AMERICAN JOURNAL OF MANAGEMENT
Creating Effective Industrial-Control-System Honeypots
Author(s): Neil C. Rowe, Thuy D. Nguyen, Marian M. Kendrick, Zaki A. Rucker, Dahae Hyun, Justin C. Brown
Citation: Neil C. Rowe, Thuy D. Nguyen, Marian M. Kendrick, Zaki A. Rucker, Dahae Hyun, Justin C. Brown, (2020) "Creating Effective Industrial-Control-System Honeypots," American Journal of Management, Vol. 20, Iss. 2, pp. 112-123
Article Type: Research paper
Publisher: North American Business Press
Abstract:
Cyberattacks on industrial control systems (ICSs) can be especially damaging. Honeypots are valuable network-defense tools, but it is difficult to simulate the specialized protocols of ICSs. This research compared the performance of the Conpot and GridPot honeypot tools for simulating nodes on an electrical grid with live attacks. We evaluated their success by observing their activity patterns and by scanning them. GridPot received a higher rate of traffic than Conpot, and many visitors to both, as well as scanners, did not realize they were honeypots. This is good news for collecting useful attack intelligence with ICS honeypots.