Industrial control system honeynet cluster deployment method
Patent Information
- Application Number
- CN202211239991.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-11
- Publication Date
- 2026-08-28
- Estimated Expiration
- 2042-10-11
AI Technical Summary
[0002]工业控制系统(Industrial Control Systems,ICS)包括各种自动化控制装置,用于控制重要生产设备的平稳、高效运行,广泛应用于各生产领域,其安全性极为重要,一旦受到网络攻击导致控制系统瘫痪,会造成巨大甚至不可挽回的损失
[0019]通过本发明,能够快速、动态的部署工业控制系统蜜网集群,将工控蜜罐混入真实工控设备网络中,达到降低攻击面,精确响应,防范0day攻击的目的。
Smart Images

Figure CN115913632B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of cybersecurity for industrial control systems, and more particularly to a method for deploying a honeycomb cluster for industrial control systems. Background Technology
[0002] Industrial control systems (ICS) comprise various automated control devices used to ensure the smooth and efficient operation of critical production equipment. Widely applied across various production sectors, their security is paramount. A cyberattack leading to the paralysis of the control system can cause enormous, even irreparable, losses. Currently, deploying honeynets in industrial control systems to detect malicious attacks such as network intrusions has seen some application. Summary of the Invention
[0003] Existing industrial control honeypot vendors and open-source components and analog sensors are quite complex. Deploying products with high realism takes a long time. If multiple honeypots of the same industrial control protocol need to be deployed at the same time, multiple sandboxes need to be restarted, resulting in huge time consumption and extremely low efficiency in honeypot deployment. Furthermore, honeypots lack simulation capabilities.
[0004] Therefore, this invention provides a method for deploying honeycomb clusters in industrial control systems, which can effectively solve the above-mentioned problems.
[0005] To achieve the objectives of this invention, the following technical solution is adopted:
[0006] A method for deploying a honeycomb cluster in an industrial control system includes the following steps:
[0007] Step 1. Deploy probes in the industrial control network to automatically scan the network distribution and obtain fingerprint information of industrial control equipment;
[0008] Step 2. Generate a honeypot based on the industrial control equipment fingerprint information obtained in Step 1;
[0009] Step 3. Deploy the industrial control honeypot generated in Step 2 in the industrial control network.
[0010] The aforementioned industrial control system honeycomb cluster deployment method, wherein step 1 includes:
[0011] (1) When deploying the honeypot cluster for the first time, perform the initial scan of the probe;
[0012] (2) Continue to explore for activity.
[0013] The industrial control system honeycomb cluster deployment method, wherein the fingerprint information of the industrial control equipment in step 1 includes the protocol type used by the industrial control equipment.
[0014] In the aforementioned industrial control system honeycomb cluster deployment method, step 2 involves the industrial control honeypot using the protocol detected in step 1.
[0015] The aforementioned method for deploying honeypot clusters in industrial control systems, wherein the honeypot is used to simulate the status of industrial control equipment.
[0016] The aforementioned industrial control system honeycomb cluster deployment method, wherein: the fingerprint information of the industrial control equipment is data obtained after hash operation.
[0017] The aforementioned industrial control system honeycomb cluster deployment method, wherein: the honeypot is generated by the industrial control honeycomb cluster platform.
[0018] The aforementioned industrial control system honeycomb cluster deployment method, wherein: the industrial control honeycomb cluster platform is used to collect data packets sent by attackers during attacks and to initiate alarms.
[0019] This invention enables the rapid and dynamic deployment of industrial control system honeypot clusters, integrating industrial control honeypots into real industrial control equipment networks to reduce the attack surface, provide precise responses, and prevent zero-day attacks. Attached Figure Description
[0020] Figure 1 A schematic diagram of an industrial control network structure protected by a honeycomb network;
[0021] Figure 2 A diagram illustrating the use of a Switch to deploy a honeypot for a direct network connection;
[0022] Figure 3 This diagram illustrates the deployment of proxy nodes for non-directly connected networks. Detailed Implementation
[0023] The following is in conjunction with the appendix Figure 1-3 The specific embodiments of the present invention will be described in detail below.
