Date of Submission
4-30-2026
Document Type
Thesis
Department
Electrical & Computer Engineering and Computer Science
Advisor
Elmahedi Mahalal, Ph.D.
Keywords
Large Language Models (LLMs), Honeypots, Deception Technology, Linux Shell Simulation, Threat Intelligence, Attacker Engagement
LCSH
Generative artificial intelligence, Cyber intelligence (Computer security)
Abstract
This research investigates the application of Large Language Models (LLMs) in developing realistic shell honeypots that simulate Linux environments for cybersecurity defense. The study evaluates how effectively various LLMs can generate authentic command-line interfaces, respond appropriately to attack scenarios, and maintain convincing system behaviors to engage potential attackers. Through comparative analysis of leading LLM implementations, this research determines their capabilities in creating honeypots that balance authenticity with practical resource requirements. The methodology includes constructing prototype honeypots using different LLMs, testing them against common attack vectors, and measuring their effectiveness through quantitative and qualitative metrics. Our results provide insights into which models best reproduce Linux environment behaviors with minimal configuration overhead. This work identifies a critical latency-based fingerprinting vulnerability in LLM honeypots and demonstrates that locally hosted models (Llama 4 Maverick) offer a promising path for reducing detection risk compared to cloud APIs.
Recommended Citation
Godburn, Ryan, "Evaluating Large Language Models for Realistic Real-Time Linux Shell Honeypots" (2026). Honors Theses. 128.
https://digitalcommons.newhaven.edu/honorstheses/128