HoneyPLC: A Next-Generation Honeypot for Industrial Control Systems
Efrén López-Morales, Carlos E. Rubio-Medrano, Adam Doupé, Yan Shoshitaishvili, Ruoyu Wang, Tiffany Bao, Gail-Joon Ahn
Abstract
Industrial Control Systems (ICS) provide management and control capabilities for mission-critical utilities such as the nuclear, power, water, and transportation grids. Within ICS, Programmable Logic Controllers (PLCs) play a key role as they serve as a convenient bridge between the cyber and the physical worlds, e.g., controlling centrifuge machines in nuclear power plants. The critical roles that ICS and PLCs play have made them the target of sophisticated cyberattacks that are designed to disrupt their operation, which creates both social unrest and financial losses. In this context, honeypots have been shown to be highly valuable tools for collecting real data, e.g., malware payload, to better understand the many different methods and strategies that attackers use. However, existing state-of-the-art honeypots for PLCs lack sophisticated service simulations that are required to obtain valuable data. Worse, they cannot adapt while ICS malware keeps evolving, and attack patterns become more sophisticated. To overcome these shortcomings, we present HoneyPLC, a high-interaction, extensible, and malware collecting honeypot supporting a broad spectrum of PLCs models and vendors. Results from our experiments show that HoneyPLC exhibits a high level of camouflaging: it is identified as real devices by multiple widely used reconnaissance tools, including Nmap, Shodan's Honeyscore, the Siemens Step7 Manager, PLCinject, and PLCScan, with a high level of confidence. We deployed HoneyPLC on Amazon AWS and recorded a large amount of interesting interactions over the Internet, showing not only that attackers are in fact targeting ICS systems, but also that HoneyPLC can effectively engage and deceive them while collecting data samples for future analysis.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f08b5f64-b8a1-432f-a558-21efaeee34abCited by top-tier papers3
- Identifying VPN Servers through Graph-Represented BehaviorsChenxu Wang, Jiangyi Yin, Zhao Li, Hongbo Xu et al.WWW 2024 · 6 citations
- HoneySat: A Network-based Satellite Honeypot FrameworkEfrén López-Morales, Ulysse Planta, Gabriele Marra, Carlos Gonzalez-Cortes et al.NDSS 2026 · 4 citations
- Cyber-Physical Deception Through Coordinated IoT HoneypotsChongqi Guan, Guohong CaoUSENIX Security 2025
Builds on1
Related papers
- Empirical Study of System Resources Abused by IoT AttackersZijing Yin, Yiwen Xu, Chijin Zhou, Yu JiangASE 2022 · 3 citations
- Hey, My Malware Knows Physics! Attacking PLCs with Physical Model Aware RootkitLuis Garcia, Ferdinand Brasser, Mehmet Hazar Cintuglu, Ahmad-Reza Sadeghi et al.NDSS 2017 · 205 citations
- Compromising Industrial Processes using Web-Based Programmable Logic Controller MalwareRyan Pickren, Tohid Shekari, Saman A. Zonouz, Raheem BeyahNDSS 2024
- CoToRu: Automatic Generation of Network Intrusion Detection Rules from CodeHeng Chuan Tan, Carmen Cheh, Binbin ChenINFOCOM 2022 · 12 citations
- The Art of The Scam: Demystifying Honeypots in Ethereum Smart ContractsChristof Ferreira Torres, Mathis Steichen, Radu StateUSENIX Security 2019 · 239 citations