[0024] The industrial control system honeycomb cluster deployment method of the present invention includes the following steps:
[0025] Step 1. Deploy the probe in the industrial control network to automatically scan the distribution of the industrial control network and obtain detailed fingerprint information of the industrial control equipment.
[0026] 1. When deploying the honeynet cluster for the first time, perform an initial scan of the probe to detect activity across the entire industrial control network segment, obtain information such as the address, working status, and fingerprint information of active industrial control devices, and save it.
[0027] 2. Continuously probe for activity, obtain fingerprint information of industrial control equipment and record the acquisition time, establish a fingerprint time correspondence table for industrial control equipment, and at the same time detect the equipment operation status and industrial control protocol identifier of industrial control equipment.
[0028] For example:
[0029]
[0030]
[0031] Preferably, this invention performs intelligent activity detection based on the network traffic of the probe. This includes obtaining the peak and valley times of the industrial control network traffic based on the previous day's network traffic. On the day of activity detection, a probe is triggered once during the previous day's peak time and once during the valley time. This obtains the two operating states of the same industrial control device during peak and valley times. During the remaining time, probes will be randomly triggered at different time periods to obtain the device's operating status, such as online / offline status and response status to various industrial control protocol requests. Through the above activity detection strategy, the device's operating status throughout the day can be obtained, allowing for a more realistic simulation of device operation using industrial control honeypots.
[0032] 3. During the continuous probe activity detection process, record the online and offline times of the industrial control equipment.
[0033] The aforementioned industrial control device fingerprint information is also known as industrial control fingerprint: This industrial control fingerprint is a unique identifier obtained by hashing the MAC address and industrial control protocol identifier feature value of the device. For a device, its industrial control fingerprint does not change. When a new industrial control fingerprint appears in the network, it means that a new industrial control device has come online.
[0034] The aforementioned industrial control protocol identifiers refer to the basic network information of the equipment: IP address, MAC address, and anonymously accessible characteristics of the industrial control equipment (such as vendor number and device type in the ENIP protocol; system_name and plant_ident in the S7 protocol).
[0035] Equipment operating status, also known as equipment status, mainly refers to the current operating status of industrial control equipment. For example, "the current on / off status of an IPI device controlling a certain device" is the operating status of that IPI device.
[0036] The method for determining the protocol type used by industrial control equipment is as follows: send different industrial control protocol connection requests or request packets to the target industrial control equipment in sequence. If a response consistent with the protocol of a certain request is obtained, it can be determined that the target industrial control equipment uses that protocol, thereby determining the industrial control protocol identifier of the industrial control equipment.
[0037] Step 2. Generate a honeypot based on the industrial control protocol identifier and device operating status obtained in Step 1. Honeypot generation involves reading the device's industrial control protocol identifier and operating status to create the corresponding industrial control honeypot. After generation, the industrial control device fingerprint information is used to determine the device's operating status to be switched. For example, the ENIP device fingerprint [GT341F] currently uses the supplier number [a], the device type is [sluice gate controller], the system name is [system], and the ENIP device's current operating status is [sluice gate open], [voltage 47V], and [water flow speed 3m / s]. Filling this information into the industrial control honeypot configuration information creates the corresponding protocol identifier and operating status. Industrial control fingerprints correspond to different industrial control identifiers and operating statuses. When the probe detects a device with the same fingerprint [GT341F] whose other statuses are identical, but whose operating status has been changed to [sluice gate closed], the operating status of the industrial control honeypot device can be changed accordingly to [sluice gate closed].
