Hypnotic Honey: Adaptive Honeypots Managed by Local Large Language Models

Lewis O. P. Childs, Mark A. Wood · 2024

A honeypot is a system designed to be attacked, aiming to deceive threat actors by mimicking a target network of interest. The hope is that by interacting with the honeypot, adversaries will reveal their tactics, techniques and procedures (TTPs), allowing network defenders to take preventative action. Existing honeypots are often tied to the exact system they are imitating, with limited ability to generalise. This work investigates how custom fine-tuned large language models (LLMs) and traditional honeypot methods can be combined to create a honeypot (named Hypnotic Honey; HH) capable of adapting in real time to attacker behaviour. Initial experiments revealed that greater reliance on the LLM increased the duration of attacker engagement, but at some cost to output consistency. Multiple levels of the tradeoff between LLM and proxied shell interaction were tested, and the optimal balance was identified. Adding togglable modules to manage functions such as an artificial file system and output persistence also improved performance, and highlighted potential pathways for further development. The resultant system was able to keep attackers engaged over multiple steps with a significantly reduced impact on consistency, especially when handling more commonly used commands and service discovery attempts.

Read the paper · More papers on PaperTik