IP Library Granted Patent US 12,335,308
Granted Patent B1
US 12,335,308 · App. 18/795,878 · Granted Jun 17, 2025

System and method for modelling a cyber-physical system to act as a honeypot for cyberattacks

Inventors: Amr Mohamed Saber Mohamed (Kingston, CA); Deepa Kundur (Oakville, CA)
Assignee: THE GOVERNING COUNCIL OF THE UNIVERSITY OF TORONTO
H04L63/1491H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,335,308
App. No.
18/795,878
Granted
Jun 17, 2025
Kind
B1
Abstract

A system and method for modelling a cyber-physical system to act as a honeypot for cyberattacks. The method including: building a virtual instance of the cyber-physical system including a physical layer and a cyber layer that controls the physical layer; generating a safety set defined by control barrier functions, the safety set delineates the bounds within which the cyber-physical system can operate safely; receiving a cyberattack payload from an attacking device; simulating physical dynamics of the physical layer and operation of the cyber layer; projecting whether the cyberattack payload can force the cyber-physical system to exit the safety set based on the simulated physical dynamics; and performing a safety action on the cyber-physical system when the physical system is projected to exit the safety set due to the cyberattack payload.

Claims (23)

1. A method for modelling a cyber-physical system to act as a honeypot for cyberattacks, the method executed on one or more processing units in communication with a data storage, the method comprising:

building a virtual instance of the cyber-physical system comprising a physical layer and a cyber layer that controls the physical layer, the cyber layer comprising devices that comprise one or more of network devices, control units, sensors, and intelligent electronic devices, wherein the physical layer comprising a system model of the cyber-physical system, inputs to the system model comprising effects of the devices of the cyber layer on physical dynamics of the physical layer, and outputs of the system model comprising measurements of the physical dynamics received by the devices of the cyber layer;

generating a safety set defined by control barrier functions, the safety set delineates the bounds within which the cyber-physical system can operate safely;

receiving a cyberattack payload from an attacking device;

simulating the physical dynamics of the physical layer and operation of the cyber layer;

projecting whether the cyberattack payload can force the cyber-physical system to exit the safety set based on the simulated physical dynamics; and

performing a safety action on the cyber-physical system when the physical system is projected to exit the safety set due to the cyberattack payload.

2. The method of claim 1 , wherein the attack payload is permitted to affect the cyber layer and alter the physical dynamics of the cyber-physical system while the cyber-physical system is projected to remain within the safety set.

3. The method of claim 1 , wherein the safety action comprises a modification to the cyber-physical system that minimally modifies the cyber-physical system or the cyberattack payload to maintain that the cyber-physical system is projected to stay within the safety set.

4. The method of claim 3 , wherein the safety action ceases when the attack payload is projected to not cause the cyber-physical system to exit the safety set.

5. The method of claim 1 , wherein the intelligent electronic devices comprise virtual intelligent electronic devices.

6. The method of claim 1 , wherein the intelligent electronic devices comprise a mix of the virtual intelligent electronic devices and physical intelligent electronic devices.

7. The method of claim 6 , wherein determining whether the cyberattack payload is projected to force the cyber-physical system to exit the safety set comprises determining whether deviations in the measurements of the physical dynamics would trigger protective devices of the cyber-physical system.

8. A system for modelling a cyber-physical system to act as a honeypot for cyberattacks, the system comprising one or more processors in communication with a data storage, the data storage comprising instructions for the one or more processors to execute:

a device module to build a virtual instance of the cyber-physical system and to generate a safety set defined by control barrier functions, the safety set delineates the bounds within which the cyber-physical system can operate safely, the virtual instance comprising a physical layer and a cyber layer that controls the physical layer, the cyber layer comprising devices that comprise one or more of network devices, control units, sensors, and intelligent electronic devices, and the physical layer comprising a system model of the cyber-physical system, inputs to the system model comprising effects of the devices of the cyber layer devices on physical dynamics of the physical later, and outputs of the system model comprising measurements of the physical dynamics received by the devices of the cyber layer devices;

a simulation module to receive a cyberattack payload from an attacking device, and to simulate the physical dynamics of the physical layer and operation of the cyber layer; and

a control module to project whether the cyberattack payload can force the cyber-physical system to exit the safety set based on the simulated physical dynamics, and to perform a safety action on the cyber-physical system when the physical system is projected to exit the safety set due to the cyberattack payload.

9. The system of claim 8 , wherein the attack payload is permitted to affect the cyber layer and alter the physical dynamics of the cyber-physical system while the cyber-physical system is projected to remain within the safety set.

