Table of Contents
Fetching ...

Time-to-Lie: Identifying Industrial Control System Honeypots Using the Internet Control Message Protocol

Jacob Williams, Matthew Edwards, Joseph Gardiner

TL;DR

It is shown that many ICS honeypots can be readily identified, via minimal interactions, using only basic networking tools, and raised awareness of the viability of the TTL heuristic and the prevalence of its misconfiguration despite its presence in literature.

Abstract

The convergence of information and operational technology networks has created previously unforeseen security issues. To address these issues, both researchers and practitioners have integrated threat intelligence methods into the security operations of converged networks, with some of the most valuable tools being honeypots that imitate industrial control systems (ICS). However, the development and deployment of such honeypots is a process rich with pitfalls, which can lead to undiagnosed weaknesses in the threat intelligence being gathered. This paper presents a side-channel method of covertly identifying ICS honeypots using the time-to-live (TTL) values of target devices. We show that many ICS honeypots can be readily identified, via minimal interactions, using only basic networking tools. In a study of over 8,000 devices presenting as ICS systems, we detail how our method compares to an existing honeypot detection approach, and outline what our methodology reveals about the current population of live ICS honeypots. In demonstrating our method, this study aims to raise awareness of the viability of the TTL heuristic and the prevalence of its misconfiguration despite its presence in literature.

Time-to-Lie: Identifying Industrial Control System Honeypots Using the Internet Control Message Protocol

TL;DR

It is shown that many ICS honeypots can be readily identified, via minimal interactions, using only basic networking tools, and raised awareness of the viability of the TTL heuristic and the prevalence of its misconfiguration despite its presence in literature.

Abstract

The convergence of information and operational technology networks has created previously unforeseen security issues. To address these issues, both researchers and practitioners have integrated threat intelligence methods into the security operations of converged networks, with some of the most valuable tools being honeypots that imitate industrial control systems (ICS). However, the development and deployment of such honeypots is a process rich with pitfalls, which can lead to undiagnosed weaknesses in the threat intelligence being gathered. This paper presents a side-channel method of covertly identifying ICS honeypots using the time-to-live (TTL) values of target devices. We show that many ICS honeypots can be readily identified, via minimal interactions, using only basic networking tools. In a study of over 8,000 devices presenting as ICS systems, we detail how our method compares to an existing honeypot detection approach, and outline what our methodology reveals about the current population of live ICS honeypots. In demonstrating our method, this study aims to raise awareness of the viability of the TTL heuristic and the prevalence of its misconfiguration despite its presence in literature.

Paper Structure

This paper contains 11 sections, 6 figures, 5 tables.

Figures (6)

  • Figure 1: Total search results before and after duplicate reduction.
  • Figure 2: Technodrome and Mouser strings appearing in the same result.
  • Figure 3: Consensus, Contention, and Error results visualised by distribution between search strings.
  • Figure 4: Consensus ping, traceroute, and reconstructed TTL results in linear ascending order across 3176 results.
  • Figure 5: An example of an irregular port combination, presenting as both Siemens device and Hikvision IP camera.
  • ...and 1 more figures