StallGrid slows malicious scanners in industrial control networks
StallGrid: Measuring Internet-exposed Engagement in Protocol-Native OT Tarpits
Cryptography and Security
Summary
Industrial control systems that manage machinery often don’t have strong security updates and are vulnerable to cyber attacks. The authors created StallGrid, a system that intentionally slows down malicious attackers by using the normal ways these machines talk to each other, making scanners wait longer inside the communication process. They tested StallGrid on two common industrial protocols for 24 days and found it kept many bad IP addresses engaged for long times, helping to identify and potentially prevent attacks. This method offers a practical security layer without needing to patch the vulnerable systems themselves.
What this means in practice
- •For industrial control network operators: Add StallGrid to OT networks to slow down and detect malicious scanning activities without needing system patches.
- •For internet security teams: Use protocol-native tarpitting as an additional detector of hostile IPs engaging with control system protocols.
Authors
Arthur Cordeiro, Casper Andersen, Emmanouil Vasilomanolakis
Abstract
Operational technology systems face exposure to scanning and protocol-specific attack tools, where compromise risks disrupting physical processes rather than just data. Traditional OT defenses rely on blocking and filtering under strict patch constraints, while tarpitting delays scanners through sustained protocol-level interaction. Modbus TCP and IEC-104 carry no native authentication or integrity protection. Application-layer tarpitting, which stalls scanners inside a legitimate protocol exchange, has been studied for IT and IoT protocols, but not for OT/ICS, whose session semantics (state machines, exception codes) create stalling opportunities IT/IoT lack, and whose patch-constrained environments need exactly this kind of alternative defense. We present StallGrid, to our knowledge the first application-layer tarpits for OT/ICS, stalling scanners via Modbus Exception Codes \texttt{0x05}/\texttt{0x06} and prolonged residence in IEC-104's connected state machine. Five variants (three Modbus TCP, two IEC-104) ran simultaneously for 24 days online, logging 6,709 sessions, 2,039 cumulative per-tarpit unique IPs, and over 2,000 hours of accumulated connection engagement. GreyNoise enrichment attributes 87--97\% of stall time to malicious-tagged IPs, just 22--30\% of connecting addresses; protocol-level behavior further correlates with malicious classification, a fingerprinting signal beyond raw stall time. Shorter induced delay (1.5s) yielded more total engagement than longer delay (3s), observed across both protocols. These results position protocol-native tarpitting as a practical, low-cost complementary defense for OT/ICS environments where patching remains infeasible.