LATIDIA · Ciberseguridad
OllamaDrama: Diseño e implementación de un Honeypot para medir los ataques a la infraestructura de LLM expuesta
arXiv: 2609.29757v1Tipo de anuncio: nuevo Resumen: La infraestructura de modelo de lenguaje grande (LLM) expuesta públicamente crea una superficie de ataque creciente, pero la orientación en el mundo real sigue siendo poco conocida. Presentamos Ollure, una baja a
WhatsApp ↗Telegram ↗
La noticia
arXiv:2609.29757v1 Announce Type: new Abstract: Publicly exposed large language model (LLM) infrastructure creates a growing attack surface, yet real-world targeting remains poorly understood. We present Ollure, a low- and medium-interaction honeypot that emulates the Ollama API without a backend LLM. Spanning four deployments across cloud and university networks, Ollure operated for 84 days and recorded 290,887 interactions from 2,793 unique source IP addresses. Most of the activity consisted of automated discovery, fingerprinting, and model enumeration. However, we also observed concrete exploitation attempts against both the infrastructure and LLM layers. These included model management abuse, path traversal and SSRF probes, RCE and cryptocurrency mining payloads, resource exhaustion attempts, prompt injection, information