Medium Interactivity Operational Technology Honeypots for Threat Intelligence
Medium Interactivity Operational Technology Honeypots for Threat Intelligence
批准号:
2603671
负责人:
金额:
$0.0万
依托单位:
依托单位国家:
英国
项目类别:
Studentship
财政年份:
2021
资助国家:
英国
项目状态:
未结题
起止时间:
2021 至 --
中文摘要
对作战技术和工业控制系统的威胁在不断增加。由于业务和信息技术部门之间的连通性越来越强,情况变得更加危险。新的威胁不仅表现为复杂的恶意软件工具集,如Chernovite的“pipeDream”或SandWorm的“CrashOverride”,而且我们还看到,源于勒索软件即服务趋势的通用勒索软件攻击正在增加。在攻击日益频繁的时代,重要的是我们保持威胁情报流,以帮助保护这些系统的安全。蜜罐长期以来一直被部署模仿物联网设备来收集威胁情报,但它们在作战技术领域的应用却被大大开发不足。围绕这一问题的一个关键问题是缺乏对有效部署的研究。低交互蜜罐不具有足够的说服力,只能有效地捕获自动攻击,而高交互蜜罐的成本太高,无法大规模部署。本研究旨在探索一种在模拟和物理硬件之间取得平衡的蜜罐,也称为中等交互蜜罐。在整个研究阶段,将从技术实施、有效的欺骗性特征以及此类措施的合法和合乎道德的部署的角度来探索什么是有效的蜜罐。
英文摘要
Threats towards operational technology and industrial control systems are ever increasing. The landscape has become more perilous due to the increasing connectivity between operational and informational technology sectors. New threats are not only taking the form of sophisticated malware tool sets like Chernovite's "PipeDream" or Sandworm's "CrashOverride", but we are also seeing an increase in generic ransomware attacks originating from the Ransomware-as-a-service trend. In a time where attacks are growing more frequent, it is important that we maintain a flow of threat intelligence to assist in securing these systems.Honeypots have a long history being deployed mimicking Internet-of-Things devices to gather threat intelligence, but their application in the field of operational technology is considerably under-explored. A pivotal issue surrounding this is a lack of research towards effective deployments. Low-interactivity honeypots are not adequately convincing and are only effective for catching automated attacks, whereas high interaction honeypots are far too expensive to deploy on a larger scale.This research aims to explore the creation of a honeypot which strikes a balance between simulation and physical hardware, also known as a medium-interactivity honeypot. Throughout the stages of research, what makes an effective honeypot will be explored from the angle of technological implementation, effective deceptive characteristics, as well as the lawful and ethical deployment of such measures.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
海外基金