TY - JOUR
T1 - Constructing cost-effective and targetable industrial control system honeypots for production networks
AU - Winn, Michael
AU - Rice, Mason
AU - Dunlap, Stephen
AU - Lopez, Juan
AU - Mullins, Barry
N1 - Publisher Copyright:
© 2015 .
PY - 2015/9/1
Y1 - 2015/9/1
N2 - Critical infrastructure assets - and especially industrial control systems - are at risk. Malicious actors are constantly developing exploits that sneak past security controls. Honeypots offer an opportunity to acquire knowledge about the tactics, techniques and procedures used by malicious entities to compromise sensitive systems. However, the proprietary, and often expensive, hardware and software used by industrial control systems make it very challenging to build flexible, economical and scalable honeypots. This paper describes a technique that uses proxy technology to produce multiple high-interaction honeypots using a single programmable logic controller. The technique provides a cost-effective method for distributing multiple, authentic, targetable honeypots at slightly more than the cost of a single programmable logic controller.
AB - Critical infrastructure assets - and especially industrial control systems - are at risk. Malicious actors are constantly developing exploits that sneak past security controls. Honeypots offer an opportunity to acquire knowledge about the tactics, techniques and procedures used by malicious entities to compromise sensitive systems. However, the proprietary, and often expensive, hardware and software used by industrial control systems make it very challenging to build flexible, economical and scalable honeypots. This paper describes a technique that uses proxy technology to produce multiple high-interaction honeypots using a single programmable logic controller. The technique provides a cost-effective method for distributing multiple, authentic, targetable honeypots at slightly more than the cost of a single programmable logic controller.
KW - Honeypots
KW - Industrial control systems
KW - Production networks
KW - Programmable logic controllers
UR - http://www.scopus.com/inward/record.url?scp=84939266661&partnerID=8YFLogxK
U2 - 10.1016/j.ijcip.2015.04.002
DO - 10.1016/j.ijcip.2015.04.002
M3 - Article
AN - SCOPUS:84939266661
SN - 1874-5482
VL - 10
SP - 47
EP - 58
JO - International Journal of Critical Infrastructure Protection
JF - International Journal of Critical Infrastructure Protection
ER -