Honeypots are employed in Industrial Control Systems (ICSs) to detect and analyze attacker behavior, but their deployment involves trade-offs between realism, operational cost, and exposure environment. Despite increasing interest in ICS threat monitoring, there is limited empirical evidence on how deployment choices influence the effectiveness of ICS honeypots in attracting meaningful interactions. This work investigates the effect of interaction level, network type, and geographic location on the attractiveness of ICS honeypots. We deploy 16 honeypots, a mix of low- and high-interaction emulations and a physical PLC, across a corporate network and cloud networks in multiple geographic regions, and collect HTTP, S7Comm, and Modbus traffic over a three-month period. Analyzing multiple protocols allows us to capture differences in attacker behavior across web-based and ICS-specific traffic and to assess how protocol diversity influences the volume, complexity, and nature of observed interactions. To evaluate traffic nature, we fingerprint recurring Modbus and S7Comm interactions using protocol-specific features and associate them with known tools or actors. Our results show that, for ICS traffic, network type has the largest influence, while interaction level and geographic location have a limited impact. We also find that low-interaction honeypots capture traffic comparable to high-interaction setups, supporting their use for general threat intelligence collection. While most traffic consists of automated reconnaissance, filtering it reveals more complex activities, such as multi-stage campaigns, cross-environment scans, and device manipulation.

Evaluating ICS Honeypot Attractiveness: The Role of Interaction Level, Network Type, and Geolocation

Donadel, Denis;Lupia, Francesco;Merro, Massimo;Zannone, Nicola
2026-01-01

Abstract

Honeypots are employed in Industrial Control Systems (ICSs) to detect and analyze attacker behavior, but their deployment involves trade-offs between realism, operational cost, and exposure environment. Despite increasing interest in ICS threat monitoring, there is limited empirical evidence on how deployment choices influence the effectiveness of ICS honeypots in attracting meaningful interactions. This work investigates the effect of interaction level, network type, and geographic location on the attractiveness of ICS honeypots. We deploy 16 honeypots, a mix of low- and high-interaction emulations and a physical PLC, across a corporate network and cloud networks in multiple geographic regions, and collect HTTP, S7Comm, and Modbus traffic over a three-month period. Analyzing multiple protocols allows us to capture differences in attacker behavior across web-based and ICS-specific traffic and to assess how protocol diversity influences the volume, complexity, and nature of observed interactions. To evaluate traffic nature, we fingerprint recurring Modbus and S7Comm interactions using protocol-specific features and associate them with known tools or actors. Our results show that, for ICS traffic, network type has the largest influence, while interaction level and geographic location have a limited impact. We also find that low-interaction honeypots capture traffic comparable to high-interaction setups, supporting their use for general threat intelligence collection. While most traffic consists of automated reconnaissance, filtering it reveals more complex activities, such as multi-stage campaigns, cross-environment scans, and device manipulation.
2026
ICS honeypot
Modbus
S7Comm
Qualitative analysis
Fingerprinting
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11562/1201487
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? ND
social impact