arXiv:2510.06975cs.CRcs.AI2025-10被引 10

用大模型打造可骗人的多协议蜜罐,真实感强且能抗真人攻击。

VelLMes: A high-interaction AI-based deception framework

  • 基于大模型构建多协议蜜罐,支持SSH、MySQL等常见服务模拟。
  • 89名真人攻击者中30%误判为真实系统,证明欺骗效果显著。
  • 实网部署10个实例,对非结构化攻击响应准确率高,适合实战测试。

目前基于大语言模型的先进欺骗系统极少,现有系统仅能模拟单一服务(如SSH shell),且缺乏对人类攻击者的全面评估。生成式AI已成为网络安全研究的重要工具,可用于创建逼真的蜜饵、假用户甚至模拟系统作为蜜罐。本文提出名为VelLMes的AI驱动欺骗框架,可模拟多种协议与服务,包括SSH Linux shell、MySQL、POP3和HTTP,均可用作蜜罐,满足多样化欺骗需求。该框架专为人类攻击设计,强调交互性与真实性。我们评估了生成能力与欺骗能力:生成能力通过大模型单元测试验证,结果显示在精心提示下部分模型能达到100%通过率;针对SSH Linux shell的欺骗能力评估中,89名真人攻击者有约30%误认为是真实系统。此外,我们在互联网上部署了10个SSH Linux shell蜜罐实例,分析显示这些基于LLM的蜜罐能有效应对真实世界中的非结构化和意外攻击,对多数命令响应正确。

原文摘要 · Abstract (English)

There are very few SotA deception systems based on Large Language Models. The existing ones are limited only to simulating one type of service, mainly SSH shells. These systems - but also the deception technologies not based on LLMs - lack an extensive evaluation that includes human attackers. Generative AI has recently become a valuable asset for cybersecurity researchers and practitioners, and the field of cyber-deception is no exception. Researchers have demonstrated how LLMs can be leveraged to create realistic-looking honeytokens, fake users, and even simulated systems that can be used as honeypots. This paper presents an AI-based deception framework called VelLMes, which can simulate multiple protocols and services such as SSH Linux shell, MySQL, POP3, and HTTP. All of these can be deployed and used as honeypots, thus VelLMes offers a variety of choices for deception design based on the users' needs. VelLMes is designed to be attacked by humans, so interactivity and realism are key for its performance. We evaluate the generative capabilities and the deception capabilities. Generative capabilities were evaluated using unit tests for LLMs. The results of the unit tests show that, with careful prompting, LLMs can produce realistic-looking responses, with some LLMs having a 100% passing rate. In the case of the SSH Linux shell, we evaluated deception capabilities with 89 human attackers. The results showed that about 30% of the attackers thought that they were interacting with a real system when they were assigned an LLM-based honeypot. Lastly, we deployed 10 instances of the SSH Linux shell honeypot on the Internet to capture real-life attacks. Analysis of these attacks showed us that LLM honeypots simulating Linux shells can perform well against unstructured and unexpected attacks on the Internet, responding correctly to most of the issued commands.

AI欺骗蜜罐大模型网络安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。