Empirical Study of PLC Authentication Protocols in Industrial Control Systems


연구 분야: Analysis



학회: 2021 IEEE Security and Privacy Workshops (SPW)


초록

Programmable logic controllers (PLCs) run a ‘control logic’ program that defines how to control a physical process such as a nuclear plant, power grid stations, and gas pipelines. Attackers target the control logic of a PLC to sabotage a physical process. Most PLCs employ password based authentication mechanisms to prevent unauthorized remote access to control logic. This paper presents an empirical study on proprietary authentication mechanisms in five industry-scale PLCs to understand the security-design practices of four popular ICS vendors, i.e., Allen-Bradley, Schneider Electric, AutomationDirect, and Siemens. The empirical study determines whether the mechanisms are vulnerable by design and can be exploited. It reveals serious design issues and vulnerabilities in authentication mechanisms, including lack of nonce, small-sized encryption key, weak encryption scheme, and client-side authentication. The study further confirms the findings empirically by creating and testing their proof-of-concept exploits derived from MITRE ATT&CK knowledge base of adversary tactics and techniques. Unlike existing work, our study relies solely on network traffic examination and does not employ typical reverse-engineering of binary files (e.g., PLC firmware) to reveal the seriousness of design problems. Moreover, the study covers PLCs from different vendors to highlight an industry-wide issue of secure PLC authentication that needs to be addressed.


Author Profile
Adeen Ayub

Department of Computer Science Virginia Commonwealth University Richmond United States of America

United States
Author Profile
Hyunguk Yoo

Department of Computer Science The University of New Orleans New Orleans United States of America

United States
Author Profile
Irfan Ahmed

Department of Computer Science Virginia Commonwealth University Richmond United States of America

United States

📄 논문 정보

발행 연도 2021년
인용수 33
출판 국가 United States
사이트 IEEE
좋아요 수 0

연관 논문 목록 (182건)