Skip to content

Repository files navigation

Mirage (Chronos Framework)

Repository codename: Apate

Product name: Mirage

Framework name: Chronos

Mirage is a state-consistent honeypot platform built on the Chronos framework. The goal is simple enough to state and demanding enough to deserve the work: preserve believable attacker interaction without letting the environment contradict itself.

Chronos combines a FUSE-backed filesystem, Redis-based atomic state, PostgreSQL audit storage, and optional LLM-assisted content generation. The LLM is used for texture, not truth. State remains deterministic; the interesting part is that it stays interesting.

Program Phases

  • Phase 1: Core deception platform engineering and validation, completed.
  • Phase 2: AI integration that improves realism and analysis without adding unnecessary complexity, in progress.

What It Does

  • Presents a realistic filesystem through a FUSE interface.
  • Persists filesystem state atomically in Redis.
  • Records audit and session data in PostgreSQL.
  • Classifies commands, threats, and attacker behavior.
  • Generates missing file content on demand, then persists it for consistent reuse.
  • Exposes SSH and HTTP entry points for attacker interaction.
  • Uses a Rust layer for high-speed protocol analysis and early threat tagging.

For the technical case behind the design, see Problem Validation Analysis.

Quick Start

Prerequisites

  • Docker and Docker Compose
  • Optional: an OpenAI or Anthropic API key for content generation features

Run the stack

git clone https://github.com/Rizzy1857/Apate.git chronos
cd chronos
docker compose up --build -d

Check the core service logs:

docker compose logs -f core-engine

Open the container and explore the mounted filesystem:

docker exec -it chronos_core /bin/bash
cd /mnt/honeypot
ls -la

Verification

Run the core validation and verification targets from the repository root:

make up
make validate-core
make validate-attacks
make verify

You can also run the phase scripts directly:

python3 tests/verification/verify_phase1.py
python3 tests/verification/verify_phase2.py
python3 tests/verification/verify_phase3.py
python3 tests/verification/verify_phase4.py

For a lighter demonstration, use the standalone demo:

python3 tests/integration/demo_standalone.py

Documentation

Configuration

Environment variables in docker-compose.yml:

Variable Description Default
REDIS_HOST Redis service host redis-store
POSTGRES_HOST PostgreSQL service host db-store
LLM_PROVIDER openai, anthropic, or mock mock
OPENAI_API_KEY OpenAI API key, if used unset

License

MIT License.

About

An adaptive, LLM-driven honeypot

Resources

Stars

5 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages