Framework for Industrial Control System Honeypot Network Traffic Generation

Abstract

Defending critical infrastructure assets is an important but extremely difficult and expensive task. Historically, decoys have been used very effectively to distract attackers and in some cases convince an attacker to reveal their attack strategy. Several researchers have proposed the use of honeypots to protect programmable logic controllers, specifically those used to support critical infrastructure. However, most of these honeypot designs are static systems that wait for a would-be attacker. To be effective, honeypot decoys need to be as realistic as possible. This paper introduces a proof-of-concept honeypot network traffic generator that mimics genuine control systems. Experiments are conducted using a Siemens APOGEE building automation system for single and dual subnet instantiations. Results indicate that the proposed traffic generator is capable of honeypot integration, traffic matching and routing within the decoy building automation network.

Open PDF

Document Details

Document Type
Technical Report
Publication Date
Mar 23, 2017
Accession Number
AD1054692

Entities

People

  • Htein A Lin

Organizations

  • Air Force Institute of Technology

Tags

Communities of Interest

  • C4I
  • Cyber
  • Energy and Power Technologies

DTIC Thesaurus Topics

  • Air Force
  • Command And Control
  • Computer Network Security
  • Computer Networks
  • Computers
  • Control Systems
  • Department Of Homeland Security
  • Detectors
  • Engineering
  • Graphical User Interface
  • Human Machine Interface
  • Human-Machine Interfaces
  • Industrial Control Systems
  • Infrastructure
  • Intellectual Property
  • Intelligence Collection
  • Network Architecture
  • Network Protocols
  • Network Topology
  • Operating Systems
  • Pilot Studies
  • Reliability
  • Statistics
  • Test And Evaluation
  • United States
  • United States Government
  • User Interface

Fields of Study

  • Computer science

Readers

  • Computer Networking
  • Cybersecurity.