Abstract
In order to implement and fine-tune cyber defense mechanisms, it is crucial to know who are the potential enemies and what tactics they are using. In the general cyber security area, honeypot, a decoy system intended to attract cyber attackers, is considered as an effective measure to collect such threat intelligence. However, publication analysing such data is scarce, especially in industrial control systems and smart grid domain. In this paper, we discuss our findings based on the empirical study with 6-month network traces collected in low-interaction smart grid honeypot systems deployed in geographically different regions on Amazon cloud platform. In particular, we discuss actual attack patterns observed as well as insights from the data-driven study on access/attack patterns, correlations among different locations, and dynamics in access sources, some of which are considered effective when configuring security mechanisms such as firewall and intrusion detection systems.