LATIDIA · Ciberseguridad
Rouxii: Explotar los honeypots con pentesters de IA conscientes del engaño
arXiv: 2609.26555v1Announce Type: new Abstract: Los honeypots están diseñados para engañar a los atacantes, y trabajos recientes muestran que también pueden descarrilar los pentesters autónomos basados en LLM. Estas evaluaciones, sin embargo, consideran en gran medida el ataque
WhatsApp ↗Telegram ↗
La noticia
arXiv:2609.26555v1 Announce Type: new Abstract: Honeypots are designed to deceive attackers, and recent work shows they can also derail autonomous LLM-based pentesters. These evaluations, however, largely consider attackers unaware of the deception they face. We study the opposite setting: an autonomous attacker explicitly equipped to recognize and act on honeypot fingerprints. We introduce Rouxii, an AI-driven penetration-testing framework that integrates counter-deception into reconnaissance and pivots from honeypot detection to exploitation. We evaluate matched vanilla and anti-deception Rouxii configurations across three reasoning models and eleven network setups over twelve cycles (1,544 attack reports). Between the matched cohorts, which differ only in the prompt, counter-deception raises correct honeypot identification from 19% to