@inproceedings{SchubaHoefkenLinzbach2022, author = {Schuba, Marko and H{\"o}fken, Hans-Wilhelm and Linzbach, Sophie}, title = {An ICS Honeynet for Detecting and Analyzing Cyberattacks in Industrial Plants}, series = {2021 International Conference on Electrical, Computer and Energy Technologies (ICECET)}, booktitle = {2021 International Conference on Electrical, Computer and Energy Technologies (ICECET)}, publisher = {IEEE}, isbn = {978-1-6654-4231-2}, doi = {10.1109/ICECET52533.2021.9698746}, pages = {6 Seiten}, year = {2022}, abstract = {Cybersecurity of Industrial Control Systems (ICS) is an important issue, as ICS incidents may have a direct impact on safety of people or the environment. At the same time the awareness and knowledge about cybersecurity, particularly in the context of ICS, is alarmingly low. Industrial honeypots offer a cheap and easy to implement way to raise cybersecurity awareness and to educate ICS staff about typical attack patterns. When integrated in a productive network, industrial honeypots may not only reveal attackers early but may also distract them from the actual important systems of the network. Implementing multiple honeypots as a honeynet, the systems can be used to emulate or simulate a whole Industrial Control System. This paper describes a network of honeypots emulating HTTP, SNMP, S7communication and the Modbus protocol using Conpot, IMUNES and SNAP7. The nodes mimic SIMATIC S7 programmable logic controllers (PLCs) which are widely used across the globe. The deployed honeypots' features will be compared with the features of real SIMATIC S7 PLCs. Furthermore, the honeynet has been made publicly available for ten days and occurring cyberattacks have been analyzed}, language = {en} } @incollection{SchubaHoefken2022, author = {Schuba, Marko and H{\"o}fken, Hans-Wilhelm}, title = {Cybersicherheit in Produktion, Automotive und intelligenten Geb{\"a}uden}, series = {IT-Sicherheit - Technologien und Best Practices f{\"u}r die Umsetzung im Unternehmen}, booktitle = {IT-Sicherheit - Technologien und Best Practices f{\"u}r die Umsetzung im Unternehmen}, publisher = {Carl Hanser Verlag}, address = {M{\"u}nchen}, isbn = {978-3-446-47223-5}, doi = {10.3139/9783446473478.012}, pages = {193 -- 218}, year = {2022}, language = {de} } @article{SchubaHoefken2012, author = {Schuba, Marko and H{\"o}fken, Hans}, title = {Backtrack5: Datensammlung und Reporterstellung f{\"u}r Pentester mit MagicTree / H{\"o}fken, Hans ; Schuba, Marko}, series = {Hakin9. 73 (2012), H. 3}, journal = {Hakin9. 73 (2012), H. 3}, publisher = {-}, isbn = {1733-7186}, pages = {12 -- 16}, year = {2012}, language = {de} } @article{SchubaHoefkenSchaefer2012, author = {Schuba, Marko and H{\"o}fken, H. and Schaefer, T.}, title = {Smartphone Forensik}, series = {Hakin9 : Practical Protection (2012)}, journal = {Hakin9 : Practical Protection (2012)}, publisher = {-}, isbn = {1733-7186}, pages = {10 -- 20}, year = {2012}, language = {de} } @article{SchubaHermanns1994, author = {Schuba, Marko and Hermanns, Oliver}, title = {Modellierung von Multicastmechanismen zur Unterst{\"u}tzung von Gruppenkommunikation / Schuba, Marko ; Hermanns, Oliver}, series = {Neue Konzepte f{\"u}r die offene verteilte Verarbeitung : Tagungsband des 1. Arbeitstreffens an der RWTH Aachen, 5. September 1994 / Hrsg. des Bd.: Claudia Popien und Bernd Meyer}, journal = {Neue Konzepte f{\"u}r die offene verteilte Verarbeitung : Tagungsband des 1. Arbeitstreffens an der RWTH Aachen, 5. September 1994 / Hrsg. des Bd.: Claudia Popien und Bernd Meyer}, publisher = {Verl. der Augustinus-Buchh.}, address = {Aachen}, isbn = {3-86073-143-2}, pages = {137 -- 147}, year = {1994}, language = {de} } @article{SchubaHermanns1995, author = {Schuba, Marko and Hermanns, Oliver}, title = {Performance Investigations of the IP Multicast Architecture / Hermanns, Oliver ; Schuba, Marko}, series = {Performance of the IP Multicast Achitecture . Proceedings JENC 6. Proceedings of the 6th Joint European Networking Conference, Tel Aviv}, journal = {Performance of the IP Multicast Achitecture . Proceedings JENC 6. Proceedings of the 6th Joint European Networking Conference, Tel Aviv}, pages = {121-1 -- 121-8}, year = {1995}, language = {en} } @article{SchubaHaverkortSchneider2000, author = {Schuba, Marko and Haverkort, Boudewijn R. and Schneider, Gaby}, title = {Performance evaluation of multicast communication in packet-switched networks / Schuba, Marko ; Haverkort, Boudewijn R. ; Schneider, Gaby}, series = {Performance Evaluation. 39 (2000), H. 1-4}, journal = {Performance Evaluation. 39 (2000), H. 1-4}, isbn = {0166-5316}, pages = {61 -- 80}, year = {2000}, language = {en} } @article{SchubaGerstenbergerLahaije2004, author = {Schuba, Marko and Gerstenberger, Volker and Lahaije, Paul}, title = {Internet ID - Flexible Reuse of Mobile Phone Authentication Security for Service Access / Schuba, Marko ; Gerstenberger, Volker, ; Lahaije, Paul}, pages = {1 -- 7}, year = {2004}, language = {en} } @article{SchubaBusboomHerwonoetal.2002, author = {Schuba, Marko and Busboom, Axel and Herwono, Ian and Zavagli, Guido}, title = {Unambiguous Device Identification and Fast Connection Setup in Bluetooth / Busboom, Axel ; Herwono, Ian ; Schuba, Marko ; Zavagli, Guido}, series = {European wireless 2002 : next generation wireless networks: technologies, protocols, services and applications ; technical sessions: 26 - 28 February 2002, tutorials: 25 February 2002, Centro Affari, Florence, Italy ; proceedings / sponsored by EUREL ... General chair: Luciano Lenzini}, journal = {European wireless 2002 : next generation wireless networks: technologies, protocols, services and applications ; technical sessions: 26 - 28 February 2002, tutorials: 25 February 2002, Centro Affari, Florence, Italy ; proceedings / sponsored by EUREL ... General chair: Luciano Lenzini}, pages = {1 -- 5}, year = {2002}, language = {en} } @article{Schuba1999, author = {Schuba, Marko}, title = {Analyse der Antwortzeit von zuverl{\"a}ssigen Multicast-Protokollen im Internet}, series = {Multicast - Protokolle und Anwendungen : 20. - 21. Mai 1999, Braunschweig; 1. GI-Workshop / [Workshop-Leitung: Martina Zitterbart ...]}, journal = {Multicast - Protokolle und Anwendungen : 20. - 21. Mai 1999, Braunschweig; 1. GI-Workshop / [Workshop-Leitung: Martina Zitterbart ...]}, address = {Braunschweig}, pages = {1 -- 14}, year = {1999}, language = {en} }