Industrial control network attack packet response method and response system based on honeypot system

By constructing and updating the request-response table of the honeypot system and generating deceptive response messages, the problem of insufficient interactive response capability of the honeypot system in the power industrial control system is solved, and effective capture and defense against attackers are achieved.

CN115883169BActive Publication Date: 2026-02-13STATE GRID LIAONING SHENYANG ELECTRIC POWER SUPPLY COMPANY
3 Cites 0 Cited by

Patent Information

Application Number
CN202211495781.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-28
Publication Date
2026-02-13
Estimated Expiration
2042-11-28

AI Technical Summary

Technical Problem

Existing honeypot technology in industrial control systems has limited interactive response capabilities in the power industry, making it difficult to effectively mimic the complexity and diversity of power production scenarios. This results in honeypots being easily identified by attackers, making it impossible to capture their malicious behavior.

Method used

By constructing an industrial control network attack message response method based on a honeypot system, this method receives and filters valid industrial control protocol messages, extracts function codes and request data fields, calculates similarity using the Smith-Waterman algorithm, generates deceptive response messages, records interaction behavior logs, and constructs and updates request-response tables to improve interactive response capabilities.

Benefits of technology

Without altering the existing power industrial control system network architecture, it generates reasonable deceptive responses to attract deep interaction from attackers, increasing the interaction response range of the honeypot system, reducing the risk of being identified, and achieving information capture of attackers.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

The application discloses a kind of based on honeypot system's industrial control network attack message response method and response system, wherein, the method includes the following steps: receiving attack message and screening out the valid industrial control protocol message in the attack message;From the valid industrial control protocol message, corresponding industrial control application data unit function code field and industrial control application data unit request data domain field are extracted, and the corresponding field of the data in the request response table in the honeypot system is matched, and according to different matching results, the response message corresponding to the result is replied.The based on honeypot system's industrial control network attack message response method and response system, by collecting and processing specific power industrial control network flow data, request response table can be generated, using the request response table, reasonable response with high fraud can be returned to the sniffer behavior of attacker.
Need to check novelty before this filing date? Find Prior Art