Containerized Cozenage: Exploring the Effectiveness of High Interaction ICS Honeypot Containers

Loading...
Thumbnail Image

Contributor

Advisor

Editor

Performer

Department

Instructor

Depositor

Speaker

Researcher

Consultant

Interviewer

Interviewee

Narrator

Transcriber

Annotator

Journal Title

Journal ISSN

Volume Title

Publisher

Journal Name

Volume

Number/Issue

Starting Page

1112

Ending Page

Alternative Title

Abstract

Industrial control systems (ICS) provide critical functionality and are responsible for ensuring water treatment and electrical grid operation, among other vital services. Therefore, they are prime targets for cyber attackers. As attackers employ techniques such as living-off-the-land to remain undetected, defenders need to adapt their tools to protect ICS networks. We present a high interaction honeypot which runs the Sedona Framework within a Docker container. Containerized honeypots could mitigate costs associated with deployment and maintenance. Fingerprint evasion methods are implemented in our honeypot's design. These methods include creating a physics-aware simulated centrifuge device, and ensuring compatibility with human machine interface (HMI) software. The honeypot's behavior was compared against a physical system: the Contemporary Controls BASC-20T. The honeypot was found to fully interoperate with two HMI control applications. Network traffic analysis reveals that the honeypot's network response time signature can be made to closely resemble the BASC-20T.

Description

Citation

Extent

10

Format

Type

Conference Paper

Geographic Location

Time Period

Related To

Proceedings of the 58th Hawaii International Conference on System Sciences

Related To (URI)

Table of Contents

Rights

Attribution-NonCommercial-NoDerivatives 4.0 International

Rights Holder

Catalog Record

Local Contexts

Email libraryada-l@lists.hawaii.edu if you need this content in ADA-compliant format.