Creating Convincing Industrial-Control-System Honeypots

dc.contributor.authorRowe, Neil
dc.contributor.authorNguyen, Thuy
dc.contributor.authorKendrick, Marian
dc.contributor.authorRucker, Zaky
dc.contributor.authorHyun, Dahae
dc.contributor.authorBrown, Justin
dc.date.accessioned2020-01-04T07:31:52Z
dc.date.available2020-01-04T07:31:52Z
dc.date.issued2020-01-07
dc.description.abstractCyberattacks on industrial control systems (ICSs) can be especially damaging since they often target critical infrastructure. Honeypots are valuable network-defense tools, but they are difficult to implement for ICSs because they must then simulate more than familiar protocols. This research compared the performance of the Conpot and GridPot honeypot tools for simulating nodes on an electric grid for live (not recorded) traffic. We evaluated the success of their deceptions by observing their activity types and by scanning them. GridPot received a higher rate of traffic than Conpot, and many visitors to both were deceived as to whether they were dealing with a honeypot. We also tested Shodan’s Honeyscore for finding honeypots, and found it was fooled by our honeypots as well as others when, like most users, it did not take site history into account. This is good news for collecting useful attack intelligence with ICS honeypots.
dc.format.extent10 pages
dc.identifier.doi10.24251/HICSS.2020.228
dc.identifier.isbn978-0-9981331-3-3
dc.identifier.urihttp://hdl.handle.net/10125/63967
dc.language.isoeng
dc.relation.ispartofProceedings of the 53rd Hawaii International Conference on System Sciences
dc.rightsAttribution-NonCommercial-NoDerivatives 4.0 International
dc.rights.urihttps://creativecommons.org/licenses/by-nc-nd/4.0/
dc.subjectCyber Deception for Defense
dc.subjectconpot
dc.subjectdeception
dc.subjecthoneypot
dc.subjectindustrial control systems
dc.subjectnetwork monitoring
dc.titleCreating Convincing Industrial-Control-System Honeypots
dc.typeConference Paper
dc.type.dcmiText

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
0183.pdf
Size:
347.13 KB
Format:
Adobe Portable Document Format