题名: |
Dynamic Honeypot Configuration for Programmable Logic Controller Emulation. |
作者: |
Girtz, K. A. |
关键词: |
Theses, Simulation, Automation, Computer security, Control systems, Intrusion detectors, Honeypot, Programmable logic controller, Industrial control systems, Honeypots |
摘要: |
This research develops an enhanced, application layer emulator capable of alleviating honey net scalability and honeypot inauthenticity limitations. The proposed emulator combines protocol-agnostic replay with dynamic updating via a proxy. The result is a software tool which can be readily integrated into existing honeypot frameworks for improved performance. The proposed emulator is evaluated on traffic reduction on the back-end proxy device, application layer task accuracy, and byte-level traffic accuracy. Experiments show the emulator is able to successfully reduce the load on the proxy device by up to 98 for some protocols. The emulator also provides equal or greater accuracy over a design which does not use a proxy. At the byte level, traffic variation is statistically equivalent while task success rates increase by 14 to 90 depending on the protocol. Finally, of the proposed proxy synchronization algorithms, temp lock and its minimal variant are found to provide the best overall performance. |
报告类型: |
科技报告 |