A method for identifying industrial control honeypots based on multidimensional feature distribution

By combining a multi-dimensional feature distribution method with a Bayesian classifier and multiple features to identify industrial control honeypots, the problems of the existing technology of few identification protocols, low number and low accuracy are solved, and efficient identification of industrial control honeypots is achieved.

CN119051889BActive Publication Date: 2025-09-30NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410996232.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-24
Publication Date
2025-09-30
Estimated Expiration
2044-07-24

AI Technical Summary

Technical Problem

The existing industrial control honeypot identification technology has few identification protocols, low number and low accuracy, making it difficult to effectively identify industrial control honeypots.

Method used

A method based on multidimensional feature distribution is adopted, combined with a Bayesian classifier and multiple features to identify industrial control honeypots, including protocol features, operating system features, business features and feature parameters. By constructing specific data packets to interact with the target device, its response and interaction features are analyzed to improve the recognition accuracy.

Benefits of technology

The recognition quantity and recognition accuracy of industrial control honeypots have been significantly improved, and industrial control honeypots on the Internet can be discovered more effectively.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119051889B_ABST
    Figure CN119051889B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for identifying industrial control honeypots based on multi-dimensional feature distribution, which includes: performing industrial control honeypot detection on the industrial control network asset detection results based on a Bayesian classifier, and finding the industrial control IP addresses that may be honeypots in the industrial control network asset detection results; for each new target host, a priori probability of judging that the target host is an industrial control honeypot under feature X is given, and if the priori probability is greater than or equal to a pre-set threshold, subsequent online honeypot identification and offline honeypot identification are performed on the target host. Among them, feature X is a vector composed of static features extracted from the industrial control network asset detection results; if the priori probability is less than a pre-set threshold, it is determined to be a real industrial control device rather than a honeypot; finally, the results of online honeypot identification and offline honeypot identification are aggregated and output according to IP. The present invention has a wide range of identification protocols, a large number of identifications, and high identification accuracy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to an industrial control honeypot identification method based on multi-dimensional feature distribution. Background Art

[0002] With the increasing number and diversification of network attacks, and the emergence of more and more industrial control system equipment on the Internet, the security issues of industrial control network equipment have become increasingly prominent. Discovering industrial control equipment in cyberspace and efficiently and intelligently identifying industrial control honeypots are important means of real-time security monitoring of industrial control networks.

[0003] Problems with existing industrial control honeypot identification technology:

[0004] (1) Existing identification technologies target a small number of protocols and have a low number of identifications: In cases where honeypots implement incomplete industrial control protocols, this method constructs specific data packets to conduct in-depth interactive communication with industrial control honeypots, and identifies honeypots by distinguishing the differences in responses between honeypots and real devices. This method generally supports a small number of industrial control protocols and has a low number of identifications.

[0005] (2) Low recognition accuracy: Existing technologies mainly use node deployment characteristics for identification. For example, industrial control equipment is usually located in a real industrial operating environment, rather than being deployed on a cloud server like a honeypot. By querying the whois information of the IP address of the industrial control network asset detection, it is possible to determine whether the target is a honeypot. Common honeypot characteristics include: port openness, deployment characteristics, etc., but their accuracy is relatively low. Summary of the Invention

[0006] To address the existing problems of limited identification and low accuracy in industrial control honeypot identification, this paper proposes an industrial control honeypot identification method based on multidimensional feature distribution. This method identifies industrial control honeypots using multidimensional features, namely, combining protocol features, operating system features, business features, and feature parameters. This not only improves the identification data of honeypots, but also enhances the recognition accuracy.

