DocumentCode
3781528
Title
A flexible architecture for Industrial Control System honeypots
Author
Alexandru Vlad Serbanescu;Sebastian Obermeier;Der-Yeuan Yu
Author_Institution
KPMG AG, Zurich, Switzerland
Volume
4
fYear
2015
fDate
7/1/2015 12:00:00 AM
Firstpage
16
Lastpage
26
Abstract
While frequent reports on targeted attacks for Industrial Control Systems hit the news, the amount of untargeted attacks using standardized industrial protocols is still unclear, especially if devices are mistakenly or even knowingly connected to the Internet. To lay the foundation for a deeper insight into the interest of potential attackers, a large scale honeynet system that captures all interactions using industrial protocols is proposed. Special for the honeynet system architecture is the automated deployment on a cloud infrastructure and its modularisation of the industrial protocols. The centralized-but-redundant data collection allows correlating attacks that happen on multiple devices. A real-world experiment confirms the feasibility of the approach, and results of the observed interactions with the honeynet are presented.
Keywords
"Protocols","Security","Control systems","Industrial control","Cloud computing","Ports (Computers)"
Publisher
ieee
Conference_Titel
e-Business and Telecommunications (ICETE), 2015 12th International Joint Conference on
Type
conf
Filename
7518018
Link To Document