A honeypot is a trap on a network that lures and studies cyber-attack techniques of threat actors, alerting defenders to unauthorized access attempts.
Though Honeypots help and assist cybersecurity researchers in several ways, they can also be used by cybercriminals to trick and mislead cybersecurity researchers.
Recently, the following cybersecurity researchers from their respective universities and organizations found a new AI-based honeypot dubbed “shelLM,” to engage attackers as a real system:-
To create sheLLM, experts used various prompts to instruct the LLM, emphasizing:-
Besides this, for better outputs and performance, they also used the following key things:-
The researchers aimed to create an LLM honeypot indistinguishable from a real system. They used an LLM to simulate a Linux terminal via SSH and tested it with 12 users of varying security expertise, analyzing their ability to detect it.
Experiments studied human interactions with cloud-based LLM honeypots, assigning unique instances to participants who logged in, interacted with, and emailed their answers.
Participants knew it was a honeypot; the focus was on whether the output appeared normal. However, they provided command-specific feedback via:-
For this honeypot evaluation, errors were categorized as false positives (misidentifying real as a honeypot), false negatives (misidentifying honeypot as real), and true positives/negatives.
Here below, we have mentioned the error interpretations
Here below, we have mentioned all the methods that are used:-
12 users tested the honeypot with 226 commands, mostly involving package, file, network, and system management. The following are the top ten commands with an average of 19 commands per user:-
In command evaluation, the following results were revealed:-
In this study, security researchers used LLMs to create a convincing honeypot system generating synthetic data, validated by experts with 92% accuracy.
Keep informed about the latest Cyber Security News by following us on Google News, Linkedin, Twitter, and Facebook.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…