OT Intrusion Detection

Honeypots
for industrial
networks

HoneyShark places imitation industrial equipment on your control network and records everything that touches it. The equipment has no production role, so contact with it is worth investigating.

honeyshark / live feed
10:42:03  [ENIP] list identity, 10.10.8.41low
10:42:11  [CIP] chassis enumerated, 6 slotsmedium
10:42:19  [CIP] engineering session, Studio 5000high
10:42:24  [SCAN] 12 ports sweptmedium
10:42:31  [UMAS] reservation taken, ENG-WKS-07high
decoys online: 3high-risk events: 2
Built by control systems engineers

HoneyShark is an OT honeypot appliance developed by EEHA Automation.

Every decoy is reproduced from packet captures of real industrial equipment, so it responds the way genuine devices do. Built and supported by EEHA Automation's IT/OT and PCS team.

Visit Company Website →
The Problem

Most control networks cannot detect an intruder.

An attacker who reaches the plant network will look for controllers and operator stations, map what is there, then attach engineering software. That traffic looks normal and usually passes unnoticed.

01

No Visibility

Most control networks carry no security monitoring, so scanning goes unnoticed.

02

No Software Can Be Installed

Industrial equipment cannot run security software, and production traffic must not be disturbed.

03

Unclear Alerts

IT security tools report protocol errors, not what somebody tried to do to a controller.

Features

What the decoys do

The main capabilities of a HoneyShark appliance.

01

Authentic Decoys

Each decoy is reproduced from packet captures of the real equipment collected from over a decade of control systems engineering.

02

Protocol Accuracy

Industrial protocols and device services answer as the genuine unit does with support for a variety of OT protocols.

03

Engineering Tool Detection

Detects device enumeration and engineering sessions from crafted scripts and commercial engineering software.

04

Event Detection

Honeyshark is not just a packet scanner. It scans for patterns in bursts of packets to report a single event to operators.

05

Source Attribution

Every event carries the source address, the hardware address and the vendor behind it.

06

OT Secure

A non-invasive standalone device on your network. Runs passively without connection to the internet.

Product

All activity on one dashboard

One dashboard showing who touched the decoys, what they attempted and how serious it is.

Event Feed
Events, last 24 hours
Recent Activity
Chassis enumerationMedium
Port sweepLow
Web interface browsedMedium
Engineering sessions2
Benefits

Why plants run HoneyShark

01

Network Oversight

Adds detection to a network that has no security tools of its own.

02

Decoy Spawning

One appliance runs several decoys, and more can be added as the network grows.

03

Early detection

Scanning and browsing happen long before anything is changed on real equipment.

04

No Change To Production

Decoys use their own addresses and do not interact with real equipment.

05

Robust Reporting

Each event names the source, the software used and what it attempted to do.

How Detection Works

How an event is built

Every packet a decoy receives is recorded. Packets that belong to one action are grouped together, given a plain description and a severity, then shown on the dashboard.

PACKET
Every contact recorded
→
PATTERN
Grouped into one action
→
INTENT
Named in plain language
→
RISK
Severity assigned
→
ALERT
Operator notified
Implementation

From install to first alert

01

Place

Give the appliance one address on the control network you want to watch.

02

Configure

Choose which devices to imitate, their addresses and their identities, from the dashboard.

03

Deploy

Decoys appear on the network with vendor hardware addresses and answer like the real equipment.

04

Watch

Any contact is captured, classified and raised on the dashboard, with an email alert if you want one.

Demo

See HoneyShark in action

Tell us about your site and what you need to protect.
See how a honeypot exposes reconnaissance on a live control network.

Phone

1800 433 422

Email

sales@eehaa.com.au

Brisbane Office

Level 4, 451 St Pauls Terrace, Fortitude Valley, QLD 4006

Unit 14, 49 Shore St West, Cleveland, QLD 4163

Perth Office

Unit 2, 100 Terrace Road, East Perth, WA 6004

PO Box 1854,Emerald, QLD 4720

PO Box

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.