Beekeeper: Accelerating Honeypot Analysis with LLM-driven Feedback
Author(s) -
Niclas Ilg,
Dominik Germek,
Paul Duplys,
Michael Menth
Publication year - 2025
Publication title -
ieee access
Language(s) - English
Resource type - Magazines
SCImago Journal Rank - 0.587
H-Index - 127
eISSN - 2169-3536
DOI - 10.1109/access.2025.3613118
Subject(s) - aerospace , bioengineering , communication, networking and broadcast technologies , components, circuits, devices and systems , computing and processing , engineered materials, dielectrics and plasmas , engineering profession , fields, waves and electromagnetics , general topics for engineers , geoscience , nuclear engineering , photonics and electrooptics , power, energy and industry applications , robotics and control systems , signal processing and analysis , transportation
Honeypots are decoy resources intended to entice adversaries and collect threat intelligence in the process. The amount and quality of the collected insights strongly correlate with the honeypot’s credibility to the adversary. However, the development of medium to high interaction honeypots, so, environments that offer at minimum a shell to the attacker, is laborious and complex. Additionally, getting feedback on a honeypot is often expensive and time-consuming, slowing down development and discouraging investment into honeypots. Therefore, we propose Beekeeper: a modular framework that combines static tests, known attack sequences, and automated, large language model based querying to investigate medium to high interaction honeypots. Afterward, the results are analyzed to provide feedback on the current state of the system and recommendations on how to improve key characteristics of the honeypot. To demonstrate the framework’s functionalities, we deploy Beekeeper with two medium and one high interaction systems and highlight how feedback and recommendations change after an initial set of improvements is implemented for each honeypot.
Accelerating Research
Robert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom
Address
John Eccles HouseRobert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom