Date of Submission

4-30-2026

Document Type

Thesis

Department

Electrical & Computer Engineering and Computer Science

Advisor

Elmahedi Mahalal, Ph.D.

Keywords

Large Language Models (LLMs), Honeypots, Deception Technology, Linux Shell Simulation, Threat Intelligence, Attacker Engagement

LCSH

Generative artificial intelligence, Cyber intelligence (Computer security)

Abstract

This research investigates the application of Large Language Models (LLMs) in developing realistic shell honeypots that simulate Linux environments for cybersecurity defense. The study evaluates how effectively various LLMs can generate authentic command-line interfaces, respond appropriately to attack scenarios, and maintain convincing system behaviors to engage potential attackers. Through comparative analysis of leading LLM implementations, this research determines their capabilities in creating honeypots that balance authenticity with practical resource requirements. The methodology includes constructing prototype honeypots using different LLMs, testing them against common attack vectors, and measuring their effectiveness through quantitative and qualitative metrics. Our results provide insights into which models best reproduce Linux environment behaviors with minimal configuration overhead. This work identifies a critical latency-based fingerprinting vulnerability in LLM honeypots and demonstrates that locally hosted models (Llama 4 Maverick) offer a promising path for reducing detection risk compared to cloud APIs.

Share

COinS