[0007] The present invention discloses an industrial control honeypot identification method based on multi-dimensional feature distribution, which includes:

[0008] Based on a Bayesian classifier, industrial control honeypot detection is performed on the industrial control network asset detection results to identify industrial control IP addresses that may be honeypots. For each new target host, a prior probability is given that the target host is an industrial control honeypot under feature X. If the prior probability is greater than or equal to a preset threshold, the target host is subsequently identified as an industrial control honeypot online and offline. Feature X is a vector composed of static features extracted from the industrial control network asset detection results. Static features include the number of open ports, IP address, and AS domain. The industrial control network asset detection results include IP address, port, protocol, and AS domain. If the prior probability is less than the preset threshold, the target host is considered to be a real industrial control device and no further processing is performed. Finally, the results of online and offline honeypot identification are aggregated and output according to IP address.

[0009] Furthermore, online honeypot identification includes conpot industrial control honeypot identification based on business features, conpot industrial control honeypot identification based on protocol features, and conpot industrial control honeypot identification based on operating system features; offline honeypot identification is conpot industrial control honeypot identification based on feature parameters; business features include coil status, register status, file records, temperature, and valve status; protocol features include features of protocol response content and protocol interaction process; operating system features mainly refer to the fact that the operating system run by real industrial control equipment is different from the operating system of the honeypot; feature parameters include response parameter content features of the S7 and Ethernet / IP protocols.

[0010] Furthermore, the industrial control honeypot detection based on the control network asset detection results based on the Bayesian classifier includes:

[0011] Dataset construction and feature selection for the Bayesian classifier: Business features and operating system features are considered strong features. If strong features appear, the device is identified as a honeypot. Strong features are used to identify Internet conpot industrial control honeypots, and the identified results are labeled "honeypot". Secondly, four multidimensional features are used to identify conpot industrial control honeypots. Target industrial control hosts that do not meet any of the four multidimensional features are identified as real industrial control devices and labeled "non-honeypot". The four multidimensional features are protocol features, operating system features, feature parameters, and business features.

[0012] The feature selection of the Bayesian classifier includes the number of open ports, DNS, ISP, whois, location and AS information features;

[0013] Industrial control honeypot classification based on Bayesian classifier: For each feature X, the corresponding asset information of the feature is obtained from the industrial control network asset detection results of the honeypot identification process, without sending a separate detection data packet;

[0014] For each new target host, a prior probability P(y|X) that the feature X is an industrial control honeypot is given. If P(y|X) is greater than a preset threshold, the host is added to the list for subsequent honeypot identification, and subsequent conpot industrial control honeypot identification is performed.

[0015] Furthermore, the process of identifying conpot industrial control honeypots based on business characteristics includes:

[0016] By constructing Modbus protocol messages to communicate with PLCs, device manufacturer information and product module information can be obtained. By actually checking the Modbus protocol configuration file of the conpot industrial control honeypot, the conpot industrial control honeypot Modbus protocol does not respond to slave_id = 0 and will disconnect. slave_id represents a distributed node number, which is used to identify the industrial control device from which the response message comes. The slave_id needs to be set to 1 or 2, and a response will be received after the data packet is sent. However, in a real industrial environment, a PLC with the Modbus protocol turned on cannot have multiple slave_ids, because the slave_id is used for communication between the master and the slave. The slave_id address range of the slave is between 1 and 247. Each 1 sent by the master includes a slave_id. Different slaves will have different slave_ids, and only the slave_id that meets the requirements will respond to the request. Therefore, if any PLC has multiple slave_ids turned on, it is likely to be a honeypot.

[0017] Furthermore, the process of identifying the conpot industrial control honeypot based on protocol features includes:

[0018] Identify the problems in the implementation of the conpot protocol and use them as features to identify honeypots. Analyze the protocol response features and protocol interaction features to further explore the characteristics of industrial control honeypots and discover more industrial control honeypots on the Internet.

[0019] Furthermore, for the protocol response characteristics, the conpot honeypot is mainly identified through the IEC104 protocol. During the industrial control network asset detection process, a test frame and a startup frame are sent in sequence, and then a summon command message is sent to communicate with the target to obtain response information. In the actual communication process, three IEC104 protocol handshake operations are established through normal communication with the target conpot industrial control honeypot. After the second handshake is completed, when the conpot industrial control honeypot receives the third general summon command data packet, the conpot industrial control honeypot cannot parse it and disconnects. This abnormal disconnection method is used to identify the honeypot.

