用大模型打造能与黑客互动的智能诱饵系统
LLM Honeypot: Leveraging Large Language Models as Advanced Interactive Honeypot Systems
- 用攻击者真实命令微调大模型,生成逼真交互响应
- 实测显示模型响应准确且信息丰富,可有效吸引攻击者
- 适合安全研究者和攻防演练人员使用
快速演进的网络威胁亟需创新的检测与分析方案。蜜罐作为诱骗并交互攻击者的诱饵系统,已成为网络安全的关键组件。本文提出一种利用大语言模型(LLMs)构建高仿真、可交互蜜罐的新方法。通过在多样化的攻击者生成命令与响应数据集上微调预训练开源语言模型,我们开发出能够与攻击者进行复杂交互的蜜罐系统。方法包括数据收集与处理、提示工程、模型选择及监督微调以优化性能。通过相似性度量评估与实时部署验证,结果表明该方法能生成准确且富有信息量的响应。研究凸显了大语言模型在革新蜜罐技术方面的潜力,为网络安全从业者提供了一种强大工具,有助于提升整体安全防护能力。
原文摘要 · Abstract (English)
The rapid evolution of cyber threats necessitates innovative solutions for detecting and analyzing malicious activity. Honeypots, which are decoy systems designed to lure and interact with attackers, have emerged as a critical component in cybersecurity. In this paper, we present a novel approach to creating realistic and interactive honeypot systems using Large Language Models (LLMs). By fine-tuning a pre-trained open-source language model on a diverse dataset of attacker-generated commands and responses, we developed a honeypot capable of sophisticated engagement with attackers. Our methodology involved several key steps: data collection and processing, prompt engineering, model selection, and supervised fine-tuning to optimize the model's performance. Evaluation through similarity metrics and live deployment demonstrated that our approach effectively generates accurate and informative responses. The results highlight the potential of LLMs to revolutionize honeypot technology, providing cybersecurity professionals with a powerful tool to detect and analyze malicious activity, thereby enhancing overall security infrastructure.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。