Honeyeye: A Network Traffic Collection Framework for Distributed ICS Honeynets
Chuan Sheng, Yu Kai Yao, Dongbiao Li, Hongna An, Wei Yang · 2020
The honeynet, as an important security resource, is increasingly used in the industrial field in order to detect, analyze, and prevent network attacks against industrial control systems (ICSs). However, conventional network traffic collection methods used in honeynets cannot meet the more and more complex requirements of large-scale and distributed honeynets. This paper presents a new network traffic collection framework for distributed ICS honeynets called Honeyeye. Honeyeye can provide some different running modes for different application scenarios and purposes. Honeyeye can not only collect and save network traffic, but also parse it into readable data and convert it into the required format. By this way, Honeyeye tends to provide network administrators and intrusion detection systems (IDSs) with more understandable and directly available data rather than captured opaque binary data. Experimental results show that the framework is effective in parsing, converting, and transmitting ICS honeynet traffic.