Distributed denial-of-service (DDoS) attack remains an exceptional security risk,

alleviating these digital attacks are for all intents and purposes extremely intense to
actualize, particularly when it faces exceptionally well conveyed attacks. The early
disclosure of these attacks, through testing, is critical to ensure safety of end-
clients and the wide-ranging expensive network resources. With respect to DDoS
attacks – its hypothetical establishment, engineering, and calculations of a
honeypot have been characterized. At its core, the honeypot consists of an
intrusion prevention system (Interruption counteractive action framework) situated
in the Internet Service Providers level. The IPSs then create a safety net to protect
the hosts by trading chosen movement data. The evaluation of honeypot promotes
broad reproductions and an absolute dataset is introduced, indicating honeypot’s
activity and low overhead. The honeypot anticipates such assaults and mitigates
the servers. The prevailing IDS are generally modulated to distinguish known
authority level system attacks. This spontaneity makes the honeypot system
powerful against uncommon and strange vindictive attacks.


The aim of a DDoS attack is to make any online administration’s application

impassable by stopping its progress from various onsets. They target a wide
collection of resources from banks to report sites and prompt a conspicuous test to
ensuring individuals, can disseminate and get to vital information [1]. In other
words, DDoS attack is triggered in which various adjudicate computer networks on
a targeted terminal for example, a server, site or other system resources and
motivate a dissent of organizational policy for clients of the direct-on resources.
While a DDoS assault may include one single PC simply running a DOS
"instrument", a DDoS attack is regularly significantly more supplicated. DDOS
attacks are generally done from inside Botnets. A botnet is a gathering of PCs that
have been gathered together without wanting to, more often than not in view of an
infection or some different noxious code.

When an online service is unavailable, it’s known as ‘denial of service’ (DoS). A

denial of service usually arises when individual IT infrastructure components are
overloaded. If external parties (attackers) cause this deliberately, it is called as a
DoS attack. This occurs when an attacker floods a target URL with so many
requests that the server can no longer process them all. This means that network
devices, operating systems, and individual server services are only able to respond
to requests in a delayed manner, if at all. A common abbreviation of DoS is known
as ‘distributed denial of service’ (DDoS). Instead of just using one computer, cyber
criminals overload systems with requests from many computers, which are
combined together to form gigantic botnets. It is a kind of attack when multiple
systems are connected and flooded with system bandwidth. The incoming traffic
flooding originates from many different sources.

Existing System:

These assaults happen when a performing artist misuses a zero-day powerlessness

to do a DDoS attack. A zero-day defencelessness is a framework or application
imperfection beforehand obscure to the seller and has not been settled or fixed.

It is known as a "zero-day" in light of the fact that once an imperfection is found

the seller has zero days (before revelation) to settle it. Zero-day DDoS assaults are
especially hard to shield against as they start from an obscure risk.

The selection of bug abundance programs by programming sellers and different

organizations are getting popular to incentivise security researchers to report
possible vulnerabilities.


Moreover, an assault can likewise be a mix of the three sorts recorded above,
which makes it much all the more trying for connections to battle.

Otherwise called “surges”, the aim of this attack is to flood the network with
seemingly lawful data (high volume) that it overpowers the networks data
transmission capacity thus causing a very slow or non-existent response. These
attacks form the bulk of DDoS attacks and are often carried out with a botnet
consisting largely of unsecured IOT devices.

Proposed System:

From the above discussions we came to know that even so many mechanisms are
identified, attackers still have opportunities to exploit the database. The aim of this
study is to analyze the efficiency and effectiveness of Virtual Honeypot [8] to
prevent Intrusion, adopting a covered approach instead of the traditional manner.
The motto of this experiment may accord to give a demo of a functional and
achievable solution, and also to focus on the accuracy and robustness to detect
intrusions & attacks.

Since Distributed denial-of-service (DDoS) attacks remain an extreme security

problem, mitigating these attacks require a cohesive implementation, notably when
it is triggered as a highly distributed attack. Although detection of these exploits
are extremely challenging, it is of paramount importance to save our end-users and
network resources.

The structural architecture, underlying theoretical foundation, and algorithms of a

Honeypot system have been defined to counter the complications arising from a
DDoS attack. The base logic of Honeypot are the intrusion prevention systems
designed to work at the ISPs.


The IPSs form a layer of virtual security rings enclosing the hosts to defend them
by swapping selected traffic information. The assessment of such a Honeypot
system using large-scale simulations and an extensive dataset is presented, to
demonstrate its efficacy and low operational cost, as well as its ability to support
additional distribution in legitimate networks.

The Honeypot system prevents such attacks and mitigates them. The common IDS
are generally designed to detect known service level network exploits and threats.
The indicated void area makes the concern computer network as vulnerable to
original and novel malicious attacks.

Module Description:

Honeypot system:

An important aspect of operation of the Honeypot system is that the intruder needs
to be somehow given the access to the system without arousinghis suspicion. A
module called the system entry point, representing a special instance of the
Honeypot system, is responsible for solving this problem. The system entry point
must fulfill all the requirements described above and have the abovementioned
components for the system instances. Along with this, it has an additional
component that allows an intruder to gain access to its operating system.

