Honeypots are pretend subnetworks or knowledge storages that security teams deploy as decoys. These network segments have intentional flaws that appeal to attackers. Frequent users never access honeypots, so any action in that network space is definitely an indicator of 3rd-occasion presence. Security information and occasion management collects information https://www.researchgate.net/publication/365308473_Development_of_Cyber_Attack_Model_for_Private_Network