An industrial control honeypot trapping method and system
By adopting a cloud-edge dual-layer distributed architecture and iteratively trained industrial control honeypot system, the problems of rigid interaction logic and high maintenance costs of industrial control honeypots are solved. It achieves efficient and dynamic trapping response and adaptive defense, improving the trapping success rate and system defense capabilities.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHINA DATANG CORPORATION SCIENCE AND TECHNOLOGY GENERAL RESEARCH INSTITUTE
- Filing Date
- 2026-04-16
- Publication Date
- 2026-05-29
AI Technical Summary
Existing industrial control honeypot technology suffers from rigid interaction logic that is easily identified, high maintenance costs, inability to achieve dynamic self-adaptation, and difficulty in cross-domain intelligence sharing, resulting in a low success rate of trapping.
It adopts a cloud-edge dual-layer distributed architecture, utilizes iterative training of global and local models, acquires attack data through honeypot nodes, generates trap response data using a pre-set trap database and local models, and updates the model by combining low-rank adaptive training and federated averaging algorithms to achieve dynamic adaptation and high-fidelity deception.
It achieves accurate identification and non-disruptive collection of attack traffic, generates highly realistic deception data, improves the success rate of trapping, extends the interaction depth, fully acquires attack methods, provides samples for model evolution, reduces computing power consumption, and enhances the active defense capability of industrial control systems.
Smart Images

Figure CN122120014A_ABST