HoneyPLC: A Next-Generation Honeypot for Industrial Control Systems

被引:27
|
作者
Morales, Efren Lopez [1 ]
Rubio-Medrano, Carlos [2 ]
Doupe, Adam [1 ]
Shoshitaishvili, Yan [1 ]
Wang, Ruoyu [1 ]
Bao, Tiffany [1 ]
Ahn, Gail-Joon [1 ,3 ]
机构
[1] Arizona State Univ, Tempe, AZ 85287 USA
[2] Texas A&M Univ, Corpus Christi, TX USA
[3] Samsung Res, Seoul, South Korea
基金
美国国家科学基金会;
关键词
D O I
10.1145/3372297.3423356
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Industrial Control Systems (ICS) provide management and control capabilities for mission-critical utilities such as the nuclear, power, water, and transportation grids. Within ICS, Programmable Logic Controllers (PLCs) play a key role as they serve as a convenient bridge between the cyber and the physical worlds, e.g., controlling centrifuge machines in nuclear power plants. The critical roles that ICS and PLCs play have made them the target of sophisticated cyberattacks that are designed to disrupt their operation, which creates both social unrest and financial losses. In this context, honeypots have been shown to be highly valuable tools for collecting real data, e.g., malware payload, to better understand the many different methods and strategies that attackers use. However, existing state-of-the-art honeypots for PLCs lack sophisticated service simulations that are required to obtain valuable data. Worse, they cannot adapt while ICS malware keeps evolving, and attack patterns become more sophisticated. To overcome these shortcomings, we present HoneyPLC, a high-interaction, extensible, and malware-collecting honeypot supporting a broad spectrum of PLCs models and vendors. Results from our experiments show that HoneyPLC exhibits a high level of camouflaging: it is identified as real devices by multiple widely used reconnaissance tools, including Nmap, Shodan's Honeyscore, the Siemens Step? Manager, PLCinject, and PLCScan, with a high level of confidence. We deployed HoneyPLC on Amazon AWS and recorded a large amount of interesting interactions over the Internet, showing not only that attackers are in fact targeting ICS systems, but also that HoneyPLC can effectively engage and deceive them while collecting data samples for future analysis.
引用
收藏
页码:279 / 291
页数:13
相关论文
共 50 条
  • [1] Intrusion and anomaly detection for the next-generation of industrial automation and control systems
    Rosa, Luis
    Cruz, Tiago
    de Freitas, Miguel Borges
    Quiterio, Pedro
    Henriques, Joao
    Caldeira, Filipe
    Monteiro, Edmundo
    Simoes, Paulo
    [J]. FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2021, 119 : 50 - 67
  • [2] Automatic Attack Surface Reduction in Next-Generation Industrial Control Systems
    Obermeier, Sebastian
    Wahler, Michael
    Sivanthi, Thanikesavan
    Schlegel, Roman
    Monot, Aurelien
    [J]. 2014 IEEE SYMPOSIUM ON COMPUTATIONAL INTELLIGENCE IN CYBER SECURITY (CICS), 2014, : 42 - 49
  • [3] Advanced Motion Control for Next-Generation Industrial Applications
    Fujimoto, Yasutaka
    Murakami, Toshiyuki
    Oboe, Roberto
    [J]. IEEE TRANSACTIONS ON INDUSTRIAL ELECTRONICS, 2016, 63 (03) : 1886 - 1888
  • [4] Next-Generation Access Control for Distributed Control Systems
    Huh, Jun Ho
    Bobba, Rakesh B.
    Markham, Tom
    Nicol, David M.
    Hull, Julie
    Chernoguzov, Alex
    Khurana, Himanshu
    Staggs, Kevin
    Huang, Jingwei
    [J]. IEEE INTERNET COMPUTING, 2016, 20 (05) : 28 - 37
  • [5] Realising next-generation web service-driven industrial systems
    Stamatis Karnouskos
    [J]. The International Journal of Advanced Manufacturing Technology, 2012, 60 : 409 - 419
  • [6] Realising next-generation web service-driven industrial systems
    Karnouskos, Stamatis
    [J]. INTERNATIONAL JOURNAL OF ADVANCED MANUFACTURING TECHNOLOGY, 2012, 60 (1-4): : 409 - 419
  • [7] Enabling Next-Generation Industrial Networks with Industrial PON
    Jiang, Ming
    Luo, Yuanqiu
    Zhang, Dezhi
    Effenberger, Frank
    Jin, Jialiang
    Ansari, Nirwan
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2023, 61 (04) : 129 - 135
  • [8] Next-generation CAD systems
    Deitz, D
    [J]. MECHANICAL ENGINEERING, 1996, 118 (08) : 68 - 72
  • [9] Next-generation bioimaging systems
    Kovacevic, Jelena
    [J]. 2006 7th Nordic Signal Processing Symposium, 2006, : 1 - 1
  • [10] Next-generation turbine systems
    [J]. Layne, A.W., 2001, Institute of Electrical and Electronics Engineers Inc. (21):