A Bridged Sandbox–Honeypot Architecture for Behavioral Analysis of ICS Malware
Abstract
: The convergence of IT and OT networks has exposed Industrial Control Systems (ICS) to targeted malware that abuses industrial protocols. Standalone sandboxes lack the industrial context required to activate OT-specific payloads, whereas honeypots alone cannot safely execute untrusted binaries. This paper presents an integrated architecture that combines a Cuckoo3 sandbox with a programmable high-interaction honeypot (Honeybus, an extension of LOGistICS, a medium-interaction OT honeypot for Modbus and S7comm) and a forensic visualization tool (ViewMod). We validate the architecture by executing FrostyGoop, a Modbus-based ICS malware, against a simulated water-supply control system. The current evaluation focuses on Modbus and a single malware family. Performance benchmarking, systematic evasion testing, and comparison with other honeypots are explicitly identified as future work.