/s13677-022-00379-2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,2,14]]},"references-count":34,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2023,12]]}},"alternative-id":["379"],"URL":"https:\/\/doi.org\/10.1186\/s13677-022-00379-2","relation":{},"ISSN":["2192-113X"],"issn-type":[{"value":"2192-113X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,2,14]]},"assertion":[{"value":"25 August 2022","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"7 December 2022","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"14 February 2023","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors report no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"21"}}