计算机科学
可编程逻辑控制器
工业控制系统
构造(python库)
过程(计算)
计算机安全
嵌入式系统
编码(集合论)
控制(管理)
控制系统
访问控制
控制器(灌溉)
信息物理系统
方案(数学)
分布式计算
软件工程
过程控制
保护机制
安全性分析
安全控制
源代码
服务器
密码学
SCADA系统
控制系统安全
诱饵
硬件安全模块
关键基础设施
作者
Wenjun Yao,Binxing Fang,Rui Wang,Hui Lu,Yali Sun,Zhihong Tian
标识
DOI:10.1109/tmc.2026.3678913
摘要
Unlike traditional Programmable Logic Controller (PLC) honeypots, a PLC honeypoint is a lightweight, easily deployable decoy that emulates realistic Industrial Control System (ICS) services to deceive attackers and uncover their malicious intent. PLC honeypoints are an effective mechanism for enhancing ICS defense against cyber attackers. However, existing PLC honeypoints lack realism in their services, failing to sufficiently engage attackers during reconnaissance or interaction phases. To address this gap, we introduce H4PLC, a novel PLC honeypoint that employs an invariant-based approach to incorporate realistic ICS physical process properties. H4PLC overcomes challenges in characterizing and integrating these properties into PLC services by leveraging ICS log data to construct Physical Process Trees and control rule transitions, enabling dynamic and authentic responses to attacker reconnaissance and malicious code injections. To the best of our knowledge, H4PLC is the first PLC honeypoint to generate contextually variable, appropriate, and responsive ICS messages tailored to Advanced Persistent Threat (APT) attackers. Experimental evaluations demonstrate that H4PLC provides diverse realistic PLC services and effectively reports anomalies under malicious code injections.
科研通智能强力驱动
Strongly Powered by AbleSci AI