发表机构
Technical University of Denmark(丹麦技术大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文提出Rouxii框架,使AI渗透测试者能识别并利用蜜罐,将识别率从19%提升至97%,并演示了反制蜜罐的拒绝服务与情报篡改攻击。
AI 中文摘要
蜜罐旨在欺骗攻击者,近期研究表明它们也能使基于LLM的自主渗透测试者偏离目标。然而,这些评估大多假设攻击者对其所面临的欺骗并不知情。我们研究相反的情形:一个自主攻击者被明确装备以识别蜜罐指纹并据此采取行动。我们提出了Rouxii,一个AI驱动的渗透测试框架,它将反欺骗整合到侦察中,并从蜜罐检测转向利用。我们在三个推理模型和十一个网络设置上,对匹配的普通版和反欺骗版Rouxii配置进行了十二轮评估(共1,544份攻击报告)。在仅提示词不同的匹配队列之间,反欺骗将正确的蜜罐识别率从19%提升至97%,该效果在OT服务上最为显著(从11%提升至97%),而对真实服务的误报率保持在0.7%。未感知欺骗的基线(PentestGPT、HackingBuddy)表现类似,表明该效果并非我们框架所特有。此外,检测并非终点:通过对蜜罐本身的白盒分析,我们展示了如何将已识别的陷阱反用于其操作者,演示了一种禁用Conpot且不触发其存活监控的拒绝服务攻击,以及一种对GasPot实例所报告情报的篡改。这些发现表明,欺骗的有效性强烈依赖于攻击者的知识,并且对蜜罐抵御AI攻击者能力的评估必须考虑主动推理并利用欺骗层的对手。
英文摘要
Honeypots are designed to deceive attackers, and recent work shows they can also derail autonomous LLM-based pentesters. These evaluations, however, largely consider attackers unaware of the deception they face. We study the opposite setting: an autonomous attacker explicitly equipped to recognize and act on honeypot fingerprints. We introduce Rouxii, an AI-driven penetration-testing framework that integrates counter-deception into reconnaissance and pivots from honeypot detection to exploitation. We evaluate matched vanilla and anti-deception Rouxii configurations across three reasoning models and eleven network setups over twelve cycles (1,544 attack reports). Between the matched cohorts, which differ only in the prompt, counter-deception raises correct honeypot identification from 19% to 97%, an effect strongest on OT services (11% to 97%), while false alarms on the real service stay at 0.7%. Deception-unaware baselines (PentestGPT, HackingBuddy) fail similarly, indicating the effect is not specific to our framework. Detection, moreover, is not the endpoint: through a white-box analysis of the honeypots themselves we show that a detected trap can be turned against its operator, demonstrating a denial-of-service that disables Conpot without tripping its liveness monitoring, and a corruption of the intelligence a GasPot instance reports. These findings show that deception effectiveness depends strongly on attacker knowledge, and that evaluations of honeypot resilience against AI attackers must account for adversaries that actively reason about and exploit the deception layer.