[0020] For the protocol interaction characteristics, the conpot honeypot is mainly identified through the FTP protocol. When the conpot industrial control honeypot implements the FTP protocol, a fixed login account is built into its service source code, including the user account and anonymous FTP account for login. If the target is the conpot industrial control honeypot, an attempt is made to establish a connection with the target through the FTP protocol, and the account and password given in the source code are used to successfully log in, and the response field information is displayed, which is inconsistent with the real industrial control equipment, so the honeypot can be identified.

[0021] Furthermore, the conpot industrial control honeypot identification process based on operating system characteristics includes:

[0022] By obtaining the operating system information that may be included in the response information of the industrial control honeypot in the application layer protocol, combined with the device information obtained by industrial control asset detection, the rationality of running the operating system on the device is analyzed to identify the conpot honeypot.

[0023] Furthermore, if the target industrial control device opens the SSH service, by establishing a connection with the target and making a communication request with the SSH protocol, the asset information of the industrial control device can be extracted from the obtained response information. The asset information may include the operating system information of the target industrial control device; industrial control devices are all embedded devices.

[0024] Furthermore, through SSH protocol communication, the operating system information running on the target host is analyzed. If the target host IP is a PLC, DCS or RTU type industrial control device in the industrial control network asset detection results, and the operating system is identified as a non-embedded Linux operating system, it is considered a honeypot system.

[0025] Furthermore, the process of identifying conpot industrial control honeypots based on characteristic parameters includes:

[0026] The first protocol is the S7 protocol. When identifying Siemens S7 protocol conpot industrial control honeypots, the service code can be used as the highest priority honeypot feature, followed by other honeypot feature information to improve the accuracy of honeypot identification. Other honeypot feature information includes the name and model of the industrial control device.

[0027] The second protocol is the Ethernet / IP protocol. The Status and State fields in the response information of the Ethernet / IP protocol of real industrial control equipment will return different values ​​depending on the actual industrial environment status, but the Status and State fields in the Ethernet / IP protocol response information of the conpot industrial control honeypot will remain unchanged. By viewing the conpot source code and default configuration file, you can view the logic and response field content of the conpot industrial control honeypot for the Ethernet / IP protocol; Status indicates the operating status and connection status of the industrial control equipment; State indicates the fault status and warning status of the industrial control equipment.

[0028] Due to the adoption of the above technical solution, the present invention has the following advantages:

[0029] 1. Identify industrial control honeypots through protocol characteristics. The target device is analyzed for its protocol response and protocol interaction capabilities to determine if it is a honeypot. Protocol response involves sending a request message to the target for a function that the target may not implement, and then using the protocol response content to determine the difference between the protocol response of the honeypot and the real industrial control device. Protocol interaction involves using protocol reverse engineering and analysis methods to identify protocol differences and test the protocol interaction capabilities to identify whether the target is a honeypot.

[0030] 2. Identify industrial control honeypots through operating system characteristics. Industrial control honeypot systems are typically built on Docker, using port mapping to various protocol services. Analysis of the operating system reveals Linux-related operating systems, however, real industrial control equipment typically uses specialized operating systems such as VxWorks. Therefore, in practice, identifying the target's execution environment and analyzing the plausibility of different operating systems in different physical devices, industrial environments, and scenarios can be used to determine whether the target is a honeypot.

[0031] 3. Identify industrial control honeypots through business characteristics. Real industrial control equipment in industrial environments has complex business logic, and the physical data captured by various sensors increases the difficulty of honeypot simulation. Since many honeypots pre-set the values ​​of these physical data, they do not change with time, working environment, and other factors. However, the values ​​in the real environment will show a normal distribution within a certain range and have a certain regularity. In particular, information such as coil status, register status, file records, temperature, and valve status will change depending on the current system operation. Therefore, whether the target response content conforms to the actual business logic can be used to determine whether it is a honeypot.

