簡易檢索 / 詳目顯示

研究生: 林俊豪
Lin, Jun-Hao
論文名稱: 工業控制系統中可擴展性蜜罐研究-以Modbus/TCP 為例
An Extendable Honeypot Research in Industrial Control System : A Modbus/TCP Example
指導教授: 李忠憲
Li, Jung-Shian
學位類別: 碩士
Master
系所名稱: 電機資訊學院 - 電腦與通信工程研究所
Institute of Computer & Communication Engineering
論文出版年: 2021
畢業學年度: 109
語文別: 中文
論文頁數: 58
中文關鍵詞: 工業控制系統蜜罐網路安全可程式化邏輯控制器物聯網搜尋引擎
外文關鍵詞: industrial control system, honeypot, cybersecurity, programmable logic controller, Shodan
相關次數: 點閱:161下載:0
分享至:
查詢本校圖書館目錄 查詢臺灣博碩士論文知識加值系統 勘誤回報
  • 工業控制系統是智慧製造重要的樞紐,其安全性是需要被重視的,一但受到駭客攻擊後果不堪設想,近年來攻擊案例更是層出不窮,保護工業控制系統安全刻不容緩。在擬定防禦策略之前,勢必得先了解工業控制環境中的攻擊手段,常用的手法就是部署蜜罐在其中。工業控制系統蜜罐主要用以偽裝成真實工業控制設備,使攻擊者進入系統時真偽莫辨,並從中蒐集與監控攻擊者行為,例如蜜罐模擬成可程式化邏輯控制器藉此成為攻擊者目標,誘使攻擊者與其互動並記錄整個過程。但因現今常見的工業控制蜜罐通常互動性較低且指紋特徵明顯,容易由回應內容及蜜罐識別工具判斷此為蜜罐裝置。因此本研究以此為出發點,以Modbus/TCP協定為例,設計一套工業控制系統蜜罐雛形,由一伺服器集中控管所有蜜罐,提升管理性可擴展性;並利用輕量級資料交換語言JSON格式,制定蜜罐描述檔規範,定義其特徵及回應方式,達成具有擴展性且互動性高的工控蜜罐系統;後續將比較本蜜罐系統、可程式化邏輯控制器與Conpot蜜罐三者在網路回應的差異,結果顯示本蜜罐可與真實設備之回應相當。最後透過物聯網搜尋引擎Shodan對本工控蜜罐系統進行蜜罐識別,並成功在Shodan的蜜罐評分機制取得較好的分數,證實本工控蜜罐系統也能具備不錯的真實性。

    Industrial control system (ICS) is a critical node of intelligent manufacturing, its cybersecurity is the need to be paid attention to. Once by the consequences of hacker attacks can not be imagined. In recent years, the attack cases are emerging in endlessly, the protection of industrial control system security is urgent. Before developing a defense strategy, it is necessary to understand the attack methods in the environment of the ICS. A common technique is to deploy a honeypot in it. ICS honeypots persuade attackers to believing that it is a real system collect and monitor their attacks. For example, ICS honeypot can be simulated as a programmable logic controller (PLC) to become the attacker’s target. However, because the common ICS honeypot usually responds to useless information, the interaction is low and the fingerprint features are obvious, it is easy to recognize that is honeypot by the response content and the honeypot identification tools. Therefore, in this paper we take the Modbus/TCP protocol as an example, designing a prototype of an ICS honeypot. All honeypots are controlled by a single server to improve the scalability of management, and using lightweight data Exchange language JSON format, formulate honeypot description file specifications to define its characteristics and response methods, so as to achieve the ICS honeypot with scalability and high interaction. Finally, we compare the network responses of our honeypot system, PLC and Conpot, and the results show that the responses of our honeypot system can match the responses of the real industrial device. Next, we used the Internet of Things search engine Shodan to identify our ICS honeypot, and successfully obtained a good score in the honeypot scoring mechanism of Shodan, which confirmed that our honeypot system can also have a high fidelity.

    摘要 II EXTENDED ABSTRACT III 誌謝 XII 目錄 XIV 表目錄 XVI 圖目錄 XVII 一、 緒論 1 1.1 研究背景 1 1.2 研究動機 2 1.3 研究貢獻 4 1.4 全文架構 5 二、 相關研究 6 2.1 工業控制系統 6 2.1.1 工業乙太網路 7 2.1.2 工控相關攻擊 11 2.2 工控蜜罐 15 2.2.1 蜜罐分類 16 2.2.2 Honeyd 18 2.2.3 Conpot 19 2.3 蜜罐識別技術 19 2.3.1 Shodan物聯網搜尋引擎 19 2.3.2 其他物聯網搜尋引擎 21 三、 工業控制系統蜜罐雛型設計 22 3.1 系統架構 23 3.1.1 蜜罐管理伺服器 25 3.1.2 蜜罐節點 26 3.2 描述檔設計 27 3.3 Modbus/TCP協定解析與實現方法 35 四、 實驗結果 36 4.1 實驗環境 36 4.2 SMOD Modbus/TCP 功能碼探測比較 38 4.3 Modbus/TCP 回應比較 39 4.3.1 功能碼03 回應比較 40 4.3.2 功能碼06 回應比較 42 4.4 Shodan Honeyscore評分比較 44 4.4.1 Shodan ICS判斷機制 44 4.4.2 蜜罐雛型Shodan蜜罐分數 47 4.4.3 Conpot Shodan蜜罐分數 49 4.5 蜜罐攻擊日誌 52 4.5.1 偵查攻擊 52 4.5.2 回應注入及命令注入攻擊 53 4.5.3 阻斷服務攻擊 53 五、 結論與未來展望 55 5.1 結論 55 5.2 未來展望 56 參考資料 57

