Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Honeypot: Har den geografiska platsen betydelse?
University West, Department of Engineering Science.
University West, Department of Engineering Science.
2025 (Swedish)Independent thesis Basic level (university diploma), 5 credits / 7,5 HE creditsStudent thesisAlternative title
Honeypot : Does the geographical location matter? (English)
Abstract [en]

In this project, honeypots have been configured and deployed via Google Cloud Platform in three geographically distinct locations: Sweden, the USA, and China. The purpose of the experiment is to examine whether the geographical placement of a honeypot affects attack patterns, with a particular focus on which ports attackers target in different regions.

To collect and analyze data, we have used T-PotCE, an advanced honeypot platform that integrates multiple honeypots to identify and log malicious activities. By monitoring and comparing attacks from the three different regions, we have been able to identify differ-ences in the most frequently targeted port numbers and the origin of these attacks.

The results show clear differences in attack patterns depending on geographical location.

For example, the honeypot in Sweden was primarily targeted by attacks on ports related to web and network services (80, 443, 445, 9200), while honeypots in the USA and China were more frequently attacked on port 5060, which is used for SIP (Session Initiation Pro-tocol). Furthermore, the analysis shows that attacks against Sweden mainly originated from the United States, while honeypots in the USA and China were largely attacked from Romania.

This study provides a deeper understanding of how cyber threats can vary depending on geographical location and how attackers target specific services in different parts of the world.

Place, publisher, year, edition, pages
2025. , p. 8
Keywords [en]
Honeypot, Cyber security, Cyber attack, Vulnerable gates, T-PotCE
National Category
Computer and Information Sciences
Identifiers
URN: urn:nbn:se:hv:diva-23738Local ID: EXN300OAI: oai:DiVA.org:hv-23738DiVA, id: diva2:1988347
Subject / course
Computer engineering
Educational program
Nätverksteknik med IT-säkerhet
Supervisors
Examiners
Available from: 2025-08-26 Created: 2025-08-11 Last updated: 2025-09-30Bibliographically approved

Open Access in DiVA

No full text in DiVA

By organisation
Department of Engineering Science
Computer and Information Sciences

Search outside of DiVA

GoogleGoogle Scholar

urn-nbn

Altmetric score

urn-nbn
Total: 89 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf