{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,30]],"date-time":"2026-07-30T10:22:09Z","timestamp":1785406929561,"version":"3.56.0"},"reference-count":24,"publisher":"MDPI AG","issue":"5","license":[{"start":{"date-parts":[[2025,4,22]],"date-time":"2025-04-22T00:00:00Z","timestamp":1745280000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Symmetry"],"abstract":"<jats:p>Anomaly detection is essential in cybersecurity for identifying abnormal activities, a requirement that has grown increasingly critical with the complexity of cyberthreats. This study leverages the BPF-Extended Tracking Honeypot (BETH) dataset, a comprehensive resource designed to benchmark robustness in detecting anomalous behavior in kernel-level process and network logs. The symmetry of the proposed system lies in its ability to identify balanced and consistent patterns within kernel-level process logs, which form the foundation for accurately distinguishing anomalies. This study focuses on anomaly detection in kernel-level process logs by introducing an enhanced Isolation Forest (iForest) model, which is integrated into a structured framework that includes exploratory data analysis (EDA), data pre-processing, model training, validation, and evaluation. The proposed approach achieves a significant performance improvement in the anomaly detection results, with an area under the receiver operating characteristic curve (AUROC) score of 0.917\u2014an approximate 7.88% increase over the baseline model\u2019s AUROC of 0.850. Additionally, the model demonstrates high precision (99.57%), F1-score (91.69%), and accuracy (86.03%), effectively minimizing false positives while maintaining balanced detection capabilities. These results underscore the role of leveraging symmetry in designing advanced intrusion detection systems, offering a structured and efficient solution for identifying cyberthreats.<\/jats:p>","DOI":"10.3390\/sym17050628","type":"journal-article","created":{"date-parts":[[2025,4,22]],"date-time":"2025-04-22T05:00:42Z","timestamp":1745298042000},"page":"628","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":10,"title":["Harnessing AI for Cyber Defense: Honeypot-Driven Intrusion Detection Systems"],"prefix":"10.3390","volume":"17","author":[{"ORCID":"https:\/\/orcid.org\/0009-0000-4472-5247","authenticated-orcid":false,"given":"Eman","family":"Alatawi","sequence":"first","affiliation":[{"name":"College of Computing and Information Technology, University of Tabuk, Tabuk 71491, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4852-3981","authenticated-orcid":false,"given":"Umar","family":"Albalawi","sequence":"additional","affiliation":[{"name":"College of Computing and Information Technology, University of Tabuk, Tabuk 71491, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2025,4,22]]},"reference":[{"key":"ref_1","unstructured":"Verma, R. (2024). Cybersecurity Challenges in the Era of Digital Transformation, Infinity Publication Pvt. Ltd."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"11","DOI":"10.1016\/S1361-3723(14)70480-4","article-title":"A larger problem: Financial and reputational risks","volume":"2014","author":"Pearson","year":"2014","journal-title":"Comput. Fraud. Secur."},{"key":"ref_3","first-page":"2283","article-title":"Machine learning applications of network security enhancement: Review","volume":"5","author":"Mahdi","year":"2024","journal-title":"Comput. Sci. Res. J."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"271","DOI":"10.30574\/wjaets.2024.13.1.0416","article-title":"Advancements in cybersecurity and machine learning: A comprehensive review of recent research","volume":"13","author":"Albtosh","year":"2024","journal-title":"World J. Adv. Eng. Technol. Sci."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Phulre, A.K., Jain, S., and Jain, G. (2024, January 24\u201325). Evaluating Security Enhancement Through Machine Learning Approaches for Anomaly-Based Intrusion Detection Systems. Proceedings of the 2024 IEEE International Students\u2019 Conference on Electrical, Electronics and Computer Science (SCEECS), Bhopal, India.","DOI":"10.1109\/SCEECS61402.2024.10482161"},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Vajpayee, P., and Hossain, G. (2024, January 15\u201324). Reduction of Cyber Value at Risk (CVaR) Through AI Enabled Anomaly Detection. Proceedings of the SoutheastCon 2024, Atlanta, GA, USA.","DOI":"10.1109\/SoutheastCon52093.2024.10500040"},{"key":"ref_7","first-page":"1023","article-title":"Detecting Anomalies and Intrusions in Unstructured Cybersecurity Data Using Natural Language Processing","volume":"12","author":"Arjunan","year":"2024","journal-title":"Int. J. Sci. Technol. Eng."