LLMPot: Dynamically Configured LLM-based Honeypot for Industrial Protocol and Physical Process Emulation
Industrial Control Systems (ICS) are extensively used in critical infrastructures ensuring efficient, reliable, and continuous operations. However, their increasing connectivity and addition of advanced features make them vulnerable to cyber threats, potentially leading to severe disruptions in essential services. In this context, honeypots play a vital role by acting as decoy targets within ICS networks, or on the Internet, helping to detect, log, analyze, and develop mitigations for ICS-specific cyber threats. Deploying ICS honeypots, however, is challenging due to the necessity of accurately replicating industrial protocols and device characteristics, a crucial requirement for effectively mimicking the unique operational behavior of different industrial systems. Additionally, the difficulty is increased by the substantial manual effort involved in replicating the PLC’s control logic. This is necessary to capture attacker traffic that seeks to interfere with critical infrastructure operations. In this paper, we propose LLMPot, a novel approach for designing honeypots in ICS networks harnessing the potency of Large Language Models (LLMs). LLMPot aims to provide a dynamic framework that can be used to optimize the creation of realistic honeypots with vendor-agnostic configurations and for various control logic, aiming to eliminate the manual effort and specialized knowledge traditionally required by existing strategies. We conducted extensive experiments focusing on a wide array of parameters, demonstrating that LLMPot can effectively create honeypot devices implementing different industrial protocols, PLC configurations, and diverse control logic.
Paper
References (71)
Scroll for more · 38 remaining