Published May 1, 2014 | Version v1
Journal article

Cyber-Physical System Security With Deceptive Virtual Hosts for Industrial Control Networks

  • 1. Idaho National Lab. (INL), Idaho Falls, ID (United States)

Description

A challenge facing industrial control network administrators is protecting the typically large number of connected assets for which they are responsible. These cyber devices may be tightly coupled with the physical processes they control and human induced failures risk dire real-world consequences. Dynamic virtual honeypots are effective tools for observing and attracting network intruder activity. This paper presents a design and implementation for self-configuring honeypots that passively examine control system network traffic and actively adapt to the observed environment. In contrast to prior work in the field, six tools were analyzed for suitability of network entity information gathering. Ettercap, an established network security tool not commonly used in this capacity, outperformed the other tools and was chosen for implementation. Utilizing Ettercap XML output, a novel four-step algorithm was developed for autonomous creation and update of a Honeyd configuration. This algorithm was tested on an existing small campus grid and sensor network by execution of a collaborative usage scenario. Automatically created virtual hosts were deployed in concert with an anomaly behavior (AB) system in an attack scenario. Virtual hosts were automatically configured with unique emulated network stack behaviors for 92% of the targeted devices. The AB system alerted on 100% of the monitored emulated devices

Availability note (English)

Available from: DOI:10.1109/TII.2014.2304633 ; DOE Accepted Manuscript full text, or the publishers Best Available Version will be available free of charge after the embargo period from OSTI using http://www.osti.gov/pages/biblio/1136315

Additional details

Publishing Information

Journal Title
IEEE Transactions on Industrial Informatics
Journal Volume
10
Journal Issue
2
Journal Page Range
p. 1337-1347
ISSN
1551-3203

INIS

Country of Publication
United States
Country of Input or Organization
United States
INIS RN
47051913
Subject category
S97: MATHEMATICAL METHODS AND COMPUTING;
Descriptors DEI
ALGORITHMS; CONTROL SYSTEMS; HAZARDS; SECURITY
Descriptors DEC
MATHEMATICAL LOGIC

Optional Information

Contract/Grant/Project number
AC07-05ID14517
Funding organization
USDOE (United States)
Secondary number(s)
INL/JOU--14-32392; OSTIID--1136315