honeysite deployment

Designs and deploys decoy web sites (honeysites/web honeypots) and their surrounding infrastructure to attract, emulate, and observe automated or human adversaries. Builds layered telemetry, configurable anti-bot defenses, and orchestration tooling for controlled agent interactions, and analyzes logs and experiment results to measure bypass rates, failure modes, and capture multi-layer traces.

honeysitedeployment

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
0.05
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$200K/year
Oct 01, 2026Oct 01, 2026

Must-Read Papers

Most classic and influential ideas
View more

This study addresses the inability of traditional honeypots to counter the dynamic attack strategies employed by autonomous penetration testing agents. We propose the first closed-loop dynamic deception framework tailored for autonomous agents, integrating sentinel endpoint detection, application-layer stateful deception, and behavior-guided attack escalation techniques. This architecture enables continuous entrapment, controlled disclosure, and forensic evidence collection regarding agent behaviors. Experimental evaluations demonstrate that the proposed system reduces the attack success rate against genuine targets by 79.2% and successfully extracts attacker API keys in 18.8% of execution instances. These findings establish a novel paradigm for defending against AI agent-driven threats.

adaptive defenseautonomous penetration testing agentshoneypot

This work addresses the limitations of existing adversarial simulation tools, which rely on agent-based instrumentation of target systems, often leaving anomalous artifacts and failing to faithfully replicate human attacker behavior—particularly in critical phases of the cyber kill chain such as initial access and interactive operations. To overcome these shortcomings, the authors propose and implement an open-source attack scripting language coupled with an agentless execution engine that closely emulates real-world attacker tactics. This approach enables high-fidelity, interactive simulation of complete kill chain stages, including initial access, privilege escalation, and lateral movement. Experimental results demonstrate that system logs generated by this method exhibit significantly greater behavioral similarity to those produced by actual human-driven attacks, thereby enhancing the realism and effectiveness of security testing and intrusion detection research.

adversary emulationattack automationcyber attack scenarios

Industrial Control Systems (ICS) face escalating cyber threats due to increased connectivity, yet conventional honeypots—relying on firmware reverse engineering and expert-crafted rules—struggle to efficiently and realistically emulate multi-vendor protocols and PLC control logic. To address this, we propose the first large language model (LLM)-based, dynamically configurable ICS honeypot framework, leveraging LLaMA-3 and Qwen. Our approach integrates protocol semantic parsing, prompt-engineered control logic generation, and finite-state machine modeling to enable zero-shot, vendor-agnostic automation of both protocol and control behavior simulation. Evaluated across seven industrial protocols and twelve representative control scenarios, our framework achieves 98.2% session-level interaction fidelity, improves attack traffic capture rate by 3.8×, and reduces configuration time from hours to seconds—effectively overcoming the core bottlenecks of high manual effort and poor generalizability in ICS honeypot deployment.

Automate realistic ICS honeypot creation using LLMsEliminate manual effort in mimicking industrial protocolsEnhance cyber threat detection in critical infrastructures

This work addresses a novel class of social engineering attacks targeting web automation agents, which exploit induced contextual cues to manipulate agent behavior—threats that existing defenses struggle to mitigate. We introduce AgentBait, the first attack framework specifically designed for web-based intelligent agents, and propose SUPERVISOR, a lightweight, plug-and-play runtime protection module that blocks such attacks by verifying the consistency between the web environment and the agent’s intended task. Experimental evaluation demonstrates that AgentBait achieves an average success rate of 67.5% against mainstream agent frameworks, whereas integrating SUPERVISOR reduces this success rate by 78.1% with only a 7.7% runtime overhead, effectively balancing security and usability.

AgentBaitattack surfaceLLM-based agents

HoneyGPT: Breaking the Trilemma in Terminal Honeypots with Large Language Model

Jun 04, 2024
ZW
Ziyang Wang
🏛️ Chinese Academy of Sciences | University of Chinese Academy of Sciences | Sangfor Technologies Inc. | Virginia Tech | Shenzhen Institute of Advanced Technology

Existing endpoint honeypots struggle to simultaneously achieve flexibility, deep interactivity, and high deception fidelity, limiting their effectiveness against novel attacks. This paper introduces HoneyGPT—the first ChatGPT-based endpoint honeypot system—designed to reconcile these competing objectives. Leveraging a novel structured Chain-of-Thought (CoT) prompting framework, HoneyGPT integrates long-term memory, dynamic interaction modeling, and semantic parsing of security logs, enabling the first systematic co-optimization of all three capabilities. Baseline experiments demonstrate significant improvements in the balanced performance across flexibility, interactivity, and deception metrics. During a three-month real-world deployment, HoneyGPT increased detection of previously unseen attack vectors, extended attacker average interaction duration by 3.2×, and achieved a deception success rate of 91.4%.

Adapting to evolving attacker tacticsEnhancing honeypot interaction depthImproving honeypot deception capabilities

Latest Papers

What's happening recently
View more

This work addresses the challenge of reconstructing adversarial attack contexts in cloud environments, where attackers often leverage legitimate identities and native APIs to operate stealthily, rendering vast telemetry data ineffective for forensic analysis. The authors propose a high-fidelity cloud deception framework synergized with an autonomous large language model (LLM) agent. Their approach introduces a novel session aggregation operator based on provider-specific identifier fields and a two-stage dynamic prompt generation mechanism. This ensures that all inference remains strictly grounded in observed evidence while mitigating indirect injection risks inherent in log-driven prompting. Evaluated across ten controlled AWS S3 attack scenarios, the system successfully reconstructed nine complete attack chains, with every reported assertion traceable to original artifacts and an average response latency of only 4–5 minutes.

cloud securitydeceptionintrusion investigation

This work addresses the vulnerability of existing deception-based defenses, which rely on static decoys that advanced autonomous penetration agents can readily identify and bypass. To overcome this limitation, the authors propose a trajectory-adaptive deception system that dynamically generates context-aware decoy artifacts based on the agent’s behavioral trajectory. By integrating a validation mechanism with incremental fusion techniques, the system constructs a factually consistent and coherently evolving deceptive environment. Evaluated across 15 CVE-Bench applications and three attack models, the system effectively delays and misdirects attacks: it absorbs 46.8% of tool invocations, traps 55.9% of subsequent actions within the deceptive environment, and leads 90.0% of attack reports to rely on fabricated evidence. Critically, none of the 45 attack–vulnerability pairings succeeded in compromising the real target.

attack trajectoryautonomous penetration agentsdeception defense

Hot Scholars

AS

Anwar Shah

Assistant Professor @ FAST National University of Computer and Emerging Sciences
ML/DL/LLMs3WDsBIFCybersecurity
SI

Shereen Ismail

Merit Network Inc., University of Michigan
Wireless NetworksIoTCybersecurityMachine Learning
SS

Sebastian Schinzel

Münster University of Applied Sciences, Fraunhofer SIT, Athene
Computer Security
WR

Walter Rudametkin

Full Professor @ University of Rennes / IRISA / Inria / IUF
Browser FingerprintingWebPrivacySoftware Engineering
AA

Arghavan Asad

Toronto Metropolitan University, Toronto, Ontario, Canada
Heterogeneous ComputingMemory Architectures