Abstract
As cyber adversaries increasingly leverage automation and artificial intelligence (AI) to evade conventional security mechanisms, static honeypots face growing challenges in maintaining effective deception and capturing meaningful threat intelligence. This presentation introduces Q-Cowrie, an AI-driven adaptive honeypot that extends the Cowrie medium-interaction honeypot by integrating Reinforcement Learning (RL) to enable autonomous decision-making and dynamic response generation during attacker interactions. The research addresses the limitations of conventional honeypots, which rely on static configurations and predefined responses that may be insufficient against evolving attack techniques. To support adaptive behaviour, real-world attack data collected from a deployed Cowrie honeypot was analysed to identify attackers’ objectives, tactics, and behavioural patterns. These observations were used to construct a Markov Decision Process (MDP) model representing attacker decision-making under different attack scenarios. The MDP model was subsequently integrated with Reinforcement Learning to enable Q-Cowrie to learn from attacker interactions and autonomously select adaptive responses while maintaining deception. Experimental evaluation demonstrated that the proposed framework enhances attacker behaviour analysis, intelligent threat intelligence collection, and adaptive response generation. The integration of AI enabled the honeypot to recognise attacker behavioural patterns, improve adaptability to evolving threats, and support more effective engagement during cryptomining and botnet attack scenarios. This presentation highlights how Reinforcement Learning can enhance modern honeypots by enabling intelligent, adaptive cyber defence, contributing to the development of next-generation AI-driven deception technologies for analysing attacker behaviour and strengthening proactive cybersecurity.