Honeypot is a sort of deception defense tool and deliberately created for capturing malicious behaviors. The trade-off between security risk and data availability often incurs arduous efforts. Since a high-interaction honeypot (HIH) can capture much deeper system-level data while it has to disclose the full operating system, which absolutely leads to a higher security risk. In contrast, a low-/medium-interaction honeypot (LIH/MIH) revealing empty or camouflaged services has a lower security risk while it can only capture network-level data such as port scanning, access attempts, etc. To tackle this issue, this paper proposes a large language model (LLM) powered medium-interaction honeypot system, termed HoneyLLM, which aims to provide an authentic shell based on LLM rather than a real operating system to spoof the attacker to be fully engaged with the “request-response” message interaction and leave useful data. A proof-of-concept system has been created and deployed for capturing real-world attacks. Our experiments demonstrate that this system outperforms traditional honeypots in effectiveness. HoneyLLM can capture not only network activities as LIH/MIH, but also delve deeper by capturing system activities, like HIH, providing a more complete picture of attacker activity. Despite the limited current exploration of LLMs for authentic response creation for honeypot (at the time of writing, 2024 May 4th), this research signifies a breakthrough in leveraging LLM for more deceptive and dynamic cyber defense mechanisms.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

HoneyLLM: A Large Language Model-Powered Medium-Interaction Honeypot

  • Wenjun Fan,
  • Zichen Yang,
  • Yuanzhen Liu,
  • Lang Qin,
  • Jia Liu

摘要

Honeypot is a sort of deception defense tool and deliberately created for capturing malicious behaviors. The trade-off between security risk and data availability often incurs arduous efforts. Since a high-interaction honeypot (HIH) can capture much deeper system-level data while it has to disclose the full operating system, which absolutely leads to a higher security risk. In contrast, a low-/medium-interaction honeypot (LIH/MIH) revealing empty or camouflaged services has a lower security risk while it can only capture network-level data such as port scanning, access attempts, etc. To tackle this issue, this paper proposes a large language model (LLM) powered medium-interaction honeypot system, termed HoneyLLM, which aims to provide an authentic shell based on LLM rather than a real operating system to spoof the attacker to be fully engaged with the “request-response” message interaction and leave useful data. A proof-of-concept system has been created and deployed for capturing real-world attacks. Our experiments demonstrate that this system outperforms traditional honeypots in effectiveness. HoneyLLM can capture not only network activities as LIH/MIH, but also delve deeper by capturing system activities, like HIH, providing a more complete picture of attacker activity. Despite the limited current exploration of LLMs for authentic response creation for honeypot (at the time of writing, 2024 May 4th), this research signifies a breakthrough in leveraging LLM for more deceptive and dynamic cyber defense mechanisms.