ICS HoneyPot project in Kuwait




I will be presenting in  a cyber-security conference in Kuwait in February 2019. I was asked to give a presentation about ICS "Industrial Control System" security. Local oil companies are attending, so I think I will demonstrate an experiment. I want to show them how an online ICS device such as a PLC or SCADA can be exploited and ultimately gain access to  an ICS network , causing an impact. Many PLC devices are exposed online and can be found by specialized search engines such as Shodan.

I thought of bringing a SCADA simulator such as the Tofino simulator. However, Its expensive and not in sale anymore. So I thought of honeypots such as Conpot. Conpot is an ICS honeypot available as an open source. Until now the honeypot idea is the best choice for my situation. I'm also thinking to link it with a physical sensor or with another page that acts like a sensor. The goal is to make this honeypot up and running soon, so Shodan can archive it right away.

The other challenge that Im facing now, is where do I install or host the honeypot. Typically most honeypots are hosted locally, but I think this is no good for me . I want it to be in the cloud so I and Mr Shodan can access it from anywhere and anytime. I looked at existing cloud providers, Amazon EC2 is my choice now.


The project has 3 components:

  1. ICS Honeypot (Conpot)
  2. Database ( storing data and logs)
  3. Logger (To log network traffic and attacker attempt)

The aim of this project is:
  1. Run an ICS honeypot that emulates a Kuwaiti oil company
  2. Make it available in Shodan
  3. Study the behavior and techniques of attackers


 Thats it for now. I will experiment with it this week and I will write my results as soon as Im done.

Peace !

Comments

Popular posts from this blog

Hacking walkthrough: Cacti 1.2.8 exploit Ubuntu 18.04.3 LTS [RCE] [PE]

Hacking Wakthrough : Linux version 3.10.0-123.el7.x86_64 / Wordpress 4.7.2

Hacking Wakthrough: Sync Breeze Enterprise v8.9.24