[0038] If fewer than two industrial control fingerprints are obtained in step 1, honeypots using other industrial control protocols different from those in the obtained fingerprints will be automatically generated. For example, the IEC104 protocol may be used in conjunction with the SNMP protocol. If a single IEC104 protocol is detected in the industrial control honeypot, an SNMP honeypot will be deployed in conjunction. In other words, to better protect industrial control equipment, when the number of industrial control fingerprints is small, honeypots using network protocols that do not exist in the industrial control network will be deployed. To better reflect real-world scenarios, these non-existent network protocols should be closely related to the network protocols that actually exist in the industrial control network, such as other network protocol devices that frequently appear alongside real network protocol devices in general situations.
[0039] The protocol used by the industrial control protocol honeypot is the protocol represented by the industrial control protocol identifier detected in step 1. If multiple different protocols are found, honeypots are created proportionally. On idle addresses in the industrial control network, honeypots can be generated directly using Vswitch technology for directly connectable network segments; for non-directly connectable network segments, honeypots can be generated using port forwarding, traffic forwarding, and other operations.
[0040] In this invention, an industrial control honeycomb cluster platform (hereinafter referred to as the honeycomb platform) can generate honeypots and control their states. The honeypots are used to simulate device states acquired at different time periods based on the industrial control protocol identifiers and industrial control fingerprints obtained by probes. By default, a device state is switched every hour. The switching state information is obtained by the probes. In principle, the more times the probes probe, the more device states can be obtained, and therefore, the more states can be switched. After a probe detects a device state, if it no longer detects that state within a predetermined time period (e.g., three weeks), the industrial control device state is deleted, and the honeypot no longer simulates that state until it is detected again.
[0041] There are two ways to deploy honeypots: Method 1: In networks directly accessible by the honeynet platform, vSwitch technology can be used to distribute the industrial control network honeypots generated by the honeynet platform to the industrial control network, such as... Figure 2 As shown. Honeypot Deployment Method Two: In network environments where the honeynet platform is unreachable, a proxy node is used to reverse-connect to the honeynet platform. Any device in the industrial control network is treated as a proxy node and reverse-connected to the honeynet platform. The proxy node's built-in vSwitch technology is used to distribute the industrial control network honeypot, such as... Figure 3 As shown.
[0042] Step 3. Deploy the industrial control honeypot created by the honeynet platform in Step 2 in the industrial control network.
[0043] To integrate industrial control honeypots into real device clusters, the following steps can be taken: Distribute honeypots throughout the industrial control network based on the proportion of industrial control device types and the online / offline time periods of the devices obtained by the probe in step 1.
[0044] The ratio of devices to honeypots matches the ratio detected by probes. For example, if an industrial control network has 4 IPMI devices and 8 IEC104 devices, then honeypots of different protocol types are deployed in the same ratio as the number of different types of devices in the industrial control network (e.g., a 1:2 ratio in this example). This results in 16 IPMI honeypots and 32 IEC104 honeypots deployed in this example. Furthermore, the number of honeypots is significantly greater than the number of devices. For instance, in this example, the industrial control network has a total of 4+16 IPM devices and 8+16 IEC104 devices, making the number of honeypots a multiple of the number of devices (4 times in this example). This ensures effective protection of industrial control equipment. Simultaneously, if any increase or decrease in the number of detected devices is detected, the ratio of honeypots is adjusted accordingly.
[0045] Furthermore, the honeynet platform will control half of the honeypots corresponding to a given type of device to go online and offline synchronously, based on the device's historical online / offline history and the probes detecting regularly going online and offline. This setting prevents the loss of a large number of honeypots due to the simultaneous offline of too many honeypots when the protocol within the industrial control network is singular. For example, in an industrial control network with only one industrial control device, there might be 2-4 industrial control honeypots after automatic deployment. However, if the industrial control device goes offline, all industrial control honeypots in the network will also go offline. But to maintain honeynet deployment and monitoring, at least one industrial control honeypot will remain online.
[0046] After completing the above three steps, the industrial control honeycomb cluster has been deployed.
