An ICS Honeynet for Detecting and Analyzing Cyberattacks in Industrial Plants

被引:1
|
作者
Schuba, Marko [1 ]
Hotken, Hans [1 ]
Linzbach, Sophie [1 ]
机构
[1] Aachen Univ Appl Sci, Aachen, Germany
关键词
Conpot; honeypot; honeynet; ICS; cybersecurity; SIMATIC S7;
D O I
10.1109/ICECET52533.2021.9698746
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Cybersecurity of Industrial Control Systems (ICS) is an important issue, as ICS incidents may have a direct impact on safety of people or the environment. At the same time the awareness and knowledge about cybersecurity, particularly in the context of ICS, is alarmingly low. Industrial honeypots offer a cheap and easy to implement way to raise cybersecurity awareness and to educate ICS staff about typical attack patterns. When integrated in a productive network, industrial honeypots may not only reveal attackers early but may also distract them from the actual important systems of the network. Implementing multiple honeypots as a honeynet, the systems can be used to emulate or simulate a whole Industrial Control System. This paper describes a network of honeypots emulating HTTP, SNMP, S7communication and the Modbus protocol using Conpot, IMUNES and SNAP7. The nodes mimic SIMATIC S7 programmable logic controllers (PLCs) which are widely used across the globe. The deployed honeypots' features will be compared with the features of real SIMATIC S7 PLCs. Furthermore, the honeynet has been made publicly available for ten days and occurring cyberattacks have been analyzed
引用
收藏
页码:796 / 801
页数:6
相关论文
共 50 条
  • [1] Analyzing the Impact of Cyberattacks on Industrial Control Systems using Timed Automata
    Jawad, Alvi
    Jaskolka, Jason
    2021 IEEE 21ST INTERNATIONAL CONFERENCE ON SOFTWARE QUALITY, RELIABILITY AND SECURITY (QRS 2021), 2021, : 966 - 977
  • [2] Detecting cyberattacks in industrial control systems using online learning algorithms
    Li, Guangxia
    Shen, Yulong
    Zhao, Peilin
    Lu, Xiao
    Liu, Jia
    Liu, Yangyang
    Hoi, Steven C. H.
    NEUROCOMPUTING, 2019, 364 : 338 - 348
  • [3] Sensors for detection of cyber threats on industrial environment using a high interaction ICS/SCADA Honeynet1
    Campos, Maxli
    Gomes, Elson
    Machado, Raphael
    PROCEEDINGS OF 2022 IEEE INTERNATIONAL WORKSHOP ON METROLOGY FOR INDUSTRY 4.0 & IOT (IEEE METROIND4.0&IOT), 2022, : 317 - 321
  • [4] Detecting Unknown Vulnerabilities Using Honeynet
    Albashir, Anas Abd Almonim Nour
    2015 FIRST INTERNATIONAL CONFERENCE ON ANTI-CYBERCRIME (ICACC), 2015, : 10 - 13
  • [5] Detecting cyberattacks using anomaly detection in industrial control systems: A Federated Learning approach
    Huong, Truong Thu
    Bac, Ta Phuong
    Long, Dao Minh
    Luong, Tran Duc
    Dan, Nguyen Minh
    Quang, Le Anh
    Cong, Le Thanh
    Thang, Bui Doan
    Tran, Kim Phuc
    COMPUTERS IN INDUSTRY, 2021, 132 (132)
  • [6] Framework for Detecting Control CommandInjection Attacks on Industrial Control Systems(ICS)
    Rasapour, Farhad
    Serra, Edoardo
    Mehrpouyan, Hoda
    2019 SEVENTH INTERNATIONAL SYMPOSIUM ON COMPUTING AND NETWORKING (CANDAR 2019), 2019, : 211 - 217
  • [7] Analyzing the Quality of Synthetic Adversarial Cyberattacks
    Sabeel, Ulya
    Heydari, Shahram Shah
    El-Khatib, Khalil
    Elgazzar, Khalid
    2023 19TH INTERNATIONAL CONFERENCE ON NETWORK AND SERVICE MANAGEMENT, CNSM, 2023,
  • [8] Detecting new and unknown malwares using honeynet
    Szczepanik M.
    Jóźwiak I.
    Advances in Intelligent and Soft Computing, 2010, 80 : 173 - 180
  • [9] Industrial Security: Detecting and closing IT security gaps in industrial plants
    GmbH, Koramis
    ZKG INTERNATIONAL, 2018, 71 (11): : 44 - 46
  • [10] An interpretable semi-supervised system for detecting cyberattacks using anomaly detection in industrial scenarios
    Gomez, Angel Luis Perales
    Maimo, Lorenzo Fernandez
    Celdran, Alberto Huertas
    Clemente, Felix J. Garcia
    IET INFORMATION SECURITY, 2023, 17 (04) : 553 - 566