DOI: 10.3390/bdcc10100335 ISSN: 2504-2289

Leveraging LLMs with Honeypots for the Security of Smart Grid SCADA Systems

Nadia Boumkheld, Phil Legg

Supervisory Control and Data Acquisition (SCADA) is a key component in smart grid electric systems. It improves the grid’s efficiency and reliability by transmitting information between field devices, intelligent electronic devices (IEDs) and remote control centers, which enables the real-time monitoring and control of the grid state, the optimization of energy use, and quick detection and response to failures and outages. The use of information and communications technologies in SCADA systems improves their performance, but also exposes them to high security risks and attacks that can cause grid disturbances, blackouts, data theft and other serious issues. To help secure SCADA systems, we implemented a SCADA honeypot that leverages a Large Language Model (LLM) to simulate the operation of a real Distributed Network Protocol 3 (DNP3) Remote Terminal Unit (RTU). It has two modules: (1) an LLM module used for the reconnaissance phase to provide attackers with fake information about the RTU (such as open ports and operating systems) and (2) a DNP3 module which uses openDNP3 to provide protocol-specific replies to attacks targeting DNP3 outstation operations. Through our experiments, we showed that the LLM SCADA honeypot is able to respond accurately to a good percentage of reconnaissance attacks, and is also efficient in handling DNP3 attacks targeting a smart grid SCADA RTU, thus fulfilling the purpose of a honeypot by keeping the attackers engaged and protecting the real RTU system.