10. The system of claim 8 , wherein the safety action comprises a modification to the cyber-physical system that minimally modifies the cyber-physical system or the cyberattack payload to maintain that the cyber-physical system is projected to stay within the safety set.

11. The system of claim 10 , wherein the safety action ceases when the attack payload is projected to not cause the cyber-physical system to exit the safety set.

12. The system of claim 8 , wherein the intelligent electronic devices comprise virtual intelligent electronic devices.

13. The system of claim 8 , wherein the intelligent electronic devices comprise a mix of the virtual intelligent electronic devices and physical intelligent electronic devices.

14. The system of claim 13 , wherein determining whether the cyberattack payload is projected to force the cyber-physical system to exit the safety set comprises determining whether deviations in the measurements of the physical dynamics would trigger protective devices of the cyber-physical system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 19, 2024
From: MOHAMED, AMR MOHAMED SABER; KUNDUR, DEEPA
To: THE GOVERNING COUNCIL OF THE UNIVERSITY OF TORONTO,
Reel/Frame 069315/0787 →
References Cited (49)
US 11381582B1 · Mohammed · 2022 [cited by examiner]
US 20180159890A1 · Warnick · 2018 [cited by examiner]
US 20200076850A1 · Edgar · 2020 [cited by examiner]
US 20210209233A1 · Rieger · 2021 [cited by examiner]
US 20210243226A1 · El Gamal · 2021 [cited by examiner]
US 20240241494A1 · Schenk · 2024 [cited by examiner]
CA 3001463A1 · 2017 [cited by examiner]
CA 3224095A1 · 2022 [cited by examiner]
CN 106302535A · 2017 [cited by applicant]
CN 106911514A · 2017 [cited by applicant]
CN 108319161A · 2018 [cited by applicant]
CN 109167796A · 2019 [cited by applicant]
CN 118590309A · 2024 [cited by examiner]
WO 2018068040A1 · 2018 [cited by applicant]
WO WO2023084279A1 · 2023 [cited by examiner]
“IEEE standard for interconnection and interoperability of distributed energy resources with associated electric power systems interfaces”, IEEE Std 1547-2018 (Revision of IEEE Std 1547-2003)—Redline, pp. 1-227, Apr. 20… [cited by applicant]
“The cyber threat to Canada's electricity sector. Government of Canada”, Canadian Center for Cyber Security, Nov. 2020. [cited by applicant]
“The honeynet project”, [Online]. Available: https://www.honeynet.org/https://www.honeynet.org/. [cited by applicant]
Ames, Aaron D. , et al., “Control barrier function based quadratic programs for safety critical systems”, IEEE Transactions on Automatic Control, vol. 62, No. 8, pp. 3861-3876, 2016. [cited by applicant]
Buza, Daniel Istvan , et al., “CryPLH: Protecting Smart Energy Systems from Targeted Attacks with a PLC Honeypot”, in Smart Grid Security: Second International Workshop SmartGridSec 2014, Munich, Germany, Feb. 26, 2014,… [cited by applicant]
Conti, Mauro , et al., “Icspot: A high-interaction honeypo for industrial control systems”, in 2022 International Symposium on Networks, Computers and Communications (ISNCC). IEEE, 2022. [cited by applicant]
Cruz, T , et al., “A cybersecurity detection framework for supervisory control and data acquisition systems”, IEEE Transactions on Industrial Informatics, vol. 12, No. 6, pp. 2236-2246, 2016. [cited by applicant]
Dutta, Nitul , et al., “Using honeypots for ics threats evaluation”, Recent developments on industrial control system. resilience, pp. 175-196, 2020. [cited by applicant]
Franco, Javier , et al., “A survey of honeypots and honeynets for internet of things, industrial internet of things, and cyber-physical systems”, IEEE Communications Surveys & Tutorials, vol. 23, No. 4, pp. 2351-2383, 2… [cited by applicant]
Hyun, Dahae , “Collecting cyberattack data for industrial control systems using honeypots”, Ph.D. dissertation, Monterey, California: Naval Postgraduate School, 2018. [cited by applicant]
Kirishikesan, K. , et al., “A high-interaction physics-aware ics honeypot for industrial environments”, The International Journal on Advances in ICT for Emerging Regions, vol. 16, No. 2, 2023. [cited by applicant]
Koltys, Kamil , et al., “Shape: A honeypot for electric power substation”, Journal of telecommunications and information technology, No. 4, pp. 37-43, 2015. [cited by applicant]
