Skip to main content
U.S. Department of Energy
Office of Scientific and Technical Information

Design Considerations for Distributed Energy Resource Honeypots and Canaries

Technical Report ·
DOI:https://doi.org/10.2172/1821540· OSTI ID:1821540

There are now over 2.5 million Distributed Energy Resource (DER) installations connected to the U.S. power system. These installations represent a major portion of American electricity critical infrastructure and a cyberattack on these assets in aggregate would significantly affect grid operations. Virtualized Operational Technology (OT) equipment has been shown to provide practitioners with situational awareness and better understanding of adversary tactics, techniques, and procedures (TTPs). Deploying synthetic DER devices as honeypots and canaries would open new avenues of operational defense, threat intelligence gathering, and empower DER owners and operators with new cyber-defense mechanisms against the growing intensity and sophistication of cyberattacks on OT systems. Well-designed DER canary field deployments would deceive adversaries and provide early-warning notifications of adversary presence and malicious activities on OT networks. In this report, we present progress to design a high-fidelity DER honeypot/canary prototype in a late-start Laboratory Directed Research and Development (LDRD) project.

Research Organization:
Sandia National Laboratories (SNL-NM), Albuquerque, NM (United States)
Sponsoring Organization:
USDOE National Nuclear Security Administration (NNSA); USDOE Laboratory Directed Research and Development (LDRD) Program
DOE Contract Number:
NA0003525
OSTI ID:
1821540
Report Number(s):
SAND2021-11609; 699602
Country of Publication:
United States
Language:
English

Similar Records

Use of Deception to Improve Client Honeypot Detection of Drive-by-Download Attacks
Book · Fri Jul 24 00:00:00 EDT 2009 · OSTI ID:985019

Identifying Adversarial Cyber-Activity in Operational Technology Environments Using Bayesian Networks
Journal Article · Sun Sep 07 20:00:00 EDT 2025 · IEEE Transactions on Information Forensics and Security · OSTI ID:3011940

HP in Cybersecurity: CyOTE
Conference · Thu Aug 12 00:00:00 EDT 2021 · OSTI ID:1894927