已入深夜,您辛苦了!由于当前在线用户较少,发布求助请尽量完整地填写文献信息,科研通机器人24小时在线,伴您度过漫漫科研夜!祝你早点完成任务,早点休息,好梦!

Control Logic Attack Detection and Forensics Through Reverse-Engineering and Verifying PLC Control Applications

计算机科学 可编程逻辑控制器 工业控制系统 嵌入式系统 上传 控制逻辑 控制(管理) 控制系统 梯形逻辑 计算机安全 计算机硬件 操作系统 工程类 人工智能 电气工程
作者
Yangyang Geng,Xin Che,Rongkuan Ma,Qiang Wei,Mufeng Wang,Yuqi Chen
出处
期刊:IEEE Internet of Things Journal [Institute of Electrical and Electronics Engineers]
卷期号:11 (5): 8386-8400 被引量:6
标识
DOI:10.1109/jiot.2023.3318988
摘要

Industrial control systems (ICSs) are prevalent in critical infrastructures, where programmable logic controllers (PLCs) and physical instruments are integrated. However, multiple successful attacks against PLC control logic programs have caused significant damage to ICSs, which has led to an urgent need for detection and forensics of such attacks. Although several off-the-shelf defending mechanisms have been presented in the past, few of them can detect and locate the control logic attacks at run time. In this article, we propose a practical and automatic control logic attack detection and forensics framework (CLADF) to conduct control logic attack detection and forensics in ICSs. Specifically, the core of CLADF includes: 1) a control application extraction module to extract PLC binary control applications by simulating PLC normal upload functionality; 2) a control application reverse engineering module to disassemble binary control applications; and 3) an attack detection and forensics module for verifying the integrity of PLC control applications, recovering the normal control application, and locating the modified control instructions. We extensively evaluated CLADF in five different application scenarios and two real-world Schneider PLCs. For each PLC, we generated three types of 150 mutated control logic attacks. The results demonstrate that CLADF can effectively extract the run-time binary control application in different application scenarios and disassemble these binary control applications into assembly instructions. Moreover, CLADF can accurately detect the attacks and locate the modified subroutines.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
彭于晏的应助被Aroma采纳,获得10
刚刚
wanci的应助被hehehe采纳,获得10
刚刚
2秒前
2秒前
qazwsx123发布了新的文献求助10
2秒前
5秒前
烟花的应助被luoshiwen采纳,获得10
5秒前
陶俊祺完成签到,获得积分10
7秒前
王哥哥发布了新的文献求助10
8秒前
8秒前
悦耳的冬易完成签到 ,获得积分10
10秒前
洁净笑白发布了新的文献求助10
10秒前
思源的应助被TongKY采纳,获得10
11秒前
SYSUer发布了新的文献求助10
11秒前
丘比特的应助被yy采纳,获得10
12秒前
湖里地儿发布了新的文献求助10
12秒前
hehehe发布了新的文献求助10
13秒前
14秒前
鱼不在乎完成签到,获得积分10
14秒前
宦邶发布了新的文献求助10
19秒前
katha完成签到,获得积分20
19秒前
rjk完成签到 ,获得积分10
20秒前
Orange的应助被jj采纳,获得10
20秒前
20秒前
21秒前
共享精神的应助被王ww采纳,获得50
21秒前
katha发布了新的文献求助10
21秒前
21秒前
轼东坡呀发布了新的文献求助10
23秒前
火的信仰完成签到 ,获得积分10
23秒前
湖里地儿完成签到,获得积分10
24秒前
小福星的应助被SYSUer采纳,获得10
25秒前
科研通AI6.4的应助被zXX采纳,获得10
25秒前
25秒前
千羽灵枫完成签到 ,获得积分10
25秒前
MY发布了新的文献求助10
25秒前
26秒前
26秒前
香蕉幻桃发布了新的文献求助10
26秒前
动人的仙人掌完成签到,获得积分20
26秒前
高分求助中
(应助此贴封号)通过应助OA文献获取积分 10000
Rosenblum, Global Change Biology 800
Organizational Behavior 510
Arbitrage Theory in Discrete and Continuous Time 500
Production Logging: Theoretical and Interpretive Elements 400
English Longitudinal Study of Ageing: Waves 0-11, 1998-2024 300
2026-2030年中國基因檢測行業市場前瞻與未來投資戰略分析報告 300
热门求助领域 (近24小时)
化学 材料科学 医学 生物 计算机科学 工程类 纳米技术 有机化学 化学工程 内科学 物理 生物化学 复合材料 催化作用 细胞生物学 人工智能 心理学 无机化学 基因 遗传学
热门帖子
关注 科研通微信公众号,转发送积分 7827564
求助须知:如何正确求助?哪些是违规求助? 9353121
关于积分的说明 20571235
捐赠科研通 7420520
什么是DOI,文献DOI怎么找? 3335584
关于科研通互助平台的介绍 2480466
邀请新用户注册赠送积分活动 2356044