This paper focuses on Internet-exposed honeypots for Industrial Control Systems (ICS), where web-facing Human-Machine Interfaces (HMIs) coexist with Modbus/TCP services. Such honeypots have been studied in severalf orms and are usually assessed through industrial-protocol fidelity, ranging from protocol emulation to process-aware decoys. The impact of HMI design has, however, remained less clear. In particular, it has not been systematically investigated whether unsolicited Internet actors react to SCADA product recognizability, graphical process controls, or known vulnerable functionality in web-facing HMIs. In this paper, we present a comparative measurement study across four HMI variants connected to the same simulated water-treatment process. During four months of exposure, recognizable SCADA products receive far more HMI-aware traffic than a custom dashboard (2,005–2,175 source IPs and 29.80–35.92% of HTTP IPs, versus 17 and 0.23%). The same-platform ScadaBR comparison shows no statistically significant difference in engagement or potentially process-relevant activity between the variants with and without graphical buttons, and the largest counts and the deepest sessions are observed on ScadaLTS. We also characterize the source IPs observed on both HTTP and Modbus. Modbus traffic is dominated by reconnaissance, and temporal analysis shows that HTTP interactions precede Modbus more often in the overlapping traffic, whereas this does not consistently occur in the HMI-aware subset, leaving open whether the observed overlap pattern reflects scanner intent, campaign-specific tooling, or deployment context.
Beyond Industrial Protocols: An Analysis of Web-Facing HMI Behavior in ICS Honeypots
Donadel, Denis;Lupia, Francesco;Merro, Massimo
In corso di stampa
Abstract
This paper focuses on Internet-exposed honeypots for Industrial Control Systems (ICS), where web-facing Human-Machine Interfaces (HMIs) coexist with Modbus/TCP services. Such honeypots have been studied in severalf orms and are usually assessed through industrial-protocol fidelity, ranging from protocol emulation to process-aware decoys. The impact of HMI design has, however, remained less clear. In particular, it has not been systematically investigated whether unsolicited Internet actors react to SCADA product recognizability, graphical process controls, or known vulnerable functionality in web-facing HMIs. In this paper, we present a comparative measurement study across four HMI variants connected to the same simulated water-treatment process. During four months of exposure, recognizable SCADA products receive far more HMI-aware traffic than a custom dashboard (2,005–2,175 source IPs and 29.80–35.92% of HTTP IPs, versus 17 and 0.23%). The same-platform ScadaBR comparison shows no statistically significant difference in engagement or potentially process-relevant activity between the variants with and without graphical buttons, and the largest counts and the deepest sessions are observed on ScadaLTS. We also characterize the source IPs observed on both HTTP and Modbus. Modbus traffic is dominated by reconnaissance, and temporal analysis shows that HTTP interactions precede Modbus more often in the overlapping traffic, whereas this does not consistently occur in the HMI-aware subset, leaving open whether the observed overlap pattern reflects scanner intent, campaign-specific tooling, or deployment context.I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.



