collaborators

7 papers

cs.CR2026

Improving LLM-Based SSH Honeypots Through Prompting and Fine-Tuning

Muris Sladić, Veronica Valeros, Eman Alibalić +1

LLM-based SSH honeypots often use closed cloud LLMs because they give strong shell realism, but cloud models create deployment problems. These include no stable versioning, provide…

cs.CR2026

Slips: Behavioral Evidence Aggregation for Network Security

Sebastian Garcia, Veronica Valeros, Alya Gomaa +7

Network intrusion detection systems often analyze individual packets or flows, although malicious behavior may develop across many connections and over time. This may limit their a…

cs.CR2026

Ghost Without Shell: Measuring Non-Interactive SSH Attacks on Honeypots

Veronica Valeros, Muris Sladić, Sebastian Garcia

Cyber deception research has focused on improving honeypot deception capabilities to increase attacker engagement and extend their interactions to collect more and better intellige…

cs.CR2026

AdvancedShelLM: A Stateful Multi-Agent LLM Honeypot for SSH Deception

Muris Sladić, Eman Alibalić, Veronica Valeros +2

LLM-based SSH honeypots can generate believable interactions, but evaluations indicate they remain somewhat identifiable to determined attackers, indicating the need for a better s…

cs.CR2026

Decoys Cannot Go Everywhere: Mapping the Deception Surface in MITRE ATT&CK

Veronica Valeros, Carlos Catania, Viliam Lisý +1

Cyber deception research often assumes that a decoy can be placed wherever there is attacker behavior. This work tests that assumption across MITRE ATT&CK v18.1. We introduce a fou…

cs.CR2025

VelLMes: A high-interaction AI-based deception framework

Muris Sladić, Veronica Valeros, Carlos Catania +1

There are very few SotA deception systems based on Large Language Models. The existing ones are limited only to simulating one type of service, mainly SSH shells. These systems - b…