HoneyPLC: A Next-Generation Honeypot for Industrial Control Systems

被引:27
|
作者
Morales, Efren Lopez [1 ]
Rubio-Medrano, Carlos [2 ]
Doupe, Adam [1 ]
Shoshitaishvili, Yan [1 ]
Wang, Ruoyu [1 ]
Bao, Tiffany [1 ]
Ahn, Gail-Joon [1 ,3 ]
机构
[1] Arizona State Univ, Tempe, AZ 85287 USA
[2] Texas A&M Univ, Corpus Christi, TX USA
[3] Samsung Res, Seoul, South Korea
基金
美国国家科学基金会;
关键词
D O I
10.1145/3372297.3423356
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Industrial Control Systems (ICS) provide management and control capabilities for mission-critical utilities such as the nuclear, power, water, and transportation grids. Within ICS, Programmable Logic Controllers (PLCs) play a key role as they serve as a convenient bridge between the cyber and the physical worlds, e.g., controlling centrifuge machines in nuclear power plants. The critical roles that ICS and PLCs play have made them the target of sophisticated cyberattacks that are designed to disrupt their operation, which creates both social unrest and financial losses. In this context, honeypots have been shown to be highly valuable tools for collecting real data, e.g., malware payload, to better understand the many different methods and strategies that attackers use. However, existing state-of-the-art honeypots for PLCs lack sophisticated service simulations that are required to obtain valuable data. Worse, they cannot adapt while ICS malware keeps evolving, and attack patterns become more sophisticated. To overcome these shortcomings, we present HoneyPLC, a high-interaction, extensible, and malware-collecting honeypot supporting a broad spectrum of PLCs models and vendors. Results from our experiments show that HoneyPLC exhibits a high level of camouflaging: it is identified as real devices by multiple widely used reconnaissance tools, including Nmap, Shodan's Honeyscore, the Siemens Step? Manager, PLCinject, and PLCScan, with a high level of confidence. We deployed HoneyPLC on Amazon AWS and recorded a large amount of interesting interactions over the Internet, showing not only that attackers are in fact targeting ICS systems, but also that HoneyPLC can effectively engage and deceive them while collecting data samples for future analysis.
引用
收藏
页码:279 / 291
页数:13
相关论文
共 50 条
  • [41] Resilient Control Systems: A Basis for Next-Generation Secure Architectures1
    Rieger, Craig
    [J]. Insight, 2009, 12 (02) : 20 - 22
  • [42] Deep Reinforcement Learning for Power Control in Next-Generation WiFi Network Systems
    El Jamous, Ziad
    Davaslioglu, Kemal
    Sagduyu, Yalin E.
    [J]. 2022 IEEE MILITARY COMMUNICATIONS CONFERENCE (MILCOM), 2022,
  • [43] Data science for next-generation recommender systems
    Wang, Shoujin
    Wang, Yan
    Sivrikaya, Fikret
    Albayrak, Sahin
    Anelli, Vito Walter
    [J]. INTERNATIONAL JOURNAL OF DATA SCIENCE AND ANALYTICS, 2023, 16 (02) : 135 - 145
  • [44] Microfluidic Techniques for Next-Generation Organoid Systems
    Gong, Jing
    Li, Minghui
    Kang, Jiahui
    Yin, Zhiyuan
    Cha, Zhe
    Yang, Jun
    Xu, Haiwei
    [J]. ADVANCED MATERIALS INTERFACES, 2022, 9 (29):
  • [45] Metasurfaces for next-generation wireless communication systems
    Younes Ra'di
    Nikita Nefedkin
    Petar Popovski
    Andrea Alù
    [J]. National Science Review, 2023, 10 (08) : 17 - 19
  • [46] Architectural considerations for next-generation file systems
    Shenoy, P
    Goyal, P
    Vin, HM
    [J]. MULTIMEDIA SYSTEMS, 2002, 8 (04) : 270 - 283
  • [47] Mobility management in next-generation wireless systems
    Akyildiz, IF
    McNair, J
    Ho, JSM
    Uzunalioglu, H
    Wang, WY
    [J]. PROCEEDINGS OF THE IEEE, 1999, 87 (08) : 1347 - 1384
  • [48] OPTICS ILLUMINATE NEXT-GENERATION RADAR SYSTEMS
    LAWRENCE, M
    [J]. MICROWAVES & RF, 1988, 27 (06) : 165 - &
  • [49] NEXT-GENERATION OPERATING-SYSTEMS ARCHITECTURE
    GIEN, M
    [J]. LECTURE NOTES IN COMPUTER SCIENCE, 1991, 563 : 227 - 232
  • [50] Metasurfaces for next-generation wireless communication systems
    Ra'di, Younes
    Nefedkin, Nikita
    Popovski, Petar
    Alu, Andrea
    [J]. NATIONAL SCIENCE REVIEW, 2023, 10 (08)