DiPot: A Distributed Industrial Honeypot System.

Jianhong Cao,Wei Li,Jianjun Li,Bo Li
DOI: https://doi.org/10.1007/978-3-319-73830-7_30
2018-01-01
Abstract:Recent years witness the prosperous of Internet and Cyber Physical Systems (CPS). More and more industrial devices and systems are connected to the Internet and thus become the target for attackers. This paper proposed a distributed industrial honeypot system called DiPot to monitor Internet scanning and attacking behaviors against industrial control systems. DiPot offers attack clustering and visualization services to users and could help users to be aware of current ICS security situation. Different from existing Honeypot systems, DiPot has two advantages: high-degree simulation and deep data analysis. DiPot is also equipped with an advanced visualization frontend and could provide users with good experience. Through 6 months running, DiPot has obtained plenty of data and captured some real-world attack samples from Internet. The experimental results demonstrate the effectiveness and efficiency of DiPot.
What problem does this paper attempt to address?