Back to Search Start Over

Exploring Shodan From the Perspective of Industrial Control Systems

Authors :
Yongle Chen
Xiaowei Lian
Dan Yu
Shichao Lv
Shaochen Hao
Yao Ma
Source :
IEEE Access, Vol 8, Pp 75359-75369 (2020)
Publication Year :
2020
Publisher :
IEEE, 2020.

Abstract

As an essential component of the critical infrastructure, the Industrial Control System (ICS) is facing increasing cyber threats. The emergence of the Shodan search engine also magnified this threat. Since it can identify and index Internet-connected industrial control devices, the Shodan search engine has become a favorite toolkit for attackers and penetration testers. In this paper, we use honeypot technology to conduct a comprehensive exploring on Shodan search engine. We first deploy six distributed honeypot systems and collect three-month traffic data. For exploring Shodan, we design a hierarchical DFA-SVM recognition model to identify Shodan scans based on the function code and traffic feature, which is adapted to find the Shodan and Shodan-like scanners superior to the predominant method of reverse resolving IPs. Finally, we conduct an in-depth analysis for Shodan scans and evaluate the impact of Shodan on industrial control systems in terms of scanning time, scanning frequency, scanning port, region preferences, ICS protocol preferences and ICS protocol function code proportion. Accordingly, we provide some defensive measures to mitigate Shodan threat.

Details

Language :
English
ISSN :
21693536
Volume :
8
Database :
Directory of Open Access Journals
Journal :
IEEE Access
Publication Type :
Academic Journal
Accession number :
edsdoj.3f51ed3a37ce4e8c84cf79b953af12f2
Document Type :
article
Full Text :
https://doi.org/10.1109/ACCESS.2020.2988691