OllamaDrama:设计与部署蜜罐以测量针对暴露的LLM基础设施的攻击
OllamaDrama: Designing and Deploying a Honeypot to Measure Attacks on Exposed LLM Infrastructure
查看机构详情
- Technical University of Denmark(丹麦技术大学)
机构由 AI 辅助整理,请以论文原文为准。
浏览论文内容
中文总结 AI 辅助
本研究设计并部署蜜罐Ollure模拟Ollama API,测量暴露LLM基础设施的真实攻击,发现自动化探测与多种利用尝试,揭示现实威胁。
中文摘要 AI 辅助
公开暴露的大语言模型(LLM)基础设施构成了日益增长的攻击面,然而现实世界中的攻击目标选择仍鲜为人知。我们提出了Ollure,一种低交互和中交互蜜罐,它在没有后端LLM的情况下模拟Ollama API。在云和大学网络中的四个部署点上,Ollure运行了84天,记录了来自2,793个唯一源IP地址的290,887次交互。大部分活动由自动化发现、指纹识别和模型枚举组成。然而,我们也观察到了针对基础设施和LLM层的具体利用尝试。这些包括模型管理滥用、路径遍历和SSRF探测、RCE和加密货币挖矿载荷、资源耗尽尝试、提示注入、信息提取以及面向代理的工具使用。我们的结果为暴露的自托管LLM服务面临的现实威胁提供了实证洞察。
英文摘要
Publicly exposed large language model (LLM) infrastructure creates a growing attack surface, yet real-world targeting remains poorly understood. We present Ollure, a low- and medium-interaction honeypot that emulates the Ollama API without a backend LLM. Spanning four deployments across cloud and university networks, Ollure operated for 84 days and recorded 290,887 interactions from 2,793 unique source IP addresses. Most of the activity consisted of automated discovery, fingerprinting, and model enumeration. However, we also observed concrete exploitation attempts against both the infrastructure and LLM layers. These included model management abuse, path traversal and SSRF probes, RCE and cryptocurrency mining payloads, resource exhaustion attempts, prompt injection, information extraction, and agent-oriented tool use. Our results provide empirical insight into real-world threats against exposed, self-hosted LLM services.