HoneyPLC: A Next-Generation Honeypot for Industrial Control Systems


연구 분야: Safety



학회: CCS '20: Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security


초록

Industrial Control Systems (ICS) provide management and control capabilities for mission-critical utilities such as the nuclear, power, water, and transportation grids. Within ICS, Programmable Logic Controllers (PLCs) play a key role as they serve as a convenient bridge between the cyber and the physical worlds, e.g., controlling centrifuge machines in nuclear power plants. The critical roles that ICS and PLCs play have made them the target of sophisticated cyberattacks that are designed to disrupt their operation, which creates both social unrest and financial losses. In this context, honeypots have been shown to be highly valuable tools for collecting real data, e.g., malware payload, to better understand the many different methods and strategies that attackers use. However, existing state-of-the-art honeypots for PLCs lack sophisticated service simulations that are required to obtain valuable data. Worse, they cannot adapt while ICS malware keeps evolving, and attack patterns become more sophisticated. To overcome these shortcomings, we present HoneyPLC, a high-interaction, extensible, and malware collecting honeypot supporting a broad spectrum of PLCs models and vendors. Results from our experiments show that HoneyPLC exhibits a high level of camouflaging: it is identified as real devices by multiple widely used reconnaissance tools, including Nmap, Shodan's Honeyscore, the Siemens Step7 Manager, PLCinject, and PLCScan, with a high level of confidence. We deployed HoneyPLC on Amazon AWS and recorded a large amount of interesting interactions over the Internet, showing not only that attackers are in fact targeting ICS systems, but also that HoneyPLC can effectively engage and deceive them while collecting data samples for future analysis.


Author Profile
Efrén López-Morales

Arizona State University Tempe AZ USA

Azerbaijan
Author Profile
Carlos E Rubio-Medrano

Texas A&M University - Corpus Christi Corpus Christi TX USA

United States
Author Profile
Adam Doupé

Arizona State University Tempe AZ USA

Azerbaijan

📄 논문 정보

발행 연도 2020년
인용수 56
출판 국가 Azerbaijan, United States
사이트 ACM
좋아요 수 0

연관 논문 목록 (661건)