Industrial control network attack packet response method and response system based on honeypot system
By constructing and updating the request-response table of the honeypot system and generating deceptive response messages, the problem of insufficient interactive response capability of the honeypot system in the power industrial control system is solved, and effective capture and defense against attackers are achieved.
Patent Information
- Application Number
- CN202211495781.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-28
- Publication Date
- 2026-02-13
- Estimated Expiration
- 2042-11-28
AI Technical Summary
Existing honeypot technology in industrial control systems has limited interactive response capabilities in the power industry, making it difficult to effectively mimic the complexity and diversity of power production scenarios. This results in honeypots being easily identified by attackers, making it impossible to capture their malicious behavior.
By constructing an industrial control network attack message response method based on a honeypot system, this method receives and filters valid industrial control protocol messages, extracts function codes and request data fields, calculates similarity using the Smith-Waterman algorithm, generates deceptive response messages, records interaction behavior logs, and constructs and updates request-response tables to improve interactive response capabilities.
Without altering the existing power industrial control system network architecture, it generates reasonable deceptive responses to attract deep interaction from attackers, increasing the interaction response range of the honeypot system, reducing the risk of being identified, and achieving information capture of attackers.