},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Tushkanova, O., Levshun, D., Branitskiy, A., Fedorchenko, E., Novikova, E., and Kotenko, I. (2023). Detection of Cyberattacks and Anomalies in Cyber-Physical Systems: Approaches, Data Sources, Evaluation. Algorithms, 16.","DOI":"10.3390\/a16020085"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"5497","DOI":"10.14704\/WEB\/V19I1\/WEB19370","article-title":"Review of cyber attack detection: Honeypot system","volume":"19","author":"Amal","year":"2022","journal-title":"Webology"},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"666","DOI":"10.1080\/23080477.2024.2375457","article-title":"Corporate network anomaly detection methodology utilizing machine learning algorithms","volume":"12","author":"Baisholan","year":"2024","journal-title":"Smart Sci."},{"key":"ref_11","unstructured":"Highnam, K., Arulkumaran, K., Hanif, Z., and Jennings, N.R. (2021, January 23). BETH Dataset: Real Cybersecurity Data for Anomaly Detection Research. Proceedings of the ICML Workshop on Uncertainty and Robustness in Deep Learning, Virtual."},{"key":"ref_12","first-page":"100470","article-title":"Deep learning for anomaly detection in log data: A survey","volume":"12","author":"Landauer","year":"2023","journal-title":"Mach. Learn. Appl."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Diamantoulakis, P., Dalamagkas, C., Radoglou-Grammatikis, P., Sarigiannidis, P., and Karagiannidis, G. (2020). Game Theoretic Honeypot Deployment in Smart Grid. Sensors, 20.","DOI":"10.3390\/s20154199"},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Kandanaarachchi, S., Ochiai, H., and Rao, A. (2021). Honeyboost: Boosting honeypot performance with data fusion and anomaly detection. arXiv.","DOI":"10.1016\/j.eswa.2022.117073"},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"17372","DOI":"10.1109\/JIOT.2021.3080527","article-title":"Honeypot detection strategy against advanced persistent threats in industrial internet of things: A prospect theoretic game","volume":"8","author":"Tian","year":"2021","journal-title":"IEEE Internet Things J."},{"key":"ref_16","first-page":"643","article-title":"Strategic honeypot deployment in ultra-dense beyond 5g networks: A reinforcement learning approach","volume":"12","author":"Sarigiannidis","year":"2022","journal-title":"IEEE Trans. Emerg. Top. Comput."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"64075","DOI":"10.1109\/ACCESS.2020.2984795","article-title":"Prospect theoretic study of honeypot defense against advanced persistent threats in power grid","volume":"8","author":"Tian","year":"2020","journal-title":"IEEE Access"},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"4844","DOI":"10.1109\/TNSM.2024.3387710","article-title":"FedPot: A Quality-Aware Collaborative and Incentivized Honeypot-Based Detector for Smart Grid Networks","volume":"21","author":"Albaseer","year":"2024","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"ref_19","unstructured":"Rehman, M.U., Ahmadi, H., and Hassan, W.U. (2024, January 19\u201323). FLASH: A Comprehensive Approach to Intrusion Detection via Provenance Graph Representation Learning. Proceedings of the 2024 IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Mo, X., Zhang, Y., Zhang, L.Y., Luo, W., Sun, N., Hu, S., Gao, S., and Xiang, Y. (2024, January 19\u201323). Robust backdoor detection for deep learning via topological evolution dynamics. Proceedings of the 2024 IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA.","DOI":"10.1109\/SP54263.2024.00174"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Inam, M.A., Chen, Y., Goyal, A., Liu, J., Mink, J., Michael, N., Gaur, S., Bates, A., and Hassan, W.U. (2023, January 21\u201325). Sok: History is a vast early warning system: Auditing the provenance of system intrusions. Proceedings of the 2023 IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA.","DOI":"10.1109\/SP46215.2023.10179405"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"42","DOI":"10.1186\/s40537-020-00320-x","article-title":"A comprehensive survey of anomaly detection techniques for high dimensional big data","volume":"7","author":"Thudumu","year":"2020","journal-title":"J. Big Data"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Stolfo, S.J., Hershkop, S., Bui, L.H., Ferster, R., and Wang, K. (2005). Anomaly detection in computer security and an application to file system accesses. Lecture Notes in Computer Science, Springer.","DOI":"10.1007\/11425274_2"},{"key":"ref_24","unstructured":"(2024, December 02). Available online: https:\/\/www.kaggle.com\/datasets\/katehighnam\/beth-dataset\/data."}],"container-title":["Symmetry"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2073-8994\/17\/5\/628\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T17:19:12Z","timestamp":1760030352000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2073-8994\/17\/5\/628"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,4,22]]},"references-count":24,"journal-issue":{"issue":"5","published-online":{"date-parts":[[2025,5]]}},"alternative-id":["sym17050628"],"URL":"https:\/\/doi.org\/10.3390\/sym17050628","relation":{},"ISSN":["2073-8994"],"issn-type":[{"value":"2073-8994","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,4,22]]}}}