Domain Name:

Various methods can be used for such task. One them can be usage of special e-
mail addresses having domain name of the enterprise. Also it is possible to pass
registration on any specialized network resources that correspond with specifics of
the enterprise, using the data of e-mail addresses, or make them publicvia any other
way. Intruders who target information systems can use such addresses to send out
letters containing malicious software, and gain access to the system upon its
launching. The entry point is checking all received e-mails and, in case of finding
attachments to them, tries opening them.

Safe storage:

Safe storage and systematization for further and deeper analysis should be ensured
for the information gathered during the research. In this article, each instance of the
Honeypot system, upon occurrence of an event, secretly sends information about it
to a special server that is part of the system - a storage device for the events
occurred. Such server should store received information about the events that
occurred at the Honeypot system instances. Analyzing actions of the intruder, the
researcher, facilitated with this server, should have opportunity to restore the
history of the events and study received copies of malicious software. The work of
the entire proposed system can be described as follows.

Malicious Software:

The Honeypot system instance, herein called the entry point, expects
correspondence incoming to the abovementioned e-mail addresses. When an e-
mail containing attachment arrives, its contents are launched. Was such content a
malware, certain events in the operating system would be logged by the event
recorder and would be immediately sent to the event storage device, another
component of the considered Honeypot system. Further, all activity of malicious
software in the system along with actions of the intruders, including those aimed at
gaining access to other instances of the Honeypot system.


 System : Pentium IV 2.4 GHz.

 Hard Disk : 40 GB.

 Monitor : 15 inch VGA Color.

 Mouse : Logitech Mouse.

 Ram : 512 MB

 Keyboard : Standard Keyboard


 Operating System : Windows XP.


 Tool : Python 3.6

 Front End : Python anaconda script

 Back End : Spyder


The Python standard for database interfaces is the Python DB-API. Most Python database
interfaces adhere to this standard.

You can choose the right database for your application. Python Database API supports a wide
range of database servers such as −

 GadFly
 mSQL
 PostgreSQL
 Microsoft SQL Server 2000
 Informix
 Interbase
 Oracle
 Sybase

The DB API provides a minimal standard for working with databases using Python structures
and syntax wherever possible. This API includes the following:

 Importing the API module.

 Acquiring a connection with the database.
 Issuing SQL statements and stored procedures.
 Closing the connection

We have implemented a hybrid algorithm for deploying honeypot, which mitigates
the DDOs attacks and avoids the further damage to the system. In general,
Honeypots will attract the attackers to its own path in the internet. Therefore, the
attacker without knowing that they are attracted and trapped in the honeypot, and
also their IP address gets blocked. We have experimented this approach in our
research for powerful security environments as shown in the relevant screen shots.
Various security levels have been maintained to get optimized results.


The scope for further research in this area is very high, which may include efforts
for development signature verification systems using the extracted features that or
of significance. These trained signature-based systems could be deployed at the
outer edge nodes of the network to filter the triggered exploits that are well known
and often used. This experiment may be extended as virtual roaming honeypots for
preventing intrusions with mitigative.


This experiment is carried out to study the features of virtual honeypots, and it also
its mitigative capacity in terms of protective measures. DDoS attack was triggered
and its expletive scenarios with effect on the network are studied. This study will
be helpful to the research community for further exploration on network security


[1] Mirza M, Usman M, Biuk-Aghai RP, Fong S. A Modular Approach for

Implementation of Honeypots in Cyber Security. International Journal of Applied
Engineering Research. 2016;11(8):5446-51.

[2] Selvaraj R, Kuthadi VM, Marwala T. Ant-based distributed denial of service

detection technique using roaming virtual honeypots. IET Communications. 2016
May 19;10(8):929-35.

[3] Somwanshi AA, Joshi SA. Implementation of Honeypots for Server Security.
International Research Journal of Engineering and Technology (IRJET). 2016
[4] Karthikeyan R, Geetha DT, Shyamamol KS, Sivagami G. Advanced Honey Pot
Architecture for Network Threats Quantification. The international journal of
Engineering and Techniques. 2017 Mar;3(2):2395-1303.

[5] Sharma N, Singh G. Intrusion detection system using shadow honeypot.

International Journal of Emerging Technology and Advanced Engineering. 2012

[6] Al-Ali Z, Al-Duwairi B, Al-Hammouri AT. Handling system overload resulting

from DDoS attacks and flash crowd events. In Cyber Security and Cloud
Computing (CSCloud), 2015 IEEE 2nd International Conference on 2015 Nov 3
(pp. 512-512).IEEE.

[7] David J, Thomas C. DDoS attack detection using fast entropy approach on
flow-based network traffic. Procedia Computer Science. 2015 Jan 1;50:30-6.\

[8] Deshpande HA. HoneyMesh: Preventing Distributed Denial of Service Attacks

using Virtualized Honeypots. arXiv preprint arXiv:1508.05002. 2015 Aug 20.

[9] Fichera S, Galluccio L, Grancagnolo SC, Morabito G, Palazzo S. OPERETTA:

An OPEnflow-based REmedy to mitigate TCP SYNFLOOD Attacks against web
servers. Computer Networks. 2015 Dec 9;92:89-100.

[10] Lu Y, Wang M. An easy defense mechanism against botnet-based DDoS

flooding attack originated in SDN environment using sFlow. In Proceedings of the
11th International Conference on Future Internet Technologies 2016 Jun 15 (pp.
14-20). ACM.

