본문 바로가기
Hack/System

OllamaDrama: Designing and Deploying a Honeypot to Measure Attacks on Exposed LLM Infrastructure

by Becoming a Hacker 2026. 9. 26.
반응형

  • 원문: arXiv 2609.29757
  • 저자: Karina Elzer, Niklas Netterstrøm Johansen, Emmanouil Vasilomanolakis
  • 공개일: 2026-09-25
  • 공식 코드: k-elzer/Ollure
  • 공개 데이터: Zenodo 10.5281/zenodo.22918902
  • 분야: LLM Infrastructure, Honeypot, Ollama, Internet Measurement
  • Tags: Ollure, Ollama, Honeypot, LLMInfrastructure, InternetMeasurement

본 글은 원 논문의 주요 기술적 내용을 이해하기 쉽게 요약·정리한 글입니다. 자세한 내용은 상단의 원문 링크를 참고하세요.

한눈에 보기

OllamaDrama는 backend LLM 없이 Ollama REST API를 모사하는 low·medium-interaction honeypot Ollure를 만들고, DigitalOcean과 university network의 네 instance에서 84일간 공개 인터넷 traffic을 관찰한 연구입니다. 2026-06-29부터 2026-09-20까지 290,887 interaction과 2,793개 unique source IP를 수집했습니다.

traffic의 79.36%는 service·model information endpoint를 향한 discovery·fingerprinting이었지만, model management abuse, path traversal, SSRF, RCE·XMRig payload, resource exhaustion, prompt injection, information extraction, agent tool-use 시도도 관찰했습니다. 이 결과는 exposed Ollama-compatible endpoint가 단순 scan 대상이 아니라 infrastructure와 model layer가 동시에 공격받는 surface임을 보여 줍니다.

연구 배경

self-hosted LLM은 privacy와 cost control 장점 때문에 빠르게 늘었지만, Ollama API는 기본 port 11434와 model management·inference endpoint를 외부에 노출할 수 있습니다. authentication 부재, path traversal, SSRF 같은 문제는 model weight와 host resource, cloud credential까지 영향을 줄 수 있습니다.

기존 LLM honeypot 연구는 LLM을 이용해 decoy response를 생성하거나 여러 API facade의 downstream 분석에 집중했습니다. Ollure는 Ollama endpoint와 state transition을 직접 모사해 실제 actor가 어느 endpoint와 payload를 사용하는지 장기간 측정합니다.

공격 모델 / 전제 조건

공격자는 인터넷에서 unauthenticated Ollama-compatible endpoint를 찾고 HTTP request를 보낼 수 있습니다. 별도 victim interaction은 없고, public IP와 port 11434가 접근 가능하면 됩니다. 일부 공격은 알려진 path traversal·SSRF behavior 또는 unrestricted model management가 실제 backend에 존재한다는 전제를 둡니다.

Ollure 자체는 backend LLM이나 command execution engine이 없는 decoy입니다. 따라서 payload가 관찰됐다는 사실은 공격 시도를 입증하지만, 실제 vulnerable Ollama version에서 exploitation이 성공했다는 뜻은 아닙니다.

비판적 검토 / 아쉬운 점

가장 중요한 한계는 low·medium-interaction emulation이 공격 성공과 후속 행동을 관찰하지 못한다는 점입니다. RCE·XMRig string, SSRF URL, traversal path는 intent 또는 scanner signature의 증거이지 실제 code execution, credential theft, mining 성공의 증거가 아닙니다.

두 번째로 source IP는 actor identity와 같지 않습니다. cloud scanner, NAT, proxy, compromised host, distributed pool 때문에 2,793 IP를 2,793 attacker로 해석할 수 없습니다. 캠페인 clustering도 payload·timing 중심의 추가 분석이 필요합니다.

세 번째로 honeypot fingerprint 가능성이 결과에 영향을 줍니다. static response, regex response, artificial delay, no real model inference는 sophisticated actor에게 decoy임을 드러낼 수 있습니다. 따라서 관찰된 traffic은 broad automated ecosystem을 잘 보여 주지만 targeted post-exploitation을 과소 측정할 수 있습니다.

네 번째로 공개 dataset은 privacy를 위해 pseudonymization됐고 paper의 category는 regex와 manual review를 함께 사용합니다. labeling consistency, duplicate campaign, false positive에 대한 inter-rater reliability가 명확히 제시되지 않아 세부 category count는 탐색적 지표로 보는 편이 안전합니다.

핵심 Root Cause

구조적 원인은 self-hosted LLM gateway가 inference API뿐 아니라 version·model inventory·pull·push·create·delete 같은 administrative capability를 같은 unauthenticated network surface에 노출한다는 점입니다. 공격자는 단일 endpoint에서 reconnaissance, resource use, model artifact manipulation, prompt-level action을 연속 시도할 수 있습니다.

깨진 보안 불변조건은 “외부 inference client는 host·model lifecycle·internal network·tool authority에 접근해서는 안 된다”입니다. authentication, network segmentation, egress restriction, model provenance, resource quota가 없으면 LLM API가 management plane과 execution surface를 함께 노출합니다.

