Skip to content

1 paper indexed here

We haven’t gathered this author’s papers yet. Follow them and we’ll fetch their work.

Not the right person? Other researchers publish under this name.

Review Open access Aug 2026

An Integrated Honeypot and LLM-Based Framework for near Real-Time Detection and Behavioral Analysis of Malicious Activities

Malicious activity detection in honeypot environments remains challenging due to the volume and heterogeneity of captured data, as well as the sequential nature of attacker behavior. This study proposes an integrated framework combining a Cowrie-based honeypot with a locally deployed Large Language Model (LLM) to enable automated detection and near-real-time behavioral analysis. Attacker interactions are captured and processed through a structured preprocessing stage that reconstructs session-level activity. These representations are analyzed using an LLM, allowing contextual interpretation of authentication patterns, command execution sequences, and post-compromise behavior. Structured analytical outputs are generated, including severity classification, reasoning, and recommended actions. Evaluation was conducted using isolated and concurrent attack scenarios. Results indicate effective identification of brute-force attacks, reconnaissance activity, persistence staging, and download-and-execute patterns, achieving a 94.23% Accuracy (95% CI: 84.05–98.79%), 100.0% Precision, 87.50% Recall, and an F1-score of 93.33% across an expanded evaluation of 52 independent observations, with zero false positives (FPs). These figures are derived from a single evaluation run and are reported as preliminary, proof-of-concept estimates rather than as stable, production-grade performance. Analytical output remained stable for sessions governed by deterministic severity overrides. However, a low-intensity multi-stage session produced inconsistent severity classifications under concurrent conditions, indicating that analyst review is still required for borderline cases. Integration of deterministic preprocessing with LLM-based reasoning enables the transformation of raw honeypot logs into structured and actionable cybersecurity intelligence, reducing analyst workload while improving the explainability and reliability of intrusion analysis in near-real-time environments.

Rúben Oliveira, Tiago Gomes, D. Pinho et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.