Skip to main navigation Skip to search Skip to main content

OHRA: dynamic multi-protocol LLM-based cyber deception

Research output: Chapter in Book/Report/Conference proceedingArticle in proceedingsResearchpeer-review

Abstract

Honeypots aid cyber defense but traditional designs demand heavy manual setup and support few protocols. We introduce OHRA, a modular, extensible LLM-driven honeypot that supports multiple protocols (SSH, Telnet, HTTP, FTP, SMTP, SNMP, IPP) and can integrate different LLM providers. OHRA wraps the model with session memory and prompt control to generate realistic, context-aware responses with less configuration effort. We evaluate OHRA against Cowrie and a recent LLM-based honeypot using curated malware commands and a real-world Internet deployment. OHRA is among the first honeypots to demonstrate a unified LLM-based architecture across several protocols: SSH, Telnet, and HTTP are fully interactive, while FTP, SMTP, IPP, and SNMP are currently implemented in partial form. Results show higher response realism, improved session handling, and greater deceptiveness in comparison to prior systems. This work lays the groundwork for scalable and adaptive multi-protocol deception platforms.
Original languageEnglish
Title of host publicationProceedings of the 30th Nordic Conference on Secure IT Systems (Nordsec 2025)
Volume16325
PublisherSpringer
Publication date2026
Pages109-128
ISBN (Print)978-3-032-14781-3
ISBN (Electronic)978-3-032-14782-0
DOIs
Publication statusPublished - 2026
Event30th Nordic Conference on Secure IT Systems - Tartu, Estonia
Duration: 12 Nov 202513 Nov 2025

Conference

Conference30th Nordic Conference on Secure IT Systems
Country/TerritoryEstonia
CityTartu
Period12/11/202513/11/2025

Keywords

  • Deception
  • Honeypots
  • Large Language Models

Fingerprint

Dive into the research topics of 'OHRA: dynamic multi-protocol LLM-based cyber deception'. Together they form a unique fingerprint.

Cite this