Compare AIFind AIAI NewsAI How-To
About Us
PrivacyTermsFAQContactContact
AIB Inc.Company info
© 2026 AIB Inc.

Leo Builds AI Honeypot Corridor

Leo Builds AI Honeypot Corridor

DEV.to·Tuesday, August 11, 2026
  • •Leo receives 12GB of raw logs and finds TLS matches but behavior diverges
  • •Derek deploys a 3-layer MediSys honeypot with copied fingerprint and 100 to 200ms delay
  • •Scan source reaches fake admin endpoint, tries authentication, and reveals retry behavior
  • •Leo receives 12GB of raw logs and finds TLS matches but behavior diverges
  • •Derek deploys a 3-layer MediSys honeypot with copied fingerprint and 100 to 200ms delay
  • •Scan source reaches fake admin endpoint, tries authentication, and reveals retry behavior
  • •Leo receives 12GB of raw logs and finds TLS matches but behavior diverges
  • •Derek deploys a 3-layer MediSys honeypot with copied fingerprint and 100 to 200ms delay
  • •Scan source reaches fake admin endpoint, tries authentication, and reveals retry behavior
  • •Leo receives 12GB of raw logs and finds TLS matches but behavior diverges
  • •Derek deploys a 3-layer MediSys honeypot with copied fingerprint and 100 to 200ms delay
  • •Scan source reaches fake admin endpoint, tries authentication, and reveals retry behavior

A Dev.to fiction installment published on 2026-08-10 follows Leo, Derek and CoreStack as Leo receives 12GB of raw network logs before dawn and checks whether a scan source matches an earlier ACL-linked fingerprint. The logs include full TCP handshake records, TLS negotiation parameters, port probe order and scan interval distribution, with no gaps, truncation, IP filtering or evidence of preprocessing. Leo compares the data against an archived fingerprint tied to `acl-train-2026q2-v3`, finding that TLS fingerprints match template A and scan intervals stay at 4.2s (±0.1), while port preferences, traversal behavior, exclusion rules and depth tolerance differ.

Leo tells Derek the data is clean and that “some parts match, some parts don’t,” then proposes a controlled observation setup inside the MediSys test environment. The plan uses 3 layers: a shallow overloaded legacy API, a middle database query interface returning partial fragments, and a deepest internal admin endpoint with fake authentication. Derek gives Leo read-only honeypot access on one condition: Derek will not draw conclusions, and Leo will not draw them for him first.

Derek deploys the corridor in the MediSys sandbox by copying the last honeypot’s fingerprint, including an unchanged 100 to 200ms response delay, the same TLS server cipher preference and identical certificate order. The honeypot terminates TLS, parses requests including header order, and exports them to disk. A mirror port on the sandbox gateway copies the full segment’s traffic into Leo’s own sandbox, where scan-interval jitter, HTTP header order and port probe priority appear live in scatter plots.

Leo verifies the 3 endpoint layers before the scan arrives. The shallow layer responds slowly like an overloaded old machine, the middle layer returns incomplete data with empty fields, and the deep layer answers with a 401 authentication challenge using a realm that looks real. He also checks that response headers show no obvious automation markers and that the TLS certificate chain is signed by Derek’s internal CA, has 3-year validity and was issued two and a half years earlier.

When the first sample window lands, Leo calculates a mean interval of 4.173 from 10 samples and a maximum drift of 0.09 from the 4.2s baseline, keeping the verdict as “same family” because the drift stays within 0.1. Later, the scan source re-sweeps the address ranges on its own cycle and finds the corridor. It first touches the shallow legacy API, matches the last honeypot’s delay and TLS fingerprint, and lands back on the same periodic curve.

The scan source circles the shallow layer, pulls back, pauses for 3.8 seconds, then re-sweeps the same path before moving into the middle database query interface. At the middle boundary, Leo writes “back off. two cycles.” The source retreats to the shallow layer, returns after two cycles, passes through the middle layer, reaches the deep admin endpoint, tries authentication, fails, and keeps probing.

Leo records behavior that was absent from the baseline: gaps between authentication attempts, parameter-tweak direction and retry strategy after failure. The first attempt uses default credential combos, the second rotates usernames in dictionary order, and the third changes the parameter format. Periodicity, TLS fingerprint and exclusion rules remain consistent, while the exclusion range extends across two adjacent CIDR blocks beyond the known source.

A Dev.to fiction installment published on 2026-08-10 follows Leo, Derek and CoreStack as Leo receives 12GB of raw network logs before dawn and checks whether a scan source matches an earlier ACL-linked fingerprint. The logs include full TCP handshake records, TLS negotiation parameters, port probe order and scan interval distribution, with no gaps, truncation, IP filtering or evidence of preprocessing. Leo compares the data against an archived fingerprint tied to `acl-train-2026q2-v3`, finding that TLS fingerprints match template A and scan intervals stay at 4.2s (±0.1), while port preferences, traversal behavior, exclusion rules and depth tolerance differ.

Leo tells Derek the data is clean and that “some parts match, some parts don’t,” then proposes a controlled observation setup inside the MediSys test environment. The plan uses 3 layers: a shallow overloaded legacy API, a middle database query interface returning partial fragments, and a deepest internal admin endpoint with fake authentication. Derek gives Leo read-only honeypot access on one condition: Derek will not draw conclusions, and Leo will not draw them for him first.

Derek deploys the corridor in the MediSys sandbox by copying the last honeypot’s fingerprint, including an unchanged 100 to 200ms response delay, the same TLS server cipher preference and identical certificate order. The honeypot terminates TLS, parses requests including header order, and exports them to disk. A mirror port on the sandbox gateway copies the full segment’s traffic into Leo’s own sandbox, where scan-interval jitter, HTTP header order and port probe priority appear live in scatter plots.

Leo verifies the 3 endpoint layers before the scan arrives. The shallow layer responds slowly like an overloaded old machine, the middle layer returns incomplete data with empty fields, and the deep layer answers with a 401 authentication challenge using a realm that looks real. He also checks that response headers show no obvious automation markers and that the TLS certificate chain is signed by Derek’s internal CA, has 3-year validity and was issued two and a half years earlier.

When the first sample window lands, Leo calculates a mean interval of 4.173 from 10 samples and a maximum drift of 0.09 from the 4.2s baseline, keeping the verdict as “same family” because the drift stays within 0.1. Later, the scan source re-sweeps the address ranges on its own cycle and finds the corridor. It first touches the shallow legacy API, matches the last honeypot’s delay and TLS fingerprint, and lands back on the same periodic curve.

The scan source circles the shallow layer, pulls back, pauses for 3.8 seconds, then re-sweeps the same path before moving into the middle database query interface. At the middle boundary, Leo writes “back off. two cycles.” The source retreats to the shallow layer, returns after two cycles, passes through the middle layer, reaches the deep admin endpoint, tries authentication, fails, and keeps probing.

Leo records behavior that was absent from the baseline: gaps between authentication attempts, parameter-tweak direction and retry strategy after failure. The first attempt uses default credential combos, the second rotates usernames in dictionary order, and the third changes the parameter format. Periodicity, TLS fingerprint and exclusion rules remain consistent, while the exclusion range extends across two adjacent CIDR blocks beyond the known source.

Read original (English)·Aug 10, 2026
Safety & Ethics#honeypot#tls fingerprint#network logs#scan source#authentication#cidr#medisys#acl train#traffic analysis