计算机科学
可编程逻辑控制器
工业控制系统
嵌入式系统
上传
控制逻辑
控制(管理)
控制系统
梯形逻辑
计算机安全
计算机硬件
操作系统
工程类
人工智能
电气工程
作者
Yangyang Geng,Xin Che,Rongkuan Ma,Qiang Wei,Mufeng Wang,Yuqi Chen
标识
DOI:10.1109/jiot.2023.3318988
摘要
Industrial control systems (ICSs) are prevalent in critical infrastructures, where programmable logic controllers (PLCs) and physical instruments are integrated. However, multiple successful attacks against PLC control logic programs have caused significant damage to ICSs, which has led to an urgent need for detection and forensics of such attacks. Although several off-the-shelf defending mechanisms have been presented in the past, few of them can detect and locate the control logic attacks at run time. In this article, we propose a practical and automatic control logic attack detection and forensics framework (CLADF) to conduct control logic attack detection and forensics in ICSs. Specifically, the core of CLADF includes: 1) a control application extraction module to extract PLC binary control applications by simulating PLC normal upload functionality; 2) a control application reverse engineering module to disassemble binary control applications; and 3) an attack detection and forensics module for verifying the integrity of PLC control applications, recovering the normal control application, and locating the modified control instructions. We extensively evaluated CLADF in five different application scenarios and two real-world Schneider PLCs. For each PLC, we generated three types of 150 mutated control logic attacks. The results demonstrate that CLADF can effectively extract the run-time binary control application in different application scenarios and disassemble these binary control applications into assembly instructions. Moreover, CLADF can accurately detect the attacks and locate the modified subroutines.
科研通智能强力驱动
Strongly Powered by AbleSci AI