Containerized Cozenage: Exploring the Effectiveness of High Interaction ICS Honeypot Containers
Loading...
Files
Date
Contributor
Advisor
Editor
Performer
Department
Instructor
Depositor
Speaker
Researcher
Consultant
Interviewer
Interviewee
Narrator
Transcriber
Annotator
Journal Title
Journal ISSN
Volume Title
Publisher
Journal Name
Volume
Number/Issue
Starting Page
1112
Ending Page
Alternative Title
Abstract
Industrial control systems (ICS) provide critical functionality and are responsible for ensuring water treatment and electrical grid operation, among other vital services. Therefore, they are prime targets for cyber attackers. As attackers employ techniques such as living-off-the-land to remain undetected, defenders need to adapt their tools to protect ICS networks. We present a high interaction honeypot which runs the Sedona Framework within a Docker container. Containerized honeypots could mitigate costs associated with deployment and maintenance. Fingerprint evasion methods are implemented in our honeypot's design. These methods include creating a physics-aware simulated centrifuge device, and ensuring compatibility with human machine interface (HMI) software. The honeypot's behavior was compared against a physical system: the Contemporary Controls BASC-20T. The honeypot was found to fully interoperate with two HMI control applications. Network traffic analysis reveals that the honeypot's network response time signature can be made to closely resemble the BASC-20T.
Description
Citation
Extent
10
Format
Type
Conference Paper
Geographic Location
Time Period
Related To
Proceedings of the 58th Hawaii International Conference on System Sciences
Related To (URI)
Table of Contents
Rights
Attribution-NonCommercial-NoDerivatives 4.0 International
Rights Holder
Catalog Record
Local Contexts
Email libraryada-l@lists.hawaii.edu if you need this content in ADA-compliant format.
