HoneyPLC: A Next-Generation Honeypot for Industrial Control Systems

被引:27
|
作者
Morales, Efren Lopez [1 ]
Rubio-Medrano, Carlos [2 ]
Doupe, Adam [1 ]
Shoshitaishvili, Yan [1 ]
Wang, Ruoyu [1 ]
Bao, Tiffany [1 ]
Ahn, Gail-Joon [1 ,3 ]
机构
[1] Arizona State Univ, Tempe, AZ 85287 USA
[2] Texas A&M Univ, Corpus Christi, TX USA
[3] Samsung Res, Seoul, South Korea
基金
美国国家科学基金会;
关键词
D O I
10.1145/3372297.3423356
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Industrial Control Systems (ICS) provide management and control capabilities for mission-critical utilities such as the nuclear, power, water, and transportation grids. Within ICS, Programmable Logic Controllers (PLCs) play a key role as they serve as a convenient bridge between the cyber and the physical worlds, e.g., controlling centrifuge machines in nuclear power plants. The critical roles that ICS and PLCs play have made them the target of sophisticated cyberattacks that are designed to disrupt their operation, which creates both social unrest and financial losses. In this context, honeypots have been shown to be highly valuable tools for collecting real data, e.g., malware payload, to better understand the many different methods and strategies that attackers use. However, existing state-of-the-art honeypots for PLCs lack sophisticated service simulations that are required to obtain valuable data. Worse, they cannot adapt while ICS malware keeps evolving, and attack patterns become more sophisticated. To overcome these shortcomings, we present HoneyPLC, a high-interaction, extensible, and malware-collecting honeypot supporting a broad spectrum of PLCs models and vendors. Results from our experiments show that HoneyPLC exhibits a high level of camouflaging: it is identified as real devices by multiple widely used reconnaissance tools, including Nmap, Shodan's Honeyscore, the Siemens Step? Manager, PLCinject, and PLCScan, with a high level of confidence. We deployed HoneyPLC on Amazon AWS and recorded a large amount of interesting interactions over the Internet, showing not only that attackers are in fact targeting ICS systems, but also that HoneyPLC can effectively engage and deceive them while collecting data samples for future analysis.
引用
收藏
页码:279 / 291
页数:13
相关论文
共 50 条
  • [21] A SERIOUS PROBLEM FOR NEXT-GENERATION SYSTEMS
    STANKOVIC, JA
    [J]. COMPUTER, 1988, 21 (10) : 10 - 19
  • [22] Comparison of Next-Generation Sequencing Systems
    Liu, Lin
    Li, Yinhu
    Li, Siliang
    Hu, Ni
    He, Yimin
    Pong, Ray
    Lin, Danni
    Lu, Lihua
    Law, Maggie
    [J]. JOURNAL OF BIOMEDICINE AND BIOTECHNOLOGY, 2012,
  • [23] Next-Generation Robots and Systems Introduction
    Popa, Dan O.
    Wijesundara, Muthu B. J.
    [J]. NEXT-GENERATION ROBOTS AND SYSTEMS, 2014, 9116
  • [24] NEXT-GENERATION OPERATING-SYSTEMS
    HELLER, M
    CRABB, D
    ULLMAN, E
    THOMPSON, T
    HAYES, F
    POURNELLE, J
    LINDERHOLM, O
    [J]. BYTE, 1992, 17 (02): : 91 - 92
  • [25] Next-Generation Infrastructure Systems and Services
    Weijnen, Margot P. C.
    [J]. IEEE SYSTEMS MAN AND CYBERNETICS MAGAZINE, 2019, 5 (03): : 8 - 9
  • [26] Plasmonics for Next-Generation Wireless Systems
    Burla, Maurizio
    Bonjour, Romain
    Salamin, Yannick
    Abrecht, Felix
    Hoessbacher, Claudia
    Haffner, Christian
    Heni, Wolfgang
    Fedoryshyn, Yuriy
    Baeuerle, Benedikt
    Josten, Arne
    Elder, Delwin
    Dalton, Larry
    Leuthold, Juerg
    [J]. 2018 IEEE/MTT-S INTERNATIONAL MICROWAVE SYMPOSIUM - IMS, 2018, : 1308 - 1311
  • [27] Next-generation Web tools for control
    Felton, B
    [J]. INTECH, 2001, 48 (03) : 52 - 54
  • [28] QoS control in next-generation networks
    Leon-Garcia, Alberto
    Choi, Jun Kyun
    Widjaja, Indra
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2007, 45 (09) : 114 - 114
  • [29] Next-generation builds total control
    Senior, Gordon
    [J]. PACE - Process and Control Engineering, 2000, 53 (01): : 30 - 31
  • [30] Next-generation people for next-generation technologies
    Mittelstadt, E
    [J]. MANUFACTURING ENGINEERING, 1996, 117 (04): : 128 - 128