[0047] Attacker attack cases:
[0048] 1. The attacker gains access to the industrial control network and begins probing.
[0049] 2. The honeypot device and the real device are detected (at this time, the honeynet platform will issue an alarm).
[0050] 3. The attacker determines the protocol type of the detected industrial control equipment and launches an attack using the corresponding vulnerability (at this time, the honeynet platform collects the data packets sent by the attacker during the attack and issues an alarm).
[0051] 4. Attackers obtain information or permissions about honeypot devices and real devices, but because the number of honeypot devices deployed is greater than the number of real devices, it disrupts the attacker's judgment (the honeynet platform will issue alerts after steps 2, 3, and 4, giving the administrator enough time to respond).
[0052] This invention enables the rapid deployment and construction of a deception defense system for industrial control networks, achieving dynamic deployment of industrial control honeypot devices and integrating them into real industrial control equipment networks. This reduces the attack surface, provides precise response, and prevents zero-day attacks.
Claims
1. A method for deploying a honeycomb cluster in an industrial control system, characterized in that... Includes the following steps: Step 1. Deploy probes in the industrial control network to automatically scan the network distribution and obtain fingerprint information of industrial control equipment. Step 1 includes: (1) When deploying the honeypot cluster for the first time, perform the initial scan of the probe; (2) Continuously perform liveness detection. During the continuous liveness detection process, record the online and offline times of the industrial control equipment. The continuous liveness detection includes obtaining the peak and valley times of the industrial control network based on the network traffic of the previous day. On the day of liveness detection, trigger a probe once at the peak time of the previous day and trigger a probe once at the valley time to obtain the two working states of the same industrial control equipment at the peak and valley times. During the remaining time, probes will be randomly triggered in different time periods to obtain the operating status of the equipment, i.e., the online and offline status of the equipment and the response status to various industrial control protocol requests. The fingerprint information of the industrial control equipment is a unique identifier obtained by hashing the MAC address and industrial control protocol identifier feature value of the equipment. Step 2. Generate an industrial control honeypot based on the industrial control device fingerprint information obtained in Step 1. There are two ways to deploy the honeypot: Honeypot deployment method 1: In a network that the honeynet platform can directly reach, use vSwitch technology to distribute the industrial control honeypot generated by the honeynet platform to the industrial control network; Honeypot deployment method 2: In a network environment that the honeynet platform cannot reach, use a proxy node to reverse connect to the honeynet platform, treat any device in the industrial control network as a proxy node, reverse connect to the honeynet platform, and use the vSwitch technology built into the proxy node to distribute the industrial control honeypot to the industrial control network. Among them: the industrial control honeycomb cluster platform generates honeypots and controls the honeypot status. The honeypot is used to simulate the device status obtained in different time periods based on the fingerprint information of the industrial control equipment obtained by the probe. By default, a device status is switched within one hour. The status information of the switch is obtained by the probe. After the probe detects a device status, if the probe does not detect this status again within a predetermined time period, the industrial control device status will be deleted and the honeypot will no longer simulate the status until the status is detected again. Step 3. Deploy the industrial control honeypot generated in Step 2 in the industrial control network; If the number of industrial control device fingerprints obtained in step 1 is less than two, other industrial control protocol honeypots that are different from the industrial control protocols in the obtained industrial control device fingerprints are automatically generated. Honeypots of network protocols that do not exist in the industrial control network are deployed in the industrial control network. These non-existent network protocols are closely related to the network protocols that actually exist in the industrial control network.
2. The industrial control system honeycomb cluster deployment method according to claim 1, characterized in that: The industrial control honeycomb cluster platform is used to collect data packets sent by attackers during attacks and to issue alarms.
Citation Information
Patent Citations
Novel dynamic honeypot system
CN111541670A
Intrusion detection method and system based on container-level honeypot group
CN112367307A
APT detection early warning method
CN112948821A
Edge data drainage trapping technical method for independent network attack of power system
CN115150175A