4 papers
AdvancedShelLM: A Stateful Multi-Agent LLM Honeypot for SSH Deception
Muris SladiÄ, Eman AlibaliÄ, Veronica Valeros +2
LLM-based SSH honeypots can generate believable interactions, but evaluations indicate they remain somewhat identifiable to determined attackers, indicating the need for a better s…
Decoys Cannot Go Everywhere: Mapping the Deception Surface in MITRE ATT&CK
Veronica Valeros, Carlos Catania, Viliam Lisý +1
Cyber deception research often assumes that a decoy can be placed wherever there is attacker behavior. This work tests that assumption across MITRE ATT&CK v18.1. We introduce a fou…
Evaluating Generalization Mechanisms in Autonomous Cyber Attack Agents
OndÅej Lukáš, Jihoon Shin, Emilia Rivas +6
Autonomous offensive agents often fail to transfer beyond the networks on which they are trained. We isolate a minimal but fundamental shift -- unseen host/subnet IP reassignment i…
VelLMes: A high-interaction AI-based deception framework
Muris SladiÄ, Veronica Valeros, Carlos Catania +1
There are very few SotA deception systems based on Large Language Models. The existing ones are limited only to simulating one type of service, mainly SSH shells. These systems - b…