[0032] 4. Identify industrial control honeypots through characteristic parameters. Typically, honeypot tools provide default configurations and startup parameters for user convenience. Some network security practitioners, to save costs and time, often use off-the-shelf honeypot tools and directly launch them using their default startup and configuration parameters, exposing numerous honeypot characteristics. For example, the initial template file for conpot contains a default configuration, and the simulated industrial control equipment uses default module serial numbers. Visitors can identify the interacting object as a honeypot based on specific model characteristics. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments described in the embodiments of the present invention. For ordinary technicians in this field, other drawings can also be obtained based on these drawings.

[0034] Figure 1 The figure is a flow chart of an industrial control honeypot identification method based on multi-dimensional feature distribution according to an embodiment of the present invention. DETAILED DESCRIPTION

[0035] The present invention will be further described with reference to the accompanying drawings and embodiments. The embodiments described are only a part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by those skilled in the art should fall within the scope of protection of the embodiments of the present invention.

[0036] See also Figure 1 The present invention provides an embodiment of an industrial control honeypot identification method based on multidimensional feature distribution. For industrial control network asset detection results, a preliminary honeypot detection is performed by setting a Bayesian classifier threshold. Depending on whether the threshold is exceeded, data packets are sent for online identification or offline analysis. For detection results that exceed the Bayesian classifier threshold, both online identification and offline processing are performed simultaneously. Online identification involves sending data packets and further honeypot identification using protocol features, operating system features, and business features; offline processing involves analyzing feature parameters in the detection results to identify honeypots. Ultimately, the online and offline honeypot identification results are aggregated and output according to IP address.

[0037] See also Figure 1To improve the accuracy and concealment of honeypot identification in the asset data returned by detection, a Bayesian classifier-based industrial control honeypot detection technology is proposed. This technology performs a preliminary screening of the industrial control network asset detection results to identify industrial control IP addresses that may be honeypots. For these IP addresses, a secondary detection and identification process is performed, which mainly includes online identification (conpot industrial control honeypot identification based on business features, conpot industrial control honeypot identification based on protocol features, and conpot industrial control honeypot identification based on operating system features) and offline analysis (conpot industrial control honeypot identification based on feature parameters). The conpot industrial control honeypot identification tool proposed in this invention is used to identify the industrial control honeypot information. The final output is the asset detection result, which includes some conpot industrial control honeypot IP information. Business features include coil status, register status, file records, temperature, and valve status. Protocol features include protocol response content and protocol interaction process features. Operating system features mainly refer to the difference between the operating system running on the actual industrial control device and the honeypot operating system. Feature parameters include response parameter content features for the S7 and Ethernet / IP protocols.

[0038] 1. The industrial control honeypot detection process based on Bayesian classifier is as follows:

[0039] The industrial control honeypot detection module based on Bayesian classifier is mainly divided into two steps:

[0040] (1) Dataset Construction and Feature Selection: This paper uses business features and operating system features as strong features, that is, the presence of these features can be used to determine whether the device is a honeypot. The strong features are used to identify Internet conpot industrial control honeypots. The identification results are labeled "honeypot". Secondly, four multidimensional features are used to identify conpot industrial control honeypots. If the target industrial control host does not meet any of the four features, it is considered to be a real industrial control device and is labeled "non-honeypot".

[0041] The features selected for the Bayesian classifier primarily include the number of open ports, DNS, ISP, WHOIS, location, and AS information. These features are already available in the first step of industrial control network asset detection, eliminating the need for secondary detection. These features were chosen primarily because honeypots differ from real industrial control devices during internet deployment. For example, ISP and AS information often reflect specific organizations, such as cloud service providers and data centers. If the target industrial control device belongs to a cloud service provider, it is likely a honeypot.

