LLMPot: Dynamically Configured LLM-based Honeypot for Industrial Protocol and Physical Process Emulation
Christoforos Vasilatos, Dunia J. Mahboobeh, Hithem Lamri, Manaar Alam, Michail Maniatakos

TL;DR
This paper introduces LLMPot, a novel LLM-based method for automatically creating realistic, vendor-agnostic honeypots in ICS networks that accurately emulate industrial protocols and control logic, reducing manual effort.
Contribution
The paper presents LLMPot, a new approach leveraging large language models to automate and optimize the deployment of ICS honeypots with diverse protocols and control logic.
Findings
Effective emulation of industrial protocols achieved
Automated honeypot configuration reduces manual effort
Vendor-agnostic and adaptable to various control logics
Abstract
Industrial Control Systems (ICS) are extensively used in critical infrastructures ensuring efficient, reliable, and continuous operations. However, their increasing connectivity and addition of advanced features make them vulnerable to cyber threats, potentially leading to severe disruptions in essential services. In this context, honeypots play a vital role by acting as decoy targets within ICS networks, or on the Internet, helping to detect, log, analyze, and develop mitigations for ICS-specific cyber threats. Deploying ICS honeypots, however, is challenging due to the necessity of accurately replicating industrial protocols and device characteristics, a crucial requirement for effectively mimicking the unique operational behavior of different industrial systems. Moreover, this challenge is compounded by the significant manual effort required in also mimicking the control logic the…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsIndustrial Automation and Control Systems · Flexible and Reconfigurable Manufacturing Systems · Service-Oriented Architecture and Web Services
