Enhancing Honeypot Fidelity with Real-Time User Behavior Emulation
Songsong Liu, Shu Wang, Kun Sun · 2023
Honeypot is an effective tool widely adopted in security systems, providing rich information to lure attackers. However, honeypots are not foolproof and can be detected by sophisticated attackers via specific features, e.g., the lack of real user activities. In this paper, we propose HoneyMustard, a real-time application-level user behavior emulation framework to enhance the fidelity of honeypots. HoneyMustard can emulate GUI-based user activities in the honeypots by a remote desktop connection. Because attackers can only observe the remote connection during the emulation, HoneyMustard can conceal the emulator as a normal service so that it achieves real-time user emulation without being detected. The user activities are emulated by reproducing real user operations or converting application manuals, ensuring that attackers can observe logical activities at an application level. We implement a prototype of HoneyMustard and evaluate the decoy effectiveness and overhead. The experimental results show that our solution can effectively improve the fidelity of honeypots with a low overhead.