[0042] (2) Industrial control honeypot classification based on Bayesian classifier: The Bayesian definition formula is:

[0043]

[0044] Among them, P(y) and P(X) are the probabilities of events y and X occurring; P(X|y) is the probability of event X occurring under the premise of event y occurring. Derived from the Bayesian formula, we can get:

[0045] P(y|X)∝P(y)P(X|y)

[0046] From the above formula, we can see that the probability of P(y|X) is proportional to P(y) and P(X|y). In this experiment, feature X is a vector composed of static features extracted from the detection results of industrial control network assets, expressed as X=<x1,x2,…,xk> , P(y|X) is the prior probability of judging that the target host is an industrial control honeypot under the condition information X. For each feature, the corresponding asset information of the feature can be obtained from the industrial control network asset detection results in the first step of the honeypot identification process, without the need to send a separate detection data packet. For example, the registration information of the device (DNS, ISP, whois, location, etc.) can be obtained without detection. Static features include the number of open ports, IP ownership and the AS domain to which it belongs; the industrial control network asset detection results include IP, port, protocol, and AS domain to which it belongs;

[0047] Bayesian reasoning is conditionally independent. Calculate the probability:

[0048] P(X|y)=∏ xi∈X P(xi|y)

[0049] Each probability P(xi|y) can be obtained:

[0050]

[0051] The influencing factor of each feature ({P(y|xi)}) can be calculated by formula deduction. For each new target host, a P(y|X) is given. If the calculated result is greater than a preset threshold Sth, the host is added to the list of honeypots to be subsequently identified for subsequent conpot industrial control honeypot identification. In this invention, in order to ensure that more conpot industrial control honeypots are discovered, the false alarm rate is increased at the expense of the false alarm rate. Therefore, the invention subsequently sets Sth = 0.64.

[0052] 2. The conpot industrial control honeypot identification process based on business characteristics is as follows:

[0053] Conpot honeypot identification based on business characteristics primarily targets the Modbus industrial control protocol. The Modbus protocol commonly uses port 502 and follows a slave / master architecture, consisting of a master node and multiple slave nodes. Each slave device using the Modbus protocol has a unique address. To identify industrial control devices using the Modbus protocol, the primary method is to construct corresponding Modbus protocol messages to communicate with the PLC (Programmable Logic Controller) to obtain device manufacturer information and product module information. A common method for identifying Modbus protocol industrial control devices is to obtain the PLC's industrial control device information through Modbus protocol function code messages 43 and 90 and setting slave_id = 0. Industrial control device information includes device name, device type, and manufacturer information. Slave_id represents a distributed node number, used to identify the industrial control device from which the response message originated.

[0054] However, a review of the Modbus protocol configuration file for the conpot industrial control honeypot reveals that the Modbus protocol does not respond to a slave_id of 0 and will disconnect. Slave_id must be set to 1 or 2, and a data packet must be sent to receive a response. However, in a real industrial environment, a PLC with Modbus enabled cannot have multiple slave_ids. This is because slave_ids are primarily used for communication between the master and slaves, and the slave_id address ranges from 1 to 247. Each 1 sent by the master includes a slave_id. Different slaves have different slave_ids, and only those with matching slave_ids will respond to requests. Therefore, if a PLC has multiple slave_ids enabled, it is likely a honeypot.

[0055] 3. The conpot industrial control honeypot identification process based on characteristic parameters is as follows:

[0056] Industrial control honeypot identification is mainly based on two protocols:

[0057] The first protocol is the S7 protocol. The commonly used port number for the S7 protocol is 102. The S7 protocol source code and default configuration file of the conpot industrial control honeypot have certain common characteristics. For normal protocol read requests, the conpot industrial control honeypot will respond with the same information, and the asset information responded does not match the actual PLC device information. In addition, whether the conpot industrial control honeypot uses the S7 protocol, Modbus protocol, or Ethernet / IP protocol, the device_name setting is usually S7-200 if it is not modified.

