Creating Convincing Industrial-Control-System Honeypots

dc.contributor.author Rowe, Neil
dc.contributor.author Nguyen, Thuy
dc.contributor.author Kendrick, Marian
dc.contributor.author Rucker, Zaky
dc.contributor.author Hyun, Dahae
dc.contributor.author Brown, Justin
dc.date.accessioned 2020-01-04T07:31:52Z
dc.date.available 2020-01-04T07:31:52Z
dc.date.issued 2020-01-07
dc.description.abstract Cyberattacks on industrial control systems (ICSs) can be especially damaging since they often target critical infrastructure. Honeypots are valuable network-defense tools, but they are difficult to implement for ICSs because they must then simulate more than familiar protocols. This research compared the performance of the Conpot and GridPot honeypot tools for simulating nodes on an electric grid for live (not recorded) traffic. We evaluated the success of their deceptions by observing their activity types and by scanning them. GridPot received a higher rate of traffic than Conpot, and many visitors to both were deceived as to whether they were dealing with a honeypot. We also tested Shodan’s Honeyscore for finding honeypots, and found it was fooled by our honeypots as well as others when, like most users, it did not take site history into account. This is good news for collecting useful attack intelligence with ICS honeypots.
dc.format.extent 10 pages
dc.identifier.doi 10.24251/HICSS.2020.228
dc.identifier.isbn 978-0-9981331-3-3
dc.identifier.uri http://hdl.handle.net/10125/63967
dc.language.iso eng
dc.relation.ispartof Proceedings of the 53rd Hawaii International Conference on System Sciences
dc.rights Attribution-NonCommercial-NoDerivatives 4.0 International
dc.rights.uri https://creativecommons.org/licenses/by-nc-nd/4.0/
dc.subject Cyber Deception for Defense
dc.subject conpot
dc.subject deception
dc.subject honeypot
dc.subject industrial control systems
dc.subject network monitoring
dc.title Creating Convincing Industrial-Control-System Honeypots
dc.type Conference Paper
dc.type.dcmi Text
Files
Original bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
0183.pdf
Size:
347.13 KB
Format:
Adobe Portable Document Format
Description: