Adaptive AI-Driven Honeypot for Evolving Network Threats

dc.contributor.advisorChen, Min
dc.contributor.authorDevkar, Samarth Mahadev
dc.date.accessioned2026-08-11T19:18:27Z
dc.date.issued2026-08-11
dc.date.submitted2026
dc.descriptionThesis (Master's)--University of Washington, 2026
dc.description.abstractTraditional SSH honeypots are effective for collecting brute-force attempts and post-login shell activity, but their research value is often limited by three connected challenges: restricted interaction realism, limited threat-intelligence extraction from attacker interactions and limited analyst-facing interpretation of captured data. Many conventional SSH honeypots rely on predefined filesystems, scripted command handlers, and static logging workflows. As a result, they may fail to sustain meaningful interaction when attackers issue commands outside the expected behavior of the decoy, and they often leave defenders with raw logs that require substantial manual analysis. To address the above limitations, this thesis investigates how an SSH honeypot can be extended from a passive command-logging mechanism into an adaptive threat-intelligence workflow. The central contribution of this thesis is a research approach for connecting adaptive SSH interaction, structured behavioral interpretation, and analyst-facing visualization. The research contribution is threefold: a hybrid interaction approach for improving SSH honeypot interaction continuity, a novel enrichment layer for converting raw shell activity into structured threat intelligence, and an analyst-facing workflow for presenting enriched telemetry through live visualization. To validate the proposed approach, an AI-enhanced SSH honeypot was designed, implemented, and evaluated. The system maintains a controlled virtual shell environment, handles common commands through deterministic emulation, uses language-model assistance for selected fallback responses, and exposes enriched telemetry through a backend API and SOC-style dashboard. The dashboard supports live monitoring, severity triage, IOC inspection, and source-centric investigation. The evaluation includes a comparison with Cowrie in a conventional emulated-shell configuration and an assessment of the enrichment pipeline using a manually labeled evaluation set. The results show that the proposed system maintains interaction quality comparable to a mature SSH honeypot baseline while adding built-in intelligence enrichment and dashboard-based interpretation. The enrichment evaluation further shows that the system can produce useful behavior, risk, and IOC outputs for analyst-facing triage. Overall, this thesis contributes a research approach for combining adaptive SSH interaction, structured threat-intelligence enrichment, and live visualization into a single workflow for improving the practical value of honeypot telemetry.
dc.embargo.lift2027-08-11T19:18:27Z
dc.embargo.termsRestrict to UW for 1 year -- then make Open Access
dc.format.mimetypeapplication/pdf
dc.identifier.otherDevkar_washington_0250O_29666.pdf
dc.identifier.urihttps://hdl.handle.net/1773/56982
dc.language.isoen_US
dc.rightsnone
dc.subjectCyber Deception
dc.subjectHoneypot
dc.subjectLarge Language Models
dc.subjectMITRE ATT&CK
dc.subjectSSH Security
dc.subjectThreat Intelligence
dc.subjectComputer science
dc.subjectArtificial intelligence
dc.subject.otherComputing and software systems
dc.titleAdaptive AI-Driven Honeypot for Evolving Network Threats
dc.typeThesis

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Devkar_washington_0250O_29666.pdf
Size:
1.46 MB
Format:
Adobe Portable Document Format