Non-Interactive SSH Attacks

Arxiv pdf 2026-06-01T00:00:00
arXiv Paper — PDF not available. Only the Executive Summary is available here. To read or download the full paper, visit the arXiv abstract page.

Abstract

Our research studies and quantifies this phenomenon of noninteractive sessions by deploying advanced LLM-based SSH honeypots on the Internet for 15 days and analyzing which attacks use interactive and non-interactive sessions and for what. Our methodology first involves developing a variant of the AdvancedShelLM LLM-based SSH honeypot [2], making it capable of distinguishing these two session types. Second, we analyze the attacks collected during the period, extracting session commands and answers. Finally, we validate our findings against an independent Honeypotas-a-Service (HaaS) Cowrie honeypot network operated by CZ.NIC over the same window [5].

Loading executive summary...

LINK COPIED TO CLIPBOARD