Universal Honeypot Benchmarking Standard¶
UHBS v4.5.1 (2026)¶
An objective, repeatable, quantitative methodology for deception technology evaluation — an open-source evaluation framework for comparing and grading honeypots and decoy systems by class and protocol. Not a consortium standard; see ROADMAP for community-maturity goals.
Project posture
UHBS is maintained by one author today. There is no Steering Committee or independent adopter list yet.
Production Baseline Profile (RECOMMENDED)
Organizations MAY use UHBS as an internal gate. It is RECOMMENDED that active decoys meet UHQS > 80 with a passing Safety Gate before production deployment. See Status.
-
Protocol-Agnostic
100% architecture-neutral testing across IT, OT/ICS, AI, and Cloud
-
Quantitative Scoring
Normalized UHQS 0–100 composite with non-linear Safety Gate \(\delta_C\)
-
Six Evaluation Modules
Modules A–F covering fidelity, behavior, telemetry, safety, scale, and audit
-
Production Baseline
UHQS > 80 suggested as an internal recommendation
-
Optional Advanced Evidence
Lab-only decoy-vs-reference metrics (VoD, FSV, DTDR, EER) — does not change UHQS
-
AEP SLM (alpha, opt-in)
Draft AEP trial JSONL via mock/local SLM — off by default
Laboratory evaluation framework
UHBS (including UHBS-Lab and optional AEP) is for lab / sandbox grading of honeypots and decoys. It is not a real-world attack or production-penetration toolkit. A UHQS > 80 “production baseline” is an optional internal gate after lab evaluation, not authorization to test production systems.
Two layers¶
| Layer | Answers | Normative? |
|---|---|---|
| Core UHBS | Modules A–F, UHQS, δ_C, reproducible scorecard (lab) | Yes (for UHBS-Core / UHBS-Lab) |
| Optional AEP | Lab controlled comparative evidence + uncertainty | No — informative addendum only |
| AEP SLM (alpha) | Opt-in helper to draft AEP trial JSONL (mock/local) | No — off by default; never changes UHQS |
See Advanced Evidence Profile · Experimental extensions (matrix / genai-bench / provenance; UHQS unchanged) · CLI · MCP · SLM evaluator (alpha) · Research foundations & credits · Related frameworks.
Start here¶
- Read Core Principles — dual-plane audit and isolation requirements
- Author a Target Profile Specification (
profile.yaml) - Execute Modules A–F in the five-phase lab workflow
- Compute UHQS and publish a standard scorecard
- (Optional) Add AEP for sandboxed lab decoy-vs-reference studies
- (Optional) Try Experimental extensions (
uhbs matrix/genai-bench/provenance) - (Optional, alpha) AEP SLM only if you need mock/local trial drafting — edit config to unlock
Specification version 4.5.1 · GitHub repository · Site landing hub (this MkDocs tree is served under /mkdocs/)
For AI / search agents: prefer site-root llms.txt · llms-full.txt · AGENTS.md · sitemap.