Skip to main navigation Skip to search Skip to main content

Time-to-lie: Identifying industrial control system honeypots using the internet control message protocol

Jacob J Williams*, Matthew Edwards, Joe Gardiner

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference Contribution (Conference Proceeding)

12 Downloads (Pure)

Abstract

The convergence of information and operational technology networks has created previously unforeseen security issues. To address these issues, both researchers and practitioners have integrated threat intelligence methods into the security operations of converged networks, with some of the most valuable tools being honeypots that imitate industrial control systems (ICS). However, the development and deployment of such honeypots is a process rich with pitfalls, which can lead to undiagnosed weaknesses in the threat intelligence being gathered. This paper presents a side-channel method of covertly identifying ICS honeypots using the time-to-live (TTL) values of target devices. We show that many ICS honeypots can be readily identified, via minimal interactions, using only basic networking tools. In a study of over 8,000 devices presenting as ICS systems, we detail how our method compares to an existing honeypot detection approach, and outline what our methodology reveals about the current population of live ICS honeypots. In demonstrating our method, this study aims to raise awareness of the viability of the TTL heuristic and the prevalence of its misconfiguration despite its presence in literature.
Original languageEnglish
Title of host publication2025 IEEE 45th International Conference on Distributed Computing Systems (ICDCS)
PublisherInstitute of Electrical and Electronics Engineers (IEEE)
ISBN (Electronic)9798331517250
ISBN (Print)9798331517267
DOIs
Publication statusPublished - 1 Dec 2025
Event45th IEEE International Conference on Distributed Computing Systems - Glasgow, United Kingdom
Duration: 20 Jul 202523 Jul 2025
https://icdcs2025.icdcs.org/

Publication series

NameInternational Conference on Distributed Computing Systems
PublisherIEEE
ISSN (Print)1063-6927
ISSN (Electronic)2575-8411

Conference

Conference45th IEEE International Conference on Distributed Computing Systems
Abbreviated titleICDCS 2025
Country/TerritoryUnited Kingdom
CityGlasgow
Period20/07/2523/07/25
Internet address

Research Groups and Themes

  • Cyber Security

Fingerprint

Dive into the research topics of 'Time-to-lie: Identifying industrial control system honeypots using the internet control message protocol'. Together they form a unique fingerprint.

Cite this