
Research Article
Faking Smart Industry: A Honeypot-Driven Approach for Exploring Cyber Security Threat Landscape
@INPROCEEDINGS{10.1007/978-3-030-98002-3_23, author={S. M. Zia Ur Rashid and Ashfaqul Haq and Sayed Tanimun Hasan and Md Hasan Furhad and Mohiuddin Ahmed and Abu S. S. M. Barkat Ullah}, title={Faking Smart Industry: A Honeypot-Driven Approach for Exploring Cyber Security Threat Landscape}, proceedings={Cognitive Radio Oriented Wireless Networks and Wireless Internet. 16th EAI International Conference, CROWNCOM 2021, Virtual Event, December 11, 2021, and 14th EAI International Conference, WiCON 2021, Virtual Event, November 9, 2021, Proceedings}, proceedings_a={CROWNCOM \& WICON}, year={2022}, month={3}, keywords={ICS security Cybersecurity OT security Honeypot Cyber-physical security Threat intelligence}, doi={10.1007/978-3-030-98002-3_23} }
- S. M. Zia Ur Rashid
Ashfaqul Haq
Sayed Tanimun Hasan
Md Hasan Furhad
Mohiuddin Ahmed
Abu S. S. M. Barkat Ullah
Year: 2022
Faking Smart Industry: A Honeypot-Driven Approach for Exploring Cyber Security Threat Landscape
CROWNCOM & WICON
Springer
DOI: 10.1007/978-3-030-98002-3_23
Abstract
The digital evolution of Industry 4.0 enabled Operational Technology (OT) infrastructures to operate and remotely maintain cyber-physical systems bridging over IT infrastructures. It has also expanded new attack surfaces and steadily increased the number of malicious cyber incidents for the interconnected smart critical systems. Within Industrial Control System (ICS), Programmable Logic Controller (PLC) plays a crucial function to bridge between cyber and physical environments which made them the victim of sophisticated cyber-attacks that are designed to interrupt and damage their operations. Honeypots have been used as a key tool for aggregating real threat data e.g., malicious activities and payloads, to observe and determine different attack methods and strategies that can easily affect poorly secured cyber-physical systems. In this research, we deployed T-pot honeypot in Amazon Elastic Compute Cloud (AWS EC2) instance across six different regions to determine the current threat landscape as well as how knowledgeable and ingenious threat actors could be in compromising internet-facing Industrial Control System (ICS).