Project Brief
This track built isolated AWS deception environments using Beelzebub to emulate SSH servers without exposing real systems or secrets, then evaluated how LLM-generated interaction patterns affect attacker engagement and telemetry quality. Two interns worked this track in parallel, each standing up honeypot infrastructure, configuring services like Cowrie, and studying methodologies to make the deception layer more intelligent while maintaining safety guardrails.
Capstone Team
Project Workstreams
Cloud Deception Lab
Deployed a safely isolated SSH honeypot in AWS, collecting commands and credential attempts to evaluate how LLM-assisted responses affect attacker engagement and telemetry quality.
Honeypot or Hallucination?
Compared static and dynamic honeypot behavior (Cowrie vs. Beelzebub) and evaluated whether LLM-generated interactions are realistic, safe, and useful for defenders.
Deliverables
Track Scope: Expected Deliverables
Skills Demonstrated