Kundur, Deepa, “Hackers will use AI to orchestrate worldwide cyberattacks”, Maclean's, pp. 54-55, Nov. 2023. [cited by applicant]
Langner, Ralph , “To kill a centrifuge: A technical analysis of what stuxnet's creators tried to achieve”, The Langner Group, Nov. 2012. [cited by applicant]
Litchfield, Samuel , et al., “Rethinking the honeypot for cyber-physical systems”, IEEE Internet Computing, vol. 20, No. 5, pp. 9-17, 2016. [cited by applicant]
Mashima, Daisuke , et al., “Towards a grid-wide, high-fidelity electrical substation honeynet”, in 2017 IEEE International Conference on Smart Grid Communications (SmartGridComm). IEEE, 2017, pp. 89-95. [cited by applicant]
Mohamed, Amr S. , et al., “On the use of reinforcement learning for attacking and defending load frequency control”, IEEE Transactions on Smart Grid, pp. 1-16, 2023. [cited by applicant]
Morales, EFRéN LóPEZ , et al., “Honeyplc: A next-generation honeypot for industrial control systems”, in Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security, 2020, pp. 279-291. [cited by applicant]
Pliatsios, Dimitrios , et al., “A novel and interactive industrial control system honeypot for critical smart grid infrastructure”, in 2019 IEEE 24th International Workshop on Computer Aided Modeling and Design of Commu… [cited by applicant]
Redwood, Owen , et al., “A symbolic honeynet framework for scada system threat intelligence”, in Critical Infrastruc ture Protection IX: 9th IFIP 11.10 International Conference, ICCIP 2015, Arlington, VA, USA, Mar. 16-1… [cited by applicant]
Scott, Charles , et al., “Designing and implementing a honeypot for a scada network”, SANS Institute Reading Room, vol. 39, 2014. [cited by applicant]
Shan, Yao , et al., “Neupot: A neural network based honeypot for detecting cyber threats in industrial control systems”, IEEE Transactions on Industrial Informatics, 2023. [cited by applicant]
Skinner, B. F. , et al., “Science and human behavior”, Simon and Schuster, 1965 , No. 92904. [cited by applicant]
Weber, James , “Description of machine models: GENROU, GENSAL, GENTPF and GENTPJ”, Oct. 2015. [Online]. Available: https://www.powerworld.com/files/GENROU-GENSAL-GENTPF-GENTPJ.pdf. [cited by applicant]
Zhang, Thomas , “Honeypot-factory: The use of deception in ics/ot environments”, Feb. 2023. [Online]. Available: https://thehackernewshttps://thehackernews.com/2023/02/honeypot-factory-use-of-deception-in.html. [cited by applicant]
International Search Report for PCT application No. PCT/CN2019/101244, China National Intellectual Property Administration, search completed: Oct. 21, 2019, mailed: Nov. 19, 2019. [cited by applicant]
Written Opinion of the International Searching Authority for PCT application No. PCT/CN2019/101244, China National Intellectual Property Administration, opinion completed: Nov. 13, 2019, mailed: Nov. 19, 2019. [cited by applicant]
Antonioli, Daniele , et al., “Towards high-interaction virtual ICS honeypots-in-a-box”, CPS-SPC '16: Proceedings of the 2nd ACM Workshop on Cyber-Physical Systems Security and Privacy, pp. 13-22, https://doi.org/10.1145… [cited by applicant]
Bernieri, Giuseppe , et al., “MimePot: a model-based honeypot for industrial control networks”, In 2019 IEEE international conference on systems, man and cybernetics (smc) (pp. 433-438). IEEE. [cited by applicant]
Hilt, Stephen , et al., “Caught in the act: Running a realistic factory honeypot to capture real threats”, Trend Micro Research, (2020). [cited by applicant]
López-Morales, EFRéN , et al., “Honeyplc: A next-generation honeypot for industrial control systems”, CCS '20: Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security, pp. 279-291, https://… [cited by applicant]
Lucchese, Marco , et al., “HoneyICS: A high-interaction physics-aware honeynet for industrial control systems”, ARES '23: Proceedings of the 18th International Conference on Availability, Reliability and Security Articl… [cited by applicant]
Murillo, ANDRéS FELIPE , et al., “A virtual environment for industrial control systems: A nonlinear use-case in attack detection, identification, and response”, ICSS '18: Proceedings of the 4th Annual Industrial Control… [cited by applicant]
Navarro, Óscar , et al., “Gathering Intelligence Through Realistic Industrial Control System Honeypots: A Real-World Industrial Experience Report”, In Critical Information Infrastructures Security: 13th International Co… [cited by applicant]