A Modular Generative Honeypot Shell

Saul Johnson, Remco Hassing, Jeroen Pijpker, Rob Loves · 2024

In this work, we present Limbosh, a generative honeypot shell written in Python that places attackers in a conversation with a large language model (LLM) configured to behave like a real shell. The use of generative AI in place of traditional honeypot shell software admits the development of arbitrary honeypot configurations by adjusting the prompt used to seed the LLM context. Key features of Limbosh include: a flexible prompt generation system based on text templating and reusable prompt fragments; the ability to make use of arbi-trary LLMs; sophisticated prompt injection mitigation measures; and a highly modular and configurable architecture permitting straightforward expansion of its feature set and enhancement of its capabilities. To demonstrate its utility and practicality, we ran a single-blind, within-subjects study of the interaction of four cybersecurity professionals with Limbosh compared to a control shell. We find that Limbosh is capable of convincingly emulating real shell software, even when faced with professional users. We present our experimental results, and make the Limbosh software itself open-source and freely available.

Read the paper · More papers on PaperTik