Realism i Honeypots och dess påverkan på angriparbeteenden : Utvärdering och analys
André Rydsäter Kaufman · KTH Publication Database DiVA (KTH Royal Institute of Technology) · 2026
SSH honeypots are an established means of attracting and redirecting unwanted traffic away from real systems, allowing attacker behaviour to be observed and studied under controlled conditions. When such systems are exposed to the open Internet, the data they collect is partly influenced by their configuration. This report examines how different configurations affect the attacker behaviours observed, and to what degree the patterns that emerge can be attributed to each respective setup. For this purpose, the honeypot platform Cowrie was deployed in four configurations: a shell emulator returning predefined responses, a proxy forwarding connections to a real system, a more realistically configured proxy whose backend environment was designed to resemble a commonly misconfigured host, and a mode in which responses were generated in real time by a large language model. Over ten days of data collection, 424,042 events were recorded, across 75,755 completed SSH interactions, with each session analysed for properties such as login activity, command input, file transfers, and port forwarding requests, among others. Machine learning was subsequently applied to these properties in order to identify recurring behavioural patterns and examine their distribution across the four configurations. Pre-authentication behaviour was largely similar across setups, with most of traffic consisting of password guessing attempts and short lived connections that did not progress further. Post-authentication, however, the differences became considerably more pronounced. The proxy-based configurations attracted a broader range of connecting clients, produced more extensive command input, and captured more varied activity than the other setups. The LLM mode, by contrast, generated very little post-authentication activity, indicating that real time generated responses were not convincing enough to sustain a credible interaction in this configuration. The clustering results confirmed these findings, with the resulting distribution aligning closely with the four configurations despite honeypot setup not being included as input. The results suggest that a honeypot’s capacity to convincingly resemble a real system has a bearing on how attackers interact with it, as this can affect the extent and variety of interactions and give rise to more sustained engagement after authentication.