Font Size: a A A

Design And Threat Analysis Of ICS Honeypot Based On UMAS Protocol

Posted on:2024-05-12Degree:MasterType:Thesis
Country:ChinaCandidate:Z LinFull Text:PDF
GTID:2558307040487004Subject:Electronic Information Control Engineering (Professional Degree)
Abstract/Summary:
Industrial Control System is widely used in important industries such as power,transportation,and healthcare,where common tools such as Modbus protocol and its affiliated UMAS protocol have high-risk functions,such as forcing the start and stop of equipment or modifying physical address.If attackers use the high-risk functions of UMAS protocol to modify industrial control equipment and cause safety issues,it will cause incalculable loss and harm to society and industry.To improve the safety of Industrial Control System,researchers have introduced honeypot technology into the safety protection of Industrial Control System.Honeypot lures attackers into attacks by simulating the vulnerabilities of the system,thereby successfully capturing the data of attackers,analyzing and studying their attack patterns and intentions,tracing their sources,and even launching counterattacks.The current traditional honeypot of industrial control does not deeply expand the simulation of industrial control protocol represented by UMAS protocol,and supports too few function codes to respond to the corresponding messages,which significantly affects its trapping ability.In accordance with UMAS protocol,this thesis designs a simulation honeypot framework and implementation method based on industrial control equipment simulation.The main work is as follows:1.Conduct a detailed study of industrial control honeypot technology and Modbus protocol,analyze the shortcomings of current technology,and proposes a method to imitate response in terms of UMAS private protocol,classify correct response and rejected response,so that the industrial honeypot can respond correctly in terms of UMAS protocol messages.The AUC value of this method is 0.853,it proves that the method works.The honeypot is constructed through engineering design,and the performance is improved by 212.5% in function code extension,which greatly improves the practicality and authenticity.Besides,the deception ability of honeypot has been verified in network detection and interactive confrontation.2.Offline and online experiments were conducted simultaneously.The offline experiment results shows that the honeypot is highly consistent with the real equipment,demonstrating the authenticity of the honeypot and enhancing the validity of the data collected from online experiment.The interactive results of online experiment verify the effectiveness of the offline experiment.The search and detection engine which is highly threatening to industrial control equipment,such as Shodan,identified the honeypot as an industrial control device rather than a honeypot.3.The thesis builds a threat analysis system to display the collected data,intuitively showing the attack characteristics of the attacker,complete the function of statistics,analysis and traceability,which can be used as a source of threat intelligence for Industrial Control Safety.The proportion of UMAS protocol data collected in Modbus protocol data exceeds 20%.Criminal IP,a well-known port information collection organization,has the highest number of UMAS protocol detections,indicating that there are many UMAS protocol detections on the network,which verifies the necessity of this thesis.
Keywords/Search Tags:honeypot technology, Industrial Control Safety, Modbus, UMAS, threat analysis
Related items