Increasing attacker engagement on SSH honeypots using semantic embeddings of cyber-attack patterns and deep reinforcement learning

Junior Samuel López-Yépez, Antoine Fagette · 2022 IEEE Symposium Series on Computational Intelligence (SSCI) · 2022

In this article, we demonstrate how combining semantic embeddings of cyber-attack patterns and deep reinforcement learning (DRL) can increase the engagement of attackers in interactive honeypots. We use a dataset of real-world cyber-attacks to pre-train, train and test our system. Our results show that our implementation is effective at increasing attackers' engagement compared to non-interactive honeypots or tabular reinforcement learning algorithms. In addition, we present how the inclusion of pattern data, as opposed to only current data increases significantly the engagement of artificial attackers in a simulated environment.

Read the paper · More papers on PaperTik