🤖 AI Summary
This study addresses the vulnerability of Operational Technology (OT) systems to scanning attacks, their patching constraints, and the absence of native application-layer defenses in Industrial Control System (ICS) protocols. We propose the first application-layer honeypot tailored for OT/ICS environments. By leveraging ICS session semantics, the approach employs Modbus TCP exception code mechanisms and IEC-104 state machine control to detain scanners, enriched by GreyNoise threat intelligence analysis. A 24-day real-world deployment captured 6,709 sessions, with 87%–97% of detention time attributable to malicious IPs, demonstrating that short-delay strategies yield superior efficacy. This work pioneers low-cost active defense by exploiting protocol-native features unavailable in IT/IoT contexts, offering a practical supplementary security solution for environments under strict patching constraints.
📝 Abstract
Operational technology systems face exposure to scanning and protocol-specific attack tools, where compromise risks disrupting physical processes rather than just data. Traditional OT defenses rely on blocking and filtering under strict patch constraints, while tarpitting delays scanners through sustained protocol-level interaction. Modbus TCP and IEC-104 carry no native authentication or integrity protection. Application-layer tarpitting, which stalls scanners inside a legitimate protocol exchange, has been studied for IT and IoT protocols, but not for OT/ICS, whose session semantics (state machines, exception codes) create stalling opportunities IT/IoT lack, and whose patch-constrained environments need exactly this kind of alternative defense. We present StallGrid, to our knowledge the first application-layer tarpits for OT/ICS, stalling scanners via Modbus Exception Codes \texttt{0x05}/\texttt{0x06} and prolonged residence in IEC-104's connected state machine. Five variants (three Modbus TCP, two IEC-104) ran simultaneously for 24 days online, logging 6,709 sessions, 2,039 cumulative per-tarpit unique IPs, and over 2,000 hours of accumulated connection engagement. GreyNoise enrichment attributes 87--97\% of stall time to malicious-tagged IPs, just 22--30\% of connecting addresses; protocol-level behavior further correlates with malicious classification, a fingerprinting signal beyond raw stall time. Shorter induced delay (1.5s) yielded more total engagement than longer delay (3s), observed across both protocols. These results position protocol-native tarpitting as a practical, low-cost complementary defense for OT/ICS environments where patching remains infeasible.