Identifying LLM‑Powered Cyber Attacks with Timing Analysis and Honeytoken‑Based Deception
Ahmed Sidibé, Shahvaly Mazlomyar · KTH Publication Database DiVA (KTH Royal Institute of Technology) · 2026
The rapid emergence of large language models capable of autonomous offensive action has introduced a qualitatively new category of attacker to internet-exposed systems. Existing SSH honeypot-based intrusion detection systems are designed around abinary classification problem distinguishing automated scripts from human operators and are fundamentally ill-equipped to handle the distinct behavioral and temporal footprint produced by an LLM-powered agent. As such tools become commercially accessible, this classification gap represents an unaddressed blind spot in current defensive practice. This thesis investigates whether LLM-powered attackers can be reliably distinguished from automated bots and human attackers in SSH honeypot environments, and proposes an integrated detection framework that combines three complementary signal modalities: network-level timing characteristics derived from packet captures, session- and command-level behavioral patterns extracted from honeypot interaction logs, and Unicode-based honeytoken deception that exploits the tokenization properties of large language models. A quantitative controlled experiment was conducted using two virtual machines deployed on IBM Cloud. A Cowrie SSH honeypot received attacks from fourteen commercial LLM models accessed through an autonomous offensive agent framework, as well as from automated scripted bots. A literature-derived behavioral profile served as the human attacker reference. Honeytoken artefacts embedding invisible Unicode characters were planted in the fake filesystem to assess whether LLM agents would reproduce these characters in their output a behavior neither human operators nor conventional scripts are likely to exhibit. Features were extracted from network packet captures and structured honeypot log files. The results demonstrate complete distributional separation between LLM-powered agents and automated bots across all evaluated models: inter-session timing gaps ranged from 3 to 15 seconds for LLM agents compared to 6 to 8 milliseconds for scripted attacks, corresponding to an approximately 375×–2500× difference. Honeytoken trigger rates varied across models, with URL-based tokens achieving the highest detection rates; the honeytokens where designed to detect LLMs not the automated bots. The findings establish that LLM-powered attackers produce a consistent and detectable operational footprint using only signals observable at the defended endpoint. Timing-based and deception-based signals are orthogonal and mutually reinforcing, providing the empirical foundation for a four-layer detection framework for three-class attacker classification in SSH honeypot environments.