首页> 外文会议>International Conference on Information and Communications Security >S7commTrace: A High Interactive Honeypot for Industrial Control System Based on S7 Protocol
【24h】

S7commTrace: A High Interactive Honeypot for Industrial Control System Based on S7 Protocol

机译:S7Commvrace:基于S7协议的工业控制系统高互动蜜罐

获取原文

摘要

Intensively happened cyber-attacks against industrial control system pose a serious threat to the critical national infrastructure. It is significant to capture the detection and the attacking data for industrial control system by means of honeypot technology, as it provides the ability of situation awareness to reveal potential attackers and their motivations before a fatal attack happens. We develop a high interactive honeypot for industrial control system-S7commTrace, based on Siemens' S7 protocol. S7commTrace supports more function codes and sub-function codes in protocol simulation, and improves the depth of interaction with the attacker to induce more high-level attacks effectively. A series of comparative experiments is carried out between S7commTrace and Conpot, by deploying these two kinds of honeypots under the same circumstance in four countries. Data captured by these two kinds of honeypots is analyzed respectively in four dimensions, which are query results in Shodan, count of data and valid data, coverage of function code and diversity of source IP address. Experiment results show that S7commTrace has better performance over Conpot.
机译:对工业控制系统的网络攻击集中攻击对关键国家基础设施构成严重威胁。通过蜜罐技术捕获工业控制系统的检测和攻击数据很重要,因为它提供了揭示潜在攻击者的情况,以揭示潜在的攻击者以及他们在致命攻击发生之前的动机。基于西门子的S7协议,我们为工业控制系统-S7Comprace开发了一个高互动蜜罐。 S7Commvrace支持协议仿真中的更多功能代码和子功能代码,并提高与攻击者的互动深度有效地引起更高级别的攻击。通过在四个国家的同样情况下部署这两种蜜罐,在S7Comprace和CoNpot之间进行了一系列比较实验。通过这两种蜜罐捕获的数据分别在四个维度中分析,这些维度是Shodan的查询结果,数据数量和有效数据的计数,功能代码的覆盖范围和源IP地址的分集。实验结果表明,S7Commvrace在巧妙上具有更好的性能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号