Skip to content

Universal Honeypot Benchmarking Standard

UHBS v4.5.1 (2026)

An objective, repeatable, quantitative methodology for deception technology evaluation — an open-source evaluation framework for comparing and grading honeypots and decoy systems by class and protocol. Not a consortium standard; see ROADMAP for community-maturity goals.

Project posture

UHBS is maintained by one author today. There is no Steering Committee or independent adopter list yet.

Production Baseline Profile (RECOMMENDED)

Organizations MAY use UHBS as an internal gate. It is RECOMMENDED that active decoys meet UHQS > 80 with a passing Safety Gate before production deployment. See Status.

  • Protocol-Agnostic


    100% architecture-neutral testing across IT, OT/ICS, AI, and Cloud

  • Quantitative Scoring


    Normalized UHQS 0–100 composite with non-linear Safety Gate \(\delta_C\)

  • Six Evaluation Modules


    Modules A–F covering fidelity, behavior, telemetry, safety, scale, and audit

  • Production Baseline


    UHQS > 80 suggested as an internal recommendation

  • Optional Advanced Evidence


    Lab-only decoy-vs-reference metrics (VoD, FSV, DTDR, EER) — does not change UHQS

  • AEP SLM (alpha, opt-in)


    Draft AEP trial JSONL via mock/local SLM — off by default

Laboratory evaluation framework

UHBS (including UHBS-Lab and optional AEP) is for lab / sandbox grading of honeypots and decoys. It is not a real-world attack or production-penetration toolkit. A UHQS > 80 “production baseline” is an optional internal gate after lab evaluation, not authorization to test production systems.

Two layers

Layer Answers Normative?
Core UHBS Modules A–F, UHQS, δ_C, reproducible scorecard (lab) Yes (for UHBS-Core / UHBS-Lab)
Optional AEP Lab controlled comparative evidence + uncertainty No — informative addendum only
AEP SLM (alpha) Opt-in helper to draft AEP trial JSONL (mock/local) No — off by default; never changes UHQS

See Advanced Evidence Profile · Experimental extensions (matrix / genai-bench / provenance; UHQS unchanged) · CLI · MCP · SLM evaluator (alpha) · Research foundations & credits · Related frameworks.

Start here

  1. Read Core Principles — dual-plane audit and isolation requirements
  2. Author a Target Profile Specification (profile.yaml)
  3. Execute Modules A–F in the five-phase lab workflow
  4. Compute UHQS and publish a standard scorecard
  5. (Optional) Add AEP for sandboxed lab decoy-vs-reference studies
  6. (Optional) Try Experimental extensions (uhbs matrix / genai-bench / provenance)
  7. (Optional, alpha) AEP SLM only if you need mock/local trial drafting — edit config to unlock
pip install -e .
uhbs validate-profile templates/profile.yaml

Specification version 4.5.1 · GitHub repository · Site landing hub (this MkDocs tree is served under /mkdocs/)

For AI / search agents: prefer site-root llms.txt · llms-full.txt · AGENTS.md · sitemap.