[0058] In addition, by reading the conpot s7 honeypot service code, we found that the last six bytes of the device information application data returned by the S7 protocol are always "\x00\x00\x00\x00\x00\x00", while the actual S7 protocol response is usually "x00\x00\x00\x00\x00\x08", "x00\x00\x00\x00\x00\x08MMC", etc. Compared with the PLC device information mentioned above, this six-byte feature is difficult to modify and is not stored in the conpot source file. Therefore, when actually identifying the conpot industrial control honeypot using the Siemens S7 protocol, the service code can be used as the highest priority honeypot feature, followed by other honeypot feature information to improve honeypot recognition accuracy; other honeypot feature information includes the industrial control device name and device model.

[0059] The second protocol is the Ethernet / IP protocol, which runs on port 44818. The Status and State fields in the Ethernet / IP protocol response information of real industrial control equipment will return different values ​​depending on the actual industrial environment status. However, the two fields in the Ethernet / IP protocol response information of the conpot industrial control honeypot will remain unchanged. By viewing the conpot source code and default configuration file, you can see its logic and response field content for the Ethernet / IP protocol; Status indicates the operating status and connection status of the industrial control equipment; State indicates the fault status and warning status of the industrial control equipment.

[0060] 4. The conpot industrial control honeypot identification process based on protocol features is as follows:

[0061] The main task is to find out the problems in the implementation of the conpot protocol, use them as features to identify honeypots, analyze them from the two aspects of protocol response and interaction capabilities, and further explore the characteristics of industrial control honeypots to discover more industrial control honeypots on the Internet.

[0062] Regarding protocol response characteristics, conpot honeypot identification is primarily based on the IEC104 protocol. The default port for the IEC104 protocol is 2404. During industrial control network asset detection, two "handshakes" are performed: a test frame and a startup frame are sent. Then, a call command packet, "\x68\0E\00\00\00\00\64\01\06\00\01\00\00\00\00\14," is sent to communicate with the target to obtain a response. The IEC104 protocol implementation in conpot is very simple, implementing only clock synchronization requests and not performing protocol specification checks. It is also unable to issue general call commands and will automatically disconnect upon receiving a general call request. Therefore, in actual communication, three IEC104 handshakes are established with the target conpot industrial control honeypot through normal communication. Typically, after the second handshake, the conpot industrial control honeypot will be unable to parse the third general call command packet and will disconnect, thus identifying the honeypot through this abnormal disconnection.

[0063] Regarding protocol interaction features, the conpot honeypot is primarily identified through the FTP protocol. When implementing the FTP protocol, the conpot industrial control honeypot has fixed login accounts built into its service source code, including a user account and an anonymous FTP account. If the target is a conpot industrial control honeypot, attempting to establish a connection with it via the FTP protocol and using the account and password provided in the source code will successfully log in. The device will respond with the "220-Technodrome-MouserFactory.Authorized personnel only" field, which is inconsistent with real industrial control devices. This feature can be used to identify the honeypot. The "Technodrome" field is a common field in the conpot industrial control honeypot and also appears on the web service page provided by conpot.

[0064] 5. The conpot industrial control honeypot identification process based on operating system characteristics is as follows:

[0065] The main task is to obtain the operating system information that may be included in the response information of the industrial control honeypot in the application layer protocol, combine it with the device information obtained by industrial control asset detection, and analyze the rationality of running the operating system on the device to identify the conpot honeypot.

