Industrial Control Honeypot Based on Power Plant Control System


연구 분야: Infrastructure



학회: International Conference on Web Services


초록

Industrial honeypot is different from ordinary honeypot mainly because of the industrial control protocol used in the communication of industrial control equipment in the industrial control system. The trapping ability of industrial control honeypot mainly depends on its simulation interaction level, and the simulation protocol communication interaction determines the authenticity of the trapping environment. Based on the investigation of the control system of real power plant, it is proposed that the control system of power plant is placed in sandbox to restore the high fidelity of honeypot. Using protocol reverse analysis technology, in-depth analysis of EGD industrial control protocol to master protocol characteristics, timely sense abnormal industrial control traffic data and abnormal protocol packets. Use the Cuckoo sandbox framework to deploy honeypots with the main aircraft deployment mechanism to prevent escape or other sabotage if an attacker identifies the honeypot as a springboard. Finally, all suspected attack data captured by honeypot will be submitted to cuckoo host for analysis, providing reliable data for network security administrators and a more secure active defense network environment for power plants.


Author Profile
Xu Yao

Inner Mongolia University of Technology Hohhot 010050 China

China
Author Profile
Gang Wang

Inner Mongolia University of Technology Hohhot 010050 China

China
Author Profile
Pei-zhi Yan

Information Construction and Management Center Hohhot China

Andorra

📄 논문 정보

발행 연도 2022년
인용수 0
출판 국가 Andorra, China
사이트 Springer
좋아요 수 0

연관 논문 목록 (168건)