Result description
SPHINX AI Honeypots are realised both as virtual and hardware appliances. The virtual one is based on docker framework making it suitable for both cloud and on premise installations; the hardware one mostly suited for on premise installations, comes in two flavours, the first one based on a low-cost Advanced RISC Machine (ARM) system – Quad-core Cortex-A7 central processing unit (CPU) – that is able to support lightweight detection algorithms whereas the second one is capable of operating as a honeypot and a router system, with the capability of handling computing intensive algorithms without a noticeable delay for the attacker. To achieve this, the system utilises programmable logic in the form of a compact low power field-programmable gate array (FPGA) module. SPHINX AI Honeypots are to be part of an organisation’s cyber defence arsenal aiming to detect manifested cyber-attacks as early as possible by luring the adversaries to attack them instead of the real production IT systems. In this direction, the honeypots host vulnerable services that may be considered targets from an adversary.
Addressing target audiences and expressing needs
- Collaboration
We would like to test the honeypots on additional use cases and gather the end-user and algorithmic feedback towards enhancing the honeypots performance (in terms of attack analysis and number of emulated vulnerable services) and maximising their user value.
- Public or private funding institutions
- Research and Technology Organisations
R&D, Technology and Innovation aspects
Currently, the SPHINX honeypots are near TRL4 and are not expected to pass TRL5 at the project’s end. We would like funding from Private Investors and/or public or private funding Institutions to continue developing the honeypots towards reaching them at least in TRL7 stage. After that and based on the TRL7 results a second round of funding may be needed for going to TRL9.
The business model does not rely on heavy investments as the HP solution builds on open-source software and is offered either in pure software or in low cost, low power embedded systems. Furthermore, the supported automation (exploiting for example docker and Kubernetes frameworks), especially in the solution’s deployment and management keeps low the relevant costs. The virtualised nature of the HP allows also for the replicability of the business model in different vertical and also horizontal domains.
Assuming that the same configuration applies (e.g. same ML model is deployed) and the same (or statistically similar) input datasets are used, the Honeypots can be deployed from different stakeholders in different environmetns and the observed results would be consistent.
The business model is sustainable as the impact of the specific solution in the environment is pretty low and is related mainly to the resources consumed from the Cloud platforms or/and the embedded systems hosting the HP solution; for the former, green friendly cloud providers are to be preferred for the solution’s hosting whereas for the latter the used embedded systems have a low-energy footprint. From the societal perspective the offering of the solution in both HW and containerised forms enables for deployment in the customers’ premises meeting as such any privacy needs. Finally in the economy side, the model is sustainable as the solution fulfils an important current and future need of the business sector in managing and addressing the risks and costs from cyber-attacks.

