arXiv:2512.07827cs.CRcs.DC2025-12被引 2

用AI动态调度蜜罐,高效捕获黑客攻击行为

An Adaptive Multi-Layered Honeynet Architecture for Threat Behavior Analysis via Deep Learning

  • 基于强化学习实时决定何时升级蜜罐层级
  • 可自动提取、聚类并版本化僵尸网络攻击链
  • 适合需要低成本高价值威胁情报的安全部门

日益复杂的网络威胁使传统静态蜜罐失效,本文提出ADLAH:一种自适应深度学习异常检测蜜网架构,通过自主编排基础设施,在最小化成本的同时最大化高保真威胁情报获取。核心贡献为端到端AI驱动欺骗平台的架构蓝图。原型验证了中心决策机制的可行性,其中强化学习(RL)代理实时判断应将低交互传感器节点会话升级至动态部署的高交互蜜罐。由于缺乏足够真实数据,未宣称大规模现场验证,但详述了设计权衡与局限,并提供了可扩展实证评估路线图。除选择性升级与异常检测外,该架构还实现自动化攻击链提取、聚类与版本管理,这一能力源于观察到暴露服务主要受自动化流量主导。这些要素共同构建了一条可行路径,实现低成本捕获高价值攻击行为、系统化僵尸网络版本追踪及可操作威胁情报生成。

原文摘要 · Abstract (English)

The escalating sophistication and variety of cyber threats have rendered static honeypots inadequate, necessitating adaptive, intelligence-driven deception. In this work, ADLAH is introduced: an Adaptive Deep Learning Anomaly Detection Honeynet designed to maximize high-fidelity threat intelligence while minimizing cost through autonomous orchestration of infrastructure. The principal contribution is offered as an end-to-end architectural blueprint and vision for an AI-driven deception platform. Feasibility is evidenced by a functional prototype of the central decision mechanism, in which a reinforcement learning (RL) agent determines, in real time, when sessions should be escalated from low-interaction sensor nodes to dynamically provisioned, high-interaction honeypots. Because sufficient live data were unavailable, field-scale validation is not claimed; instead, design trade-offs and limitations are detailed, and a rigorous roadmap toward empirical evaluation at scale is provided. Beyond selective escalation and anomaly detection, the architecture pursues automated extraction, clustering, and versioning of bot attack chains, a core capability motivated by the empirical observation that exposed services are dominated by automated traffic. Together, these elements delineate a practical path toward cost-efficient capture of high-value adversary behavior, systematic bot versioning, and the production of actionable threat intelligence.

蜜罐AI安全威胁情报

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。