Pith. sign in

REVIEW 4 cited by

HoneyGPT: Breaking the Trilemma in Terminal Honeypots with Large Language Model

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2406.01882 v2 pith:3XJKEVCY submitted 2024-06-04 cs.CR cs.AIcs.ETcs.SE

classification cs.CRcs.AIcs.ETcs.SE
keywords honeygptengagementevaluationbaselinecomparisondeceptiondepthengineering
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Honeypots, as a strategic cyber-deception mechanism designed to emulate authentic interactions and bait unauthorized entities, often struggle with balancing flexibility, interaction depth, and deception. They typically fail to adapt to evolving attacker tactics, with limited engagement and information gathering. Fortunately, the emergent capabilities of large language models and innovative prompt-based engineering offer a transformative shift in honeypot technologies. This paper introduces HoneyGPT, a pioneering shell honeypot architecture based on ChatGPT, characterized by its cost-effectiveness and proactive engagement. In particular, we propose a structured prompt engineering framework that incorporates chain-of-thought tactics to improve long-term memory and robust security analytics, enhancing deception and engagement. Our evaluation of HoneyGPT comprises a baseline comparison based on a collected dataset and a three-month field evaluation. The baseline comparison demonstrates HoneyGPT's remarkable ability to strike a balance among flexibility, interaction depth, and deceptive capability. The field evaluation further validates HoneyGPT's superior performance in engaging attackers more deeply and capturing a wider array of novel attack vectors.

Discussion (0). Sign in to comment.

Forward citations

Cited by 4 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score.

  1. Honeyval: A Comprehensive Evaluation Framework for LLM-powered HTTP Honeypots

    cs.CR 2026-05 unverdicted novelty 7.0 of 10

    Honeyval evaluates LLM HTTP honeypots with AI attackers and shows they produce longer interactions, lower detection rates, and cost advantages over rule-based baselines.

  2. Honeypot Protocol

    cs.CR 2026-04 unverdicted novelty 7.0 of 10

    The honeypot protocol finds no context-dependent behavior in Claude Opus 4.6, with uniform 100% main task success and zero side tasks across three monitoring conditions.

  3. Ghost Without Shell: Measuring Non-Interactive SSH Attacks on Honeypots

    cs.CR 2026-06 unverdicted novelty 6.0 of 10

    Large-scale SSH honeypot deployment shows 99.23% of authenticated sessions are non-interactive, suggesting most attacks do not involve shell interaction.

  4. LLMHoney: A Real-Time SSH Honeypot with Large Language Model-Driven Dynamic Response Generation

    cs.CR 2025-09 conditional novelty 4.0 of 10

    An LLM-driven SSH honeypot with a command cache can mimic a Linux shell, with Gemini-2.0 and 1.5 to 3.8B open models giving the best trade-off between fidelity and speed.

Pith tools