Cyber Deception through LLM-Driven Infrastructure as Code: A Fine-Tuned Pipeline for Context-Aware Honeypot Generation
Riccardo Benedetti · AMS Degree Thesis (University of Bologna)
Cyberattacks against modern organizations are growing in both frequency and sophistication, exposing the limitations of traditional reactive defense strate- gies that rely on perimeter security devices such as firewalls and intrusion detection systems. Cyber deception has emerged as a promising proactive approach that shifts the attacker-defender asymmetry by introducing decoys and false targets into the network, forcing adversaries to expend significant re- sources distinguishing real assets from fake ones. Honeypots, systems designed to appear as legitimate targets while observing and recording attacker behav- ior, are at the core of this paradigm. However, deploying realistic and effective honeypots remains a labor-intensive process that requires deep knowledge of both the target infrastructure and the specific attack vectors being defended against. Manual configuration does not scale across diverse enterprise environ- ments, and static deployments are vulnerable to fingerprinting by sophisticated adversaries.