[0066] This method primarily utilizes the SSH protocol. If the target industrial control device has an SSH service enabled, a standard connection can be established with the target. SSH protocol communication requests can also be used to extract the device's asset information from the response. This asset information may include the target's operating system. Industrial control devices are embedded devices, such as PLCs, DCSs, and RTUs, which typically use real-time operating systems like VxWorks and QNX. HMI devices typically use WinCC. SSH communication analyzes the target host's operating system. If the target IP address is a PLC, DCS, or RTU in the industrial control network asset detection results, and the operating system is identified as a non-embedded Linux operating system, it is generally considered a honeypot system. For example, if a target has an SSH service enabled and the operating system is detected as Ubuntu 4 through SSH communication, which is a non-embedded Linux operating system, and the industrial control network asset detection information indicates that the returned information is an Omron series PLC, it can be identified as a honeypot.

[0067] The present invention solves the problems of the current industrial control honeypot identification technology, such as a small number of identification protocols, a low number of identifications and low accuracy.

[0068] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the field should understand that the specific implementation methods of the present invention can still be modified or replaced by equivalents. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention should be covered by the scope of protection of the claims of the present invention.

Claims

1. A method for identifying industrial control honeypots based on multi-dimensional feature distribution, characterized in that: include: Based on the Bayesian classifier, industrial control honeypot detection is performed on the industrial control network asset detection results to identify industrial control IP addresses that may be honeypots in the industrial control network asset detection results. For each new target host, a prior probability is given that the target host is an industrial control honeypot under feature X. If the prior probability is greater than or equal to a pre-set threshold, the target host is subsequently identified as an industrial control honeypot online and offline. Feature X is a vector composed of static features extracted from the industrial control network asset detection results. Static features include the number of open ports, IP ownership, and the AS domain to which it belongs. The industrial control network asset detection results include IP, port, protocol, and AS domain to which it belongs. If the prior probability is less than the pre-set threshold, the target host is considered to be a real industrial control device and subsequent honeypot identification is not performed. Finally, the results of online and offline honeypot identification are aggregated and output according to IP address. The industrial control honeypot detection based on the Bayesian classifier on the control network asset detection results includes: Dataset construction and feature selection for the Bayesian classifier: Business features and operating system features are considered strong features. If strong features appear, the device is identified as a honeypot. Strong features are used to identify Internet conpot industrial control honeypots, and the identified results are labeled "honeypot". Secondly, four multidimensional features are used to identify conpot industrial control honeypots. Target industrial control hosts that do not meet any of the four multidimensional features are determined to be real industrial control devices and labeled "non-honeypot". The four multidimensional features are protocol features, operating system features, feature parameters, and business features. The feature selection of the Bayesian classifier includes the number of open ports, DNS, ISP, whois, location and AS information features; Industrial control honeypot classification based on Bayesian classifier: For each feature X, the corresponding asset information of the feature is obtained from the industrial control network asset detection results of the honeypot identification process, without sending a separate detection data packet; For each new target host, a prior probability P(y|X) that the feature X is an industrial control honeypot is given. If P(y|X) is greater than a preset threshold, the host is added to the list for subsequent honeypot identification, and subsequent conpot industrial control honeypot identification is performed.

2. The method according to claim 1, characterized in that Online honeypot identification includes conpot industrial control honeypot identification based on business features, conpot industrial control honeypot identification based on protocol features, and conpot industrial control honeypot identification based on operating system features; offline honeypot identification is conpot industrial control honeypot identification based on feature parameters; business features include coil status, register status, file records, temperature, and valve status; Protocol features include the protocol response content and the protocol interaction process; operating system features mainly refer to the fact that the operating system running on real industrial control equipment is different from the operating system of the honeypot; characteristic parameters include the response parameter content features of the S7 and Ethernet / IP protocols.

