arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.29757cs.CR

OllamaDrama:设计与部署蜜罐以测量针对暴露的LLM基础设施的攻击

OllamaDrama: Designing and Deploying a Honeypot to Measure Attacks on Exposed LLM Infrastructure

发表机构丹麦技术大学
查看机构详情
  • Technical University of Denmark(丹麦技术大学)

机构由 AI 辅助整理,请以论文原文为准。

Karina Elzer, Niklas Netterstrøm Johansen, Emmanouil Vasilomanolakis

首次发表
浏览论文内容

中文总结 AI 辅助

本研究设计并部署蜜罐Ollure模拟Ollama API,测量暴露LLM基础设施的真实攻击,发现自动化探测与多种利用尝试,揭示现实威胁。

中文摘要 AI 辅助

公开暴露的大语言模型(LLM)基础设施构成了日益增长的攻击面,然而现实世界中的攻击目标选择仍鲜为人知。我们提出了Ollure,一种低交互和中交互蜜罐,它在没有后端LLM的情况下模拟Ollama API。在云和大学网络中的四个部署点上,Ollure运行了84天,记录了来自2,793个唯一源IP地址的290,887次交互。大部分活动由自动化发现、指纹识别和模型枚举组成。然而,我们也观察到了针对基础设施和LLM层的具体利用尝试。这些包括模型管理滥用、路径遍历和SSRF探测、RCE和加密货币挖矿载荷、资源耗尽尝试、提示注入、信息提取以及面向代理的工具使用。我们的结果为暴露的自托管LLM服务面临的现实威胁提供了实证洞察。

英文摘要

Publicly exposed large language model (LLM) infrastructure creates a growing attack surface, yet real-world targeting remains poorly understood. We present Ollure, a low- and medium-interaction honeypot that emulates the Ollama API without a backend LLM. Spanning four deployments across cloud and university networks, Ollure operated for 84 days and recorded 290,887 interactions from 2,793 unique source IP addresses. Most of the activity consisted of automated discovery, fingerprinting, and model enumeration. However, we also observed concrete exploitation attempts against both the infrastructure and LLM layers. These included model management abuse, path traversal and SSRF probes, RCE and cryptocurrency mining payloads, resource exhaustion attempts, prompt injection, information extraction, and agent-oriented tool use. Our results provide empirical insight into real-world threats against exposed, self-hosted LLM services.

补充信息

↑