핵심 공격 원리

공격자는 /api/version, /api/tags, /v1/models, /api/ps, /api/show로 product와 model을 식별합니다. 이어 /api/pull, /api/push, /api/create, /api/delete에 URL, traversal path, fake model name, malicious Modelfile을 넣어 network·filesystem·model state를 건드립니다.

inference endpoint에서는 oversized num_ctx, num_predict=-1, repeated token으로 resource exhaustion을 유도하고, system prompt·role-playing·multilingual instruction으로 guardrail과 information boundary를 시험합니다. chat tool parameter에는 ping, time, file read/write, web search 같은 agent action을 요청합니다.

공격 흐름

  1. scanner가 root 또는 Ollama-specific endpoint를 직접 probe합니다.
  2. version과 model inventory를 확인해 accessible capability를 fingerprint합니다.
  3. model pull·create·push에 canary URL, localhost, cloud metadata, traversal path를 넣습니다.
  4. malicious model·Modelfile·template으로 artifact hijacking이나 command payload를 시험합니다.
  5. inference endpoint에 large context, infinite generation, prompt injection, data extraction request를 보냅니다.
  6. tool schema가 있으면 file·network action을 agent에게 위임하려 시도합니다.

성공 조건 / 실패 조건

실제 공격이 성공하려면 endpoint가 인터넷에 노출되고 authentication·authorization이 없거나 우회돼야 합니다. 사용 중인 Ollama version과 configuration이 해당 SSRF·traversal·model management behavior에 취약하고, process가 internal network·filesystem·GPU·tool credential에 도달할 수 있어야 합니다.

방화벽과 reverse proxy authentication, management endpoint 비공개, strict egress, non-root container, read-only filesystem, model registry allowlist, inference quota가 적용되면 여러 단계가 끊깁니다. honeypot에서는 backend가 없으므로 공격 payload가 host compromise로 이어지지 않습니다.

연구진의 실험 환경

Ollure는 Python 3.12.10, FastAPI, Docker 기반입니다. LIH는 correct response shape·error·static model list를 제공하고, MIH는 IP와 User-Agent 기준 session, 30-minute timeout, dynamic model list, dictionary·regex prompt response를 추가합니다.

DigitalOcean Frankfurt와 on-premises university network에 LIH·MIH를 각각 배치해 총 4개 instance를 운영했습니다. default Ollama port 11434를 직접 인터넷에 노출했고 84일간 passive observation을 수행했습니다.

realism을 위해 endpoint별 artificial delay를 넣었습니다. prompt initialization은 281–357 ms, evaluation은 2.1–2.9초, unloaded model swap은 52–54초, 기존·cloud model pull/create는 0.5–2초를 사용했습니다. 8B model 신규 pull은 linear size rule에 따라 512초 delay로 모사했습니다.

주요 실험 결과

총 290,887 request 중 /api/tags 102,795건, /v1/models 60,949건, /api/generate 52,994건, /api/version 42,783건, /api/ps 16,477건이었습니다. /api/copy만 traffic이 없었습니다.

unique IP의 65.38%는 한 instance만 방문했고 8.27%는 네 instance 모두와 상호작용했습니다. 같은 honeypot instance로 돌아온 비율은 65.72%였고 MIH 68.63%, LIH 62.59%였습니다. LIH·MIH unique source는 각각 1,799개, 1,859개였습니다.

model management modification attempt는 3,983건이었고 /api/pull 3,832건이 45개 IP에서 발생했습니다. probing·permission test 성격의 model name은 2,232 interaction이었고 official model name을 사칭한 create는 29건, custom model delete는 6건이었습니다.

inference interaction은 56,063건이며 /api/generate가 94.53%였습니다. 4,378개 unique standard prompt와 131개 unique chat을 분류했습니다. generate에는 172개 system prompt가 있었고 모두 특정 high-capability model을 가장하도록 요구했습니다. toxic guardrail test는 19건으로 전체에서 적었습니다.

실제 발견된 취약점 / 사례

한 campaign은 /api/pull에 169.254.169.254/latest/meta-data/, localhost Ollama, localhost SSH, private IP를 넣어 SSRF와 internal service access를 시험했습니다. traversal payload는 ../../../../tmp/...와 URL-encoded variant를 사용했습니다.

/api/create의 Modelfile·template에는 instruction hijacking, canary URL, command-like payload, XMRig mining 의도가 포함됐습니다. official model name으로 malicious artifact를 위장하거나 system prompt를 Bitcoin solicitation으로 바꾸는 begware도 관찰됐습니다.

논문이 연결한 CVE는 authentication 부재 CVE-2025-63389, path traversal CVE-2024-39722, SSRF CVE-2026-85180입니다. 그러나 honeypot telemetry가 이 CVE들의 성공 exploit을 확인한 것은 아닙니다.

저자 주장 vs 실제 증명 범위

public Ollama-like endpoint가 대규모 scanning과 여러 attack payload의 대상이라는 주장은 네 vantage point의 84-day telemetry가 직접 뒷받침합니다. discovery가 dominant하고 management·inference layer가 함께 probe된다는 점도 endpoint count로 입증됩니다.

