Creating Synthetic Attacks with Evolutionary Algorithms for Proactive Defense of Industrial Control Systems

dc.contributor.author Haynes, Nathaniel
dc.contributor.author Nguyen, Thuy
dc.contributor.author Rowe, Neil
dc.date.accessioned 2022-12-27T19:00:31Z
dc.date.available 2022-12-27T19:00:31Z
dc.date.issued 2023-01-03
dc.description.abstract Industrial control systems (ICS) play an important role in critical infrastructure. Cybersecurity defenders can use honeypots (decoy systems) to capture and study malicious ICS traffic. A problem with existing ICS honeypots is their low interactivity, causing intruders to quickly abandon the attack attempts. This research aims to improve ICS honeypots by feeding them realistic artificially generated packets and examining their behavior to proactively identify functional gaps in defenses. Our synthetic attack generator (SAGO) uses an evolutionary algorithm on known attack traffic to create new variants of Log4j exploits (CVE-2021-44228) and Industroyer2 malware. We tested over 5,200 and 256 unique Log4j and IEC 104 variations respectively, with success rates up to 70 percent for Log4j and 40 percent for IEC 104. We identified improvements to our honeypot’s interactivity based on its responses to these attacks. Our technique can aid defenders in hardening perimeter protection against new attack variants.
dc.format.extent 10
dc.identifier.doi 10.24251/HICSS.2023.212
dc.identifier.isbn 978-0-9981331-6-4
dc.identifier.uri https://hdl.handle.net/10125/102842
dc.language.iso eng
dc.relation.ispartof Proceedings of the 56th Hawaii International Conference on System Sciences
dc.rights Attribution-NonCommercial-NoDerivatives 4.0 International
dc.rights.uri https://creativecommons.org/licenses/by-nc-nd/4.0/
dc.subject Cybersecurity and Privacy in Government
dc.subject evolutionary algorithm
dc.subject honeypot
dc.subject industrial control system
dc.subject security testing
dc.subject synthetic attack
dc.title Creating Synthetic Attacks with Evolutionary Algorithms for Proactive Defense of Industrial Control Systems
dc.type.dcmi text
prism.startingpage 1684
Files
Original bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
0165.pdf
Size:
895.49 KB
Format:
Adobe Portable Document Format
Description: