6 papers
Slips: Behavioral Evidence Aggregation for Network Security
Sebastian Garcia, Veronica Valeros, Alya Gomaa +7
Network intrusion detection systems often analyze individual packets or flows, although malicious behavior may develop across many connections and over time. This may limit their a…
Ghost Without Shell: Measuring Non-Interactive SSH Attacks on Honeypots
Veronica Valeros, Muris SladiÄ, Sebastian Garcia
Cyber deception research has focused on improving honeypot deception capabilities to increase attacker engagement and extend their interactions to collect more and better intellige…
AdvancedShelLM: A Stateful Multi-Agent LLM Honeypot for SSH Deception
Muris SladiÄ, Eman AlibaliÄ, Veronica Valeros +2
LLM-based SSH honeypots can generate believable interactions, but evaluations indicate they remain somewhat identifiable to determined attackers, indicating the need for a better s…
VelLMes: A high-interaction AI-based deception framework
Muris SladiÄ, Veronica Valeros, Carlos Catania +1
There are very few SotA deception systems based on Large Language Models. The existing ones are limited only to simulating one type of service, mainly SSH shells. These systems - b…
ARACNE: An LLM-Based Autonomous Shell Pentesting Agent
Tomas Nieponice, Veronica Valeros, Sebastian Garcia
We introduce ARACNE, a fully autonomous LLM-based pentesting agent tailored for SSH services that can execute commands on real Linux shell systems. Introduces a new agent architect…
LLM in the Shell: Generative Honeypots
Muris SladiÄ, Veronica Valeros, Carlos Catania +1
Honeypots are essential tools in cybersecurity for early detection, threat intelligence gathering, and analysis of attacker's behavior. However, most of them lack the required real…