Industrial control honeypot creation monitoring analysis method and device
By creating industrial control honeypots and utilizing virtualization images and machine learning algorithms to monitor abnormal behavior, the problem of insufficient proactive protection in the IA+ATOS system was solved, achieving the effect of proactive defense.
CN122316652APending Publication Date: 2026-06-30CNNC FUJIAN FUQING NUCLEAR POWER
View PDF 0 Cites 0 Cited by
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CNNC FUJIAN FUQING NUCLEAR POWER
- Filing Date
- 2024-12-27
- Publication Date
- 2026-06-30
AI Technical Summary
Technical Problem
In the IA+ATOS system, existing technologies are unable to effectively simulate industrial control honeypots through protocol emulation, lacking proactive protection measures and resulting in insufficient passive defense measures.
Method used
By creating industrial control honeypots, virtualization images and machine learning algorithms are used to monitor honeypot system data in real time, identify abnormal behaviors, generate alarm logs, and assess attack behavior.
Benefits of technology
It achieves proactive defense against the IA+ATOS system, reduces the possibility of real business networks being detected, increases attack costs and timeliness, and effectively supplements passive protection.
✦ Generated by Eureka AI based on patent content.
Smart Images

Figure HDA0005213163110000011 
Figure HDA0005213163110000021
Abstract
This disclosure belongs to the field of nuclear power technology, specifically relating to a method and apparatus for creating, monitoring, and analyzing industrial control system (ICS) honeypots. The ICS honeypot creation and monitoring analysis method provided by this disclosure offers a new approach to proactive defense. Through honeypot system management software, it manages virtual machine replication, network configuration, system updates, backups, and recovery. By configuring network IPs and services, it quickly creates ICS honeypots, allowing intruders to gain full access to the system and use them as springboards to launch further network attacks, achieving a realistic simulation effect. This allows for detailed recording of intruder attack behavior. It reduces the likelihood of the real business network of the nuclear power system being detected, increases the cost, difficulty, and timeliness of attacker attacks, and effectively complements the passive protection measures existing in the nuclear power system, achieving the goal of proactive defense.
Need to check novelty before this filing date? Find Prior Art