Honeyeye: A Network Traffic Collection Framework for Distributed ICS Honeynets

Chuan Sheng,Yu Yao,Dongbiao Li,Hongna An,Wei Yang
DOI: https://doi.org/10.1109/ispa-bdcloud-socialcom-sustaincom51426.2020.00084
2020-01-01
Abstract:The honeynet, as an important security resource, is increasingly used in the industrial field in order to detect, analyze, and prevent network attacks against industrial control systems (ICSs). However, conventional network traffic collection methods used in honeynets cannot meet the more and more complex requirements of large-scale and distributed honeynets. This paper presents a new network traffic collection framework for distributed ICS honeynets called Honeyeye. Honeyeye can provide some different running modes for different application scenarios and purposes. Honeyeye can not only collect and save network traffic, but also parse it into readable data and convert it into the required format. By this way, Honeyeye tends to provide network administrators and intrusion detection systems (IDSs) with more understandable and directly available data rather than captured opaque binary data. Experimental results show that the framework is effective in parsing, converting, and transmitting ICS honeynet traffic.
What problem does this paper attempt to address?