AM
A. Malnati
info
Please Note
<p>This page displays the records of the person named above and is not linked to a unique person identifier. This record may need to be merged to a profile.</p>
1 records found
1
Industrial Control Systems (ICS) operate physical processes in environments such as energy, water, manufacturing, and transportation. Many ICS devices communicate through protocols that were designed for trusted operational networks rather than hostile public ones, and often lack authentication, encryption, or other modern security mechanisms. Exposing such services on the public Internet can therefore reveal operational information or create attack surface for systems with physical impact. ICS honeypots help researchers and defenders collect data about scans and attacks against these services by emulating industrial devices. Their value, however, depends on realism: if an attacker or automated tool can recognize the decoy, the interaction may stop and the collected data becomes less useful.
This thesis studies how open-source ICS honeypots can be fingerprinted through source-backed active probes. It combines local reproduction, protocol and source analysis, and a scanner that applies accepted signatures to Censys-derived Internet exposure data. A fingerprint is accepted only when it is remotely observable, tied to a concrete honeypot or implementation lineage, and supported by a false-positive argument. Applied to a worldwide Censys snapshot of about 143,000 hosts across 28 ICS protocols, the scanner labels about a quarter of the active hosts as honeypot-like, 7,090 of them confirmed by a protocol signature, and it confirms honeypots that neither Censys’s own tags nor previously published signatures detect. The resulting methodology and signature catalogue aim to make honeypot weaknesses measurable, support more accurate Internet measurements, and help operators improve honeypot stealth and effectiveness.
...
This thesis studies how open-source ICS honeypots can be fingerprinted through source-backed active probes. It combines local reproduction, protocol and source analysis, and a scanner that applies accepted signatures to Censys-derived Internet exposure data. A fingerprint is accepted only when it is remotely observable, tied to a concrete honeypot or implementation lineage, and supported by a false-positive argument. Applied to a worldwide Censys snapshot of about 143,000 hosts across 28 ICS protocols, the scanner labels about a quarter of the active hosts as honeypot-like, 7,090 of them confirmed by a protocol signature, and it confirms honeypots that neither Censys’s own tags nor previously published signatures detect. The resulting methodology and signature catalogue aim to make honeypot weaknesses measurable, support more accurate Internet measurements, and help operators improve honeypot stealth and effectiveness.
...
Industrial Control Systems (ICS) operate physical processes in environments such as energy, water, manufacturing, and transportation. Many ICS devices communicate through protocols that were designed for trusted operational networks rather than hostile public ones, and often lack authentication, encryption, or other modern security mechanisms. Exposing such services on the public Internet can therefore reveal operational information or create attack surface for systems with physical impact. ICS honeypots help researchers and defenders collect data about scans and attacks against these services by emulating industrial devices. Their value, however, depends on realism: if an attacker or automated tool can recognize the decoy, the interaction may stop and the collected data becomes less useful.
This thesis studies how open-source ICS honeypots can be fingerprinted through source-backed active probes. It combines local reproduction, protocol and source analysis, and a scanner that applies accepted signatures to Censys-derived Internet exposure data. A fingerprint is accepted only when it is remotely observable, tied to a concrete honeypot or implementation lineage, and supported by a false-positive argument. Applied to a worldwide Censys snapshot of about 143,000 hosts across 28 ICS protocols, the scanner labels about a quarter of the active hosts as honeypot-like, 7,090 of them confirmed by a protocol signature, and it confirms honeypots that neither Censys’s own tags nor previously published signatures detect. The resulting methodology and signature catalogue aim to make honeypot weaknesses measurable, support more accurate Internet measurements, and help operators improve honeypot stealth and effectiveness.
This thesis studies how open-source ICS honeypots can be fingerprinted through source-backed active probes. It combines local reproduction, protocol and source analysis, and a scanner that applies accepted signatures to Censys-derived Internet exposure data. A fingerprint is accepted only when it is remotely observable, tied to a concrete honeypot or implementation lineage, and supported by a false-positive argument. Applied to a worldwide Censys snapshot of about 143,000 hosts across 28 ICS protocols, the scanner labels about a quarter of the active hosts as honeypot-like, 7,090 of them confirmed by a protocol signature, and it confirms honeypots that neither Censys’s own tags nor previously published signatures detect. The resulting methodology and signature catalogue aim to make honeypot weaknesses measurable, support more accurate Internet measurements, and help operators improve honeypot stealth and effectiveness.