HIVE-OT: A Physics-Coherent Industrial Honeypot Attack Corpus
收藏资源简介:
HIVE-OT is an anonymized industrial-control-system (ICS/OT) honeypot attack corpus collected from a physics-coherent water-treatment honeypot exposed to real-world internet background traffic. The corpus contains 273,978 attack interactions captured between 2026-04-20 and 2026-07-05 during a continuous 76-day deployment. The honeypot exposes a Purdue-model-inspired IT/OT attack surface, including industrial protocol decoys for Modbus TCP, S7comm, EtherNet/IP, DNP3, IEC 60870-5-104 and BACnet/IP, together with IT/DMZ-facing services such as HTTP administrative panels, SSH, Telnet, FTP, SMB, RDP, VNC, MQTT and SNMP. Each event includes timestamp, protocol, function code, anonymized source network, destination port, MITRE ATT&CK for ICS technique mapping, physical-impact severity and protocol-specific payload fields when available. Source IPs were anonymized by network truncation and timestamps were jittered by up to ±24 hours per record. The public release does not include raw packet captures or non-anonymized source addresses. The dataset is intended to support reproducible research on ICS/OT honeypots, cyber deception, internet-exposed industrial services, MITRE ATT&CK for ICS mapping, IT/OT adversary asymmetry and critical-infrastructure cybersecurity measurement. This Zenodo record includes the anonymized corpus in CSV and Parquet formats, a data dictionary, methodology notes, license, citation metadata, summary statistics and integrity checksums.