    [1] Kevin E. Hemsley, Dr. Ronald E. Fisher, History of Industrial Control System Cyber Incidents, Idaho Falls: Idaho National Laboratory, 2018.
    [2] Modbus Organization, “Modbus_Application_Protocol_V1_1b3,” 2021. [Online]. Available: https://modbus.org/docs/Modbus_Application_Protocol_V1_1b3.pdf. [Accessed 01 06 2021].
    [3] E. International, “The JSON Data Interchange Syntax,” 2017. [Online]. Available: https://www.ecma-international.org/wp-content/uploads/ECMA-404_2nd_edition_december_2017.pdf. [Accessed 22 08 2021].
    [4] B. Scottberg, W. Yurcik and D. Doss, “Internet honeypots: protection or entrapment?,” IEEE 2002 International Symposium on Technology and Society (ISTAS'02). Social Implications of Information and Communication Technology., Raleigh, NC, USA, 2002.
    [5] R. Bodenheim, J. Butts, S. Dunlap and B. Mullins, “Evaluation of the ability of the Shodan search engine to identify Internet-facing industrial control devices,” international Journal of Critical Infrastructure Protection, vol. 7, no. 2, pp. 114 - 123, 2014.
    [6] ICS-CERT, “ICS-CERT Annual Vulnerability Coordination Report 2016,” 2016. [Online]. Available: https://us-cert.cisa.gov/sites/default/files/Annual_Reports/NCCIC_ICS-CERT_2016_Annual_Vulnerability_Coordination_Report_S508C.pdf. [Accessed 27 05 2021].
    [7] R. Langner, “Stuxnet: Dissecting a Cyberwarfare Weapon,” IEEE Security & Privacy, vol. 9, no. 3, pp. 49-51, 2011.
    [8] K. Stouffer, S. Lightman, K. Scarfone, Guide to industrial control systems (ICS) security, National Institute of Standards and Technology (NIST), 2011.
    [9] T. Carlsson, “Industrial network market shares 2020 according to HMS Networks,” 2020. [Online]. Available: https://www.hms-networks.com/news-and-insights/news-from-hms/2020/05/29/industrial-network-market-shares-2020-according-to-hms-networks. [Accessed 30 5 2021].
    [10] Zhihong Lin, Stephanie Perason, “An inside look at industrial Ethernet communication protocols (Rev. B),” 2018. [Online]. Available: https://www.ti.com/lit/wp/spry254b/spry254b.pdf. [Accessed 27 05 2021].
    [11] R. Langner, “Stuxnet: Dissecting a Cyberwarfare Weapon,” IEEE Security & Privacy, vol. 9, no. 3, pp. 49-51, 2011.
    [12] Rober M. Lee, Michael J. Assante, Time Conway, Analysis of the Cyber Attack on the Ukrainian Power Grid, E-ISAC, 2016.
    [13] P. d. Wet, “Here’s how ransomware attacks like the one on CityPower work – and why some victims end up paying criminals millions,” 2019. [Online]. Available: https://www.businessinsider.co.za/ransomware-attack-on-citypower-johannesburg-why-victims-pay-criminals-2019-7. [Accessed 27 05 2021].
    [14] W. 8. O. Y. S. Staff, “Hacker altered chemicals in Oldsmar water supply to ‘damaging’ levels, sheriff says,” 2021. [Online]. Available: https://www.wfla.com/news/local-news/hacker-caught-altering-chemicals-in-oldsmar-water-supply-to-damaging-levels/. [Accessed 27 05 2021].
    [15] A. Ginter, “THE TOP 20 CYBERATTACKS on Industrial Control Systems,” 2018. [Online]. Available: https://www.fireeye.com/content/dam/fireeye-www/products/pdfs/wp-top-20-cyberattacks.pdf. [Accessed 27 05 2021].
    [16] C. Lin, S. Wu and M. Lee, “Cyber attack and defense on industry control systems,” 2017 IEEE Conference on Dependable and Secure Computing, Taipei, Taiwan ,7-10 Aug., 2017.
    [17] Venkat Pothamsetty, Matthew Franz, “SCADA HoneyNet Project: Building Honeypots for Industrial Networks,” 2004. [Online]. Available: http://scadahoneynet.sourceforge.net/. [Accessed 27 05 2021].
    [18] incibe, “Industrial honeypot implementation guide,” 31 10 2019. [Online]. Available: https://www.incibe-cert.es/sites/default/files/contenidos/guias/doc/incibe-cert_industrial_honeypot_implementation_guide.pdf. [Accessed 06 05 2021].
    [19] N. Provos, “Honeyd: A Virtual Honeypot Daemon,” 10th DFN-CERT Workshop, Hamburg, Germany, 2003.
    [20] A. Jicha, M. Patton and H. Chen, “SCADA honeypots: An in-depth analysis of Conpot,” 016 IEEE Conference on Intelligence and Security Informatics (ISI), 2016.
    [21] SHODAN, “Honeypot Or Not?,” 2021. [Online]. Available: https://honeyscore.shodan.io/. [Accessed 27 05 2021].
    [22] “censys,” censys.io, 2017. [Online]. Available: https://censys.io/. [Accessed 28 05 2021].
    [23] “zoomeye,” 知道創宇旗下404實驗室, [Online]. Available: https://www.zoomeye.org/. [Accessed 28 05 2021].
    [24] “MODBUS TCP Client 測試程式,” 元米科技有限公司, 13 8 2013. [Online]. Available: http://www.icdt.com.tw/main/index.php/2013-07-09-05-16-50/2013-07-18-14-43-35/file/15-modbus-tcp-client-exe. [Accessed 21 05 2021].

    下載圖示
    2026-08-26公開
    QR CODE