3. The method according to claim 2, characterized in that The process of identifying the conpot industrial control honeypot based on business characteristics includes: By constructing Modbus protocol messages to communicate with PLCs, device manufacturer information and product module information can be obtained. By actually checking the Modbus protocol configuration file of the conpot industrial control honeypot, the conpot industrial control honeypot Modbus protocol does not respond to slave_id=0 and will disconnect. slave_id represents a distributed node number, which is used to identify the industrial control device from which the response message comes. The slave_id needs to be set to 1 or 2, and a response will be received after the data packet is sent. However, in a real industrial environment, a PLC with the Modbus protocol turned on cannot have multiple slave_ids, because the slave_id is used for communication between the master and the slave. The slave_id address range of the slave is between 1 and 247. Each 1 sent by the master includes a slave_id. Different slaves will have different slave_ids, and only the slave_id that meets the requirements will respond to the request. Therefore, if any PLC has multiple slave_ids turned on, it is likely to be a honeypot.

4. The method according to claim 2, characterized in that The process of identifying the conpot industrial control honeypot based on protocol features includes: Identify the problems in the implementation of the conpot protocol and use them as features to identify honeypots. Analyze the protocol response features and protocol interaction features to further explore the characteristics of industrial control honeypots and discover more industrial control honeypots on the Internet.

5. The method according to claim 4, characterized in that For protocol response characteristics, the conpot honeypot is mainly identified through the IEC104 protocol. During the industrial control network asset detection process, a test frame and a startup frame are sent in sequence, and then a summon command message is sent to communicate with the target to obtain response information. In the actual communication process, three IEC104 protocol handshake operations are established through normal communication with the target conpot industrial control honeypot. After the second handshake is completed, when the conpot industrial control honeypot receives the third general summon command data packet, the conpot industrial control honeypot cannot parse it and disconnects. This abnormal disconnection method is used to identify the honeypot. For protocol interaction features, conpot honeypots are mainly identified through the FTP protocol. When the conpot industrial control honeypot implements the FTP protocol, fixed login accounts are built into its service source code, including user accounts and anonymous FTP accounts for login. If the target is a conpot industrial control honeypot, try to establish a connection with the target through the FTP protocol and use the account and password given in the source code. You can successfully log in and respond with field information, which is inconsistent with the real industrial control equipment, so as to identify the honeypot.

6. The method according to claim 2, characterized in that The conpot industrial control honeypot identification process based on operating system characteristics includes: By obtaining the operating system information that may be included in the response information of the industrial control honeypot in the application layer protocol, combined with the device information obtained by industrial control asset detection, the rationality of running the operating system on the device is analyzed to identify the conpot honeypot.

7. The method according to claim 6, characterized in that If the target industrial control device has an SSH service, by establishing a connection with the target and making a communication request using the SSH protocol, the asset information of the industrial control device can be extracted from the response information obtained. The asset information may include the operating system information of the target industrial control device. Industrial control equipment is all embedded devices.

8. The method according to claim 7, characterized in that Through SSH protocol communication, the operating system information running on the target host is analyzed. If the target host IP is a PLC, DCS or RTU type industrial control device in the industrial control network asset detection results, and the operating system is identified as a non-embedded Linux operating system, it is considered a honeypot system.

9. The method according to claim 2, characterized in that The process of identifying conpot industrial control honeypots based on characteristic parameters includes: The first protocol is the S7 protocol. When identifying Siemens S7 protocol conpot industrial control honeypots, the service code can be used as the highest priority honeypot feature, followed by other honeypot feature information to improve the accuracy of honeypot identification. Other honeypot feature information includes the name and model of the industrial control device. The second protocol is the Ethernet / IP protocol. The Status and State fields in the response information of the Ethernet / IP protocol of real industrial control equipment will return different values ​​depending on the actual industrial environment status, but the Status and State fields in the Ethernet / IP protocol response information of the conpot industrial control honeypot will remain unchanged. By viewing the conpot source code and default configuration file, you can view the logic and response field content of the conpot industrial control honeypot for the Ethernet / IP protocol; Status indicates the operating status and connection status of the industrial control equipment; State indicates the fault status and warning status of the industrial control equipment.

Citation Information

Patent Citations

  • Industrial control honey pot recognition method based on machine learning

    CN108600193A

  • Identification method of Conpot industrial control honey pot

    CN110266650A