The growing exposure of IoT devices and industrial control systems (ICS) to the public Internet has significantly increased the attack surface. Most of the current systems still detect these threats only in retrospect. Honeypots are widely used to collect attack data, but they tend to surface only isolated alerts rather than the coordinated campaigns behind them. In this paper, we present CT-EWS, a cyber threat early warning system that treats adversarial activity as a dynamic multi-protocol campaign graph. Honeypot telemetry from heterogeneous protocols is aggregated centrally and fed into SOC-oriented workflows. Each interaction becomes a node, with edges drawn from temporal proximity, behavioral similarity, infrastructure overlap, and cross-protocol relationships. Community extraction over this graph reconstructs coordinated multi-stage campaigns and consolidates fragmented alerts into coherent campaigns. For campaign forecasting, we apply FARIMA-based long-memory modeling on the Largest Connected Component (LCC) of the campaign graph, gaining a lead time of 18–22 min over ARIMA baselines. SHAP-based attribution explains which behavioral signals contribute to each anomaly, with 91.4% rank-weighted feature relevance and an explanation fidelity of R2 = 0.88. The detected subgraphs are mapped to MITRE ATT&CK for ICS, covering 100% of tactics and 84% of techniques. On real Internet-facing honeypot traffic, CT-EWS achieves a Normalized Mutual Information (NMI) of 0.87 and an F1 score of 0.89 for campaign reconstruction, and stays stable under graph perturbations of up to 10%–20%. Together, relational graph modeling, long-memory forecasting, explainability, and ATT&CK-aligned context turn passive honeypot infrastructure into a proactive early warning capability.
CT-EWS: graph-centric early warning for multi-protocol cyber campaigns using long-memory forecasting and explainable attribution
Rakesh Matam

