Skip to content
Conference Open access

A Bridged Sandbox–Honeypot Architecture for Behavioral Analysis of ICS Malware

2026 · Proceedings of the 23rd International Conference on Security and Cryptography · 0 citations · 14 references

Abstract

: The convergence of IT and OT networks has exposed Industrial Control Systems (ICS) to targeted malware that abuses industrial protocols. Standalone sandboxes lack the industrial context required to activate OT-specific payloads, whereas honeypots alone cannot safely execute untrusted binaries. This paper presents an integrated architecture that combines a Cuckoo3 sandbox with a programmable high-interaction honeypot (Honeybus, an extension of LOGistICS, a medium-interaction OT honeypot for Modbus and S7comm) and a forensic visualization tool (ViewMod). We validate the architecture by executing FrostyGoop, a Modbus-based ICS malware, against a simulated water-supply control system. The current evaluation focuses on Modbus and a single malware family. Performance benchmarking, systematic evasion testing, and comparison with other honeypots are explicitly identified as future work.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.