Searcharxiv⌕ Search

arXiv subjects

Casper Andersen

Publications and source records attributed to Casper Andersen.

1 recordsLinked to original sources

StallGrid: Measuring Internet-exposed Engagement in Protocol-Native OT Tarpits

Operational technology systems face exposure to scanning and protocol-specific attack tools, where compromise risks disrupting physical processes rather than just data. Traditional OT defenses rely on blocking and filtering under strict patch constraints, while tarpitting delays scanners through sustained protocol-level interaction. Modbus TCP and IEC-104 carry no native authentication or integrity protection. Application-layer tarpitting, which stalls scanners inside a legitimate protocol exchange, has been studied for IT and IoT protocols, but not for OT/ICS, whose session semantics (state machines, exception codes) create stalling opportunities IT/IoT lack, and whose patch-constrained environments need exactly this kind of alternative defense. We present StallGrid, to our knowledge the first application-layer tarpits for OT/ICS, stalling scanners via Modbus Exception Codes \texttt{0x05}/\texttt{0x06} and prolonged residence in IEC-104's connected state machine. Five variants (three Modbus TCP, two IEC-104) ran simultaneously for 24 days online, logging 6,709 sessions, 2,039 cumulative per-tarpit unique IPs, and over 2,000 hours of accumulated connection engagement. GreyNoise enrichment attributes 87--97\% of stall time to malicious-tagged IPs, just 22--30\% of connecting addresses; protocol-level behavior further correlates with malicious classification, a fingerprinting signal beyond raw stall time. Shorter induced delay (1.5s) yielded more total engagement than longer delay (3s), observed across both protocols. These results position protocol-native tarpitting as a practical, low-cost complementary defense for OT/ICS environments where patching remains infeasible.

cs.CR↗