Trend Micro have released a report detailing the research they've done into ICS (industrial control systems), and SCADA (supervisory control and data acquisition) attacks. They set up three seperate honeypots on the public internet for their experiment. One of the honeypots is an actual SCADA device requiring high-interaction from the researchers. It is a web application designed to look like a water pressure station. They also have a low-interaction honeypot is a software-based emulation of a SCADA system. They honeypots were attacked a total of 39 times. 12 were unique and targeted, and 13 were repeated by a few of the attackers.
This is important to the ever-growing fear of a targeted ICS/SCADA attack that may cause physical damage to these systems and could potentially be harmful to humans living in or around the area where the attacked device has been compromised.
Download the full report from Trend Micro here: I am a big fan of this type of research as it can help unveil the types of attacks various attackers are using as well as how often they are doing it. I have set up a few honeypots on my home network for research in the past and have been running one on the internet for about a month now that I will be writing a blog posting for in the near future. |
root@dafthack:~# >