Aug 28 – 30, 2026
Asia/Kolkata timezone

Defense-by-Deception: Securing Web Authentication Endpoints Using Adaptive Honeypots

Aug 30, 2026, 12:05 PM
20m
Room 2

Room 2

Talk (20 min) Security

Speaker

Sankalp Bansal

Description

"Keep your friends close, but your enemies closer." That idea is the foundation of HALT. HALT is a modular web authentication security framework that I developed during my internship at DRDO. Authentication endpoints are one of the most common targets for attacks such as credential stuffing, brute-force attempts, password spraying, automated bots, and reconnaissance. HALT is designed to transform these endpoints from merely being an attack surface into valuable sources of threat intelligence.

HALT evaluates every incoming authentication request in real time using request metadata, behavioral indicators, and configurable detection rules. Rather than immediately rejecting suspicious requests, it silently redirects high-risk users to a honeypot environment. This allows attackers to continue interacting with the system while their activity is monitored. These events can be visualized on a SOC dashboard or integrated with external logging and analysis platforms.

In this talk, I will present the architecture behind HALT, explain how authentication requests are evaluated and redirected, and demonstrate the complete system in action. The session will show how cyber deception can transform a traditional login endpoint from a passive line of defense into an active source of threat intelligence.

Project Repository: The HALT Project (Github)

Special accommodations

I will be bringing my own laptop. I am not sure how we will be connecting to the projectors, sometimes my laptop glitches during wireless connections, but it has a HDMI port, so please ensure availability of HDMI cable.

Laptop: HP Victor Ryzen 5 5600H GTX 1680

Requirement: HDMI Cable (for backup) if connection is wireless

Session author's bio

The author of this talk is Sankalp Bansal (myself). I am final year B.Tech. student at MNNIT Allahabad. I am a security enthusiast, and an open-source contributor for OWASP Nettacker Project.

Any other info we should know?

The topic is technical in nature and is mainly directed to people who are interested in security and novel concepts. My presentation will not be interactive, however I will have a QnA session at the end of my presentation.

Agree to Privacy Policy and Notice I agree
Please confirm that there are included headshots of all speakers in their profiles Yes
In Person Attendance In-person
Level of Difficulty Intermediate
Social Media https://www.linkedin.com/in/sankalpb1401/

Presentation materials