蜜罐
计算机科学
可扩展性
小贩
可编程逻辑控制器
互联网
嵌入式系统
过程(计算)
网络安全
虚拟机
操作系统
计算机安全
计算机网络
营销
业务
作者
Samin Y. Chowdhury,Brandon Dudley,Ruimin Sun
标识
DOI:10.1109/eurospw59978.2023.00044
摘要
Programmable logic controllers (PLCs) are essential components of Industrial Control System (ICS) in acting as a practical link between the cyber and physical worlds. In recent years, we have seen an increase in attacks targeting PLCs. Honeypot for PLCs, as an effective technique to gather attacker information and attack tactics, is limited in vendor-specific implementation, configuration, extensibility, and scalability. With the emergence of virtual PLCs, this paper introduces a honeypot, named PLCHoney, to overcome the existing challenges in a cost-effective approach. We designed and implemented PLCHoney with a proxy profiler, dockerized virtual PLCs, a physical process simulator, and a security analysis engine. PLCHoney was able to correctly simulate responses to various internet requests and tested effectively on a network of virtualized traffic light applications. We enabled further security analysis with a dataset containing PLC I/O status, collected with and without attacks. We envision that PLCHoney paves the avenue for the future development of PLC-based honeypots.
科研通智能强力驱动
Strongly Powered by AbleSci AI