提出首个评估大模型蜜罐的综合框架,让安全测试更可信、可复现。
Honeyval: A Comprehensive Evaluation Framework for LLM-powered HTTP Honeypots

- 用16个真实后端系统构建蜜罐,结合AI黑客代理模拟攻击
- 大模型蜜罐互动时长比规则基蜜罐长3倍以上,被高端模型检测率低40%
- 适合安全研究人员快速验证蜜罐有效性,尤其关注低成本防御方案
蜜罐是模仿真实系统组件的诱骗系统,用于防御网络攻击。近年来,大语言模型(LLM)越来越多地被用作蜜罐的仿真核心,使防御者能以低安全风险构建高交互蜜罐。然而,当前基于大模型的蜜罐开发缺乏统一评估框架,多数评估依赖固定命令响应相似性、人工测试或实际部署,难以规模化、复现、代表真实攻击场景,也无法适配不同攻防配置。本文提出Honeyval——一个面向大模型驱动的HTTP蜜罐的综合性评估框架。通过将蜜罐基于16个真实后端应用、使用AI黑客代理作为攻击者、引入两个控制任务监控攻击者与蜜罐能力,并明确定义可验证的漏洞利用目标。实验表明,大模型蜜罐在平均交互时长上显著优于规则基蜜罐(提升3倍以上),且即使面对前沿攻击模型也更难被检测(降低40%检测率),同时维持运行成本优势。此外,探索不同反制配置发现:延长交互时间会带来更高的被检测风险,揭示关键权衡。
原文摘要 · Abstract (English)
Honeypots are decoy systems mimicking real system components designed to defend against cyber attacks. Recently, LLMs increasingly serve as simulation backbones for honeypots. They enable defenders to construct high-interaction honeypots with low system security risks. However, LLM-powered honeypot development lacks a unified evaluation framework. Most evaluations consist of measuring response similarity on fixed commands, manual testing, or real-world deployment. These methods are often not scalable for development, reproducible across evaluations, representative of practical attacks, or adaptable to various attacker and honeypot configurations. In this work, we bridge this gap and propose Honeyval, a comprehensive evaluation framework for LLM-powered HTTP honeypots. We address the limitations of prior evaluations by grounding the honeypots in 16 backend applications, using AI hacking agents as attackers, employing two control tasks to monitor agent and honeypot capabilities across customizations, and defining clear and verifiable exploit goals for the attacker. Using Honeyval, we conduct an extensive evaluation of recent cost-efficient LLMs as HTTP honeypots. Our experiments highlight the promise of LLM-powered honeypots; they lead to substantially longer interactions with the attacker than rule-based baseline honeypots and are far less frequently detected even by frontier models, all while, on average, preserving a running cost advantage against agentic attackers. Further, we experiment with different counter-offensive honeypots configurations, and observe unique trade-offs, such as longer interactions at the cost of increased detection.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。