Adaptive AI-Driven Honeypot for Evolving Network Threats
| dc.contributor.advisor | Chen, Min | |
| dc.contributor.author | Devkar, Samarth Mahadev | |
| dc.date.accessioned | 2026-08-11T19:18:27Z | |
| dc.date.issued | 2026-08-11 | |
| dc.date.submitted | 2026 | |
| dc.description | Thesis (Master's)--University of Washington, 2026 | |
| dc.description.abstract | Traditional SSH honeypots are effective for collecting brute-force attempts and post-login shell activity, but their research value is often limited by three connected challenges: restricted interaction realism, limited threat-intelligence extraction from attacker interactions and limited analyst-facing interpretation of captured data. Many conventional SSH honeypots rely on predefined filesystems, scripted command handlers, and static logging workflows. As a result, they may fail to sustain meaningful interaction when attackers issue commands outside the expected behavior of the decoy, and they often leave defenders with raw logs that require substantial manual analysis. To address the above limitations, this thesis investigates how an SSH honeypot can be extended from a passive command-logging mechanism into an adaptive threat-intelligence workflow. The central contribution of this thesis is a research approach for connecting adaptive SSH interaction, structured behavioral interpretation, and analyst-facing visualization. The research contribution is threefold: a hybrid interaction approach for improving SSH honeypot interaction continuity, a novel enrichment layer for converting raw shell activity into structured threat intelligence, and an analyst-facing workflow for presenting enriched telemetry through live visualization. To validate the proposed approach, an AI-enhanced SSH honeypot was designed, implemented, and evaluated. The system maintains a controlled virtual shell environment, handles common commands through deterministic emulation, uses language-model assistance for selected fallback responses, and exposes enriched telemetry through a backend API and SOC-style dashboard. The dashboard supports live monitoring, severity triage, IOC inspection, and source-centric investigation. The evaluation includes a comparison with Cowrie in a conventional emulated-shell configuration and an assessment of the enrichment pipeline using a manually labeled evaluation set. The results show that the proposed system maintains interaction quality comparable to a mature SSH honeypot baseline while adding built-in intelligence enrichment and dashboard-based interpretation. The enrichment evaluation further shows that the system can produce useful behavior, risk, and IOC outputs for analyst-facing triage. Overall, this thesis contributes a research approach for combining adaptive SSH interaction, structured threat-intelligence enrichment, and live visualization into a single workflow for improving the practical value of honeypot telemetry. | |
| dc.embargo.lift | 2027-08-11T19:18:27Z | |
| dc.embargo.terms | Restrict to UW for 1 year -- then make Open Access | |
| dc.format.mimetype | application/pdf | |
| dc.identifier.other | Devkar_washington_0250O_29666.pdf | |
| dc.identifier.uri | https://hdl.handle.net/1773/56982 | |
| dc.language.iso | en_US | |
| dc.rights | none | |
| dc.subject | Cyber Deception | |
| dc.subject | Honeypot | |
| dc.subject | Large Language Models | |
| dc.subject | MITRE ATT&CK | |
| dc.subject | SSH Security | |
| dc.subject | Threat Intelligence | |
| dc.subject | Computer science | |
| dc.subject | Artificial intelligence | |
| dc.subject.other | Computing and software systems | |
| dc.title | Adaptive AI-Driven Honeypot for Evolving Network Threats | |
| dc.type | Thesis |
Files
Original bundle
1 - 1 of 1
Loading...
- Name:
- Devkar_washington_0250O_29666.pdf
- Size:
- 1.46 MB
- Format:
- Adobe Portable Document Format
