This work investigates the effect of interaction level, network type, and geographic location on the attractiveness of ICS honeypots. We deploy 16 honeypots, a mix of low- and high-interaction emulations and a physical PLC, across a corporate network and cloud networks in multiple geographic regions, and collect HTTP, S7Comm, and Modbus traffic over a three-month period. Our results show that, for ICS traffic, network type has the largest influence, while interaction level and geographic location have a limited impact. We also find that low-interaction honeypots capture traffic comparable to high-interaction setups, supporting their use for general threat intelligence collection. While most traffic consists of automated reconnaissance, filtering it reveals more complex activities, such as multi-stage campaigns, cross-environment scans, and device manipulation.
Frederik Ondrikov,
Denis Donadel,
Francesco Lupia,
Massimo Merro,
Daniel dos Santos,
Emmanuele Zambon,
Nicola Zannone