반면 실제 Ollama host compromise, credential exfiltration, miner execution, downstream attack 성공은 증명하지 않았습니다. backend LLM과 execution engine이 없는 honeypot이므로 논문이 증명한 것은 in-the-wild attempt와 intent pattern입니다.

기존 공격 / 기존 점검 방식과의 차이

Shodan·Censys measurement는 exposure 규모와 banner를 측정하지만 payload와 multi-step behavior가 제한적입니다. 전통 API honeypot은 generic 404나 static JSON을 주고 LLM-specific model management·prompt semantics를 모사하지 않습니다.

Ollure는 Ollama endpoint, model list, session state, prompt response를 구현해 infrastructure request와 LLM-specific prompt를 같은 telemetry에서 봅니다. HIVE-AI가 multi-service analysis pipeline에 초점을 둔 반면 이 연구는 Ollama ecosystem의 장기 passive measurement에 집중합니다.

연구의 한계와 주의해서 볼 부분

관찰 기간과 네 instance는 인터넷 전체를 대표하지 않습니다. cloud·university 두 network와 Frankfurt region 편향이 있고, 검색 엔진 indexing 시점에 따라 traffic이 달라질 수 있습니다.

MIH의 response engine은 dictionary와 regex 중심이며 계산이나 repetition에 우선순위를 둡니다. 실제 model의 safety behavior, latency, context memory와 다르므로 advanced conversational attacker의 engagement는 제한됩니다.

training-time poisoning, vector·embedding weakness, privilege escalation, lateral movement는 architecture상 관찰하지 못했습니다. indirect prompt injection이나 honeypot을 proxy로 쓴 downstream attack도 발견하지 못했습니다.

공개 PoC / Exploit / Tool / Artifact 분석

공식 Ollure GitHub 저장소는 논문 저자 계정 k-elzer에 있으며 main은 MIH, LIH branch는 low-interaction version입니다. repository에는 FastAPI endpoint module, request·response class, response cache, logging, Dockerfile, deployment helper와 Discord maintenance bot이 포함됩니다.

README는 Python 3.12.10과 requirements.txt, main.py, LOG_DIR, LOG_FILE, LOG_HEADERS 설정을 설명합니다. Docker deployment는 UID/GID 20001과 host log bind mount를 전제로 하며, 문서 스스로 clean deployment 절차가 완전하지 않을 수 있다고 경고합니다.

공개 dataset과 analysis code는 Zenodo record에 연결됩니다. GitHub repository는 exploit 도구가 아니라 방어적 측정용 honeypot입니다.

레드팀 / 모의해킹에서 어떻게 활용할까

자산 점검에서는 먼저 Ollama port 11434의 public exposure, reverse proxy auth, version·tags·model management endpoint를 확인합니다. 승인된 lab에서만 canary model name과 loopback test endpoint를 사용해 SSRF·path normalization·quota behavior를 검증합니다.

cloud metadata, 실제 internal service, 외부 callback domain, mining payload를 사용하지 않습니다. management endpoint가 state를 변경하거나 unexpected egress를 시도하면 즉시 중단하고 network log와 container diff를 보존합니다.

실제 점검 시 추가할 체크리스트

  • port 11434와 OpenAI-compatible endpoint의 internet exposure를 inventory합니다.
  • /api/version, /api/tags, /api/ps, /api/show에 인증을 요구합니다.
  • /api/pull, /api/push, /api/create, /api/delete를 public inference plane에서 분리합니다.
  • model URL과 path를 canonicalize하고 loopback, private IP, metadata IP를 차단합니다.
  • container를 non-root, read-only filesystem, minimum volume로 실행합니다.
  • outbound network를 registry allowlist로 제한합니다.
  • model digest, signature, provenance를 검증합니다.
  • context length, token prediction, concurrent generation에 quota를 둡니다.
  • tool schema에 file·shell·network 권한이 노출되는지 확인합니다.
  • honeypot telemetry와 production detection rule을 분리하고 privacy를 보존합니다.

실무 가치 평가

self-hosted LLM infrastructure의 실제 공격 표면을 endpoint 단위로 보여 주는 실무 가치가 높습니다. SOC는 generic web scan뿐 아니라 model inventory probe, model lifecycle request, resource-exhaustion option, agent tool schema를 detection source로 추가할 수 있습니다.

다만 payload 관찰과 exploitation 성공을 구분해야 합니다. 취약점 우선순위는 제품 version, exposure, auth, egress, host privilege를 결합해 정해야 합니다.

결론

OllamaDrama는 exposed LLM endpoint가 이미 광범위한 automated discovery와 multi-layer attack probe를 받고 있음을 보여 줍니다. 공격자는 model inference만이 아니라 inventory, registry, filesystem, internal network, tool authority까지 하나의 surface로 취급합니다.

방어의 핵심은 public inference와 management plane을 분리하고, authentication·egress·model provenance·resource quota를 적용하는 것입니다. honeypot 결과는 실제 compromise 통계가 아니라 공격 시도 telemetry라는 범위 안에서 활용해야 합니다.

반응형

댓글