The invention relates to the technical field of industrial safety, in particular to an industrial control 
honeypot safety protection device and method. A 
shadow system comprises an IP 
simulation module, a flow transfer redirection module, 
virtual switch software and a plurality of 
virtual machine systems; a honeynet 
system comprises a general protocol 
simulation module, an industrial protocol 
simulation module and a 
honeypot management configuration module; an industrial 
control equipment interface provides access to a PLC module, a DSC module, an RTU module, an OPC service, 
SCADA equipment and HMI man-
machine interaction 
system industrial 
control equipment; and a safety 
protection system comprises a log acquisition and analysis module, a flow acquisition and analysis module, an abnormal behavior analysis module, a 
traceability evidence obtaining analysis module, a 
system management module and a system 
database module. The beneficial effects are that the device does not need to connecta network in series, does not need to configure a port flow 
mirror image in a bypass manner, does not change the 
physical network structure of a user, does not affect the network operation environment of the user, achieves the flexible deployment of the environment, and achieves plug-and-play.