SePanner: Analyzing Semantics of Controller Variables in Industrial Control Systems based on Network Traffic


연구 분야: Infrastructure



학회: ACSAC '23: Proceedings of the 39th Annual Computer Security Applications Conference


초록

Programmable logic controllers (PLCs), the essential components of critical infrastructure, play a crucial role in various industrial manufacturing processes. Recent attack events show that attackers have a strong interest in tampering with the controller variables, such as the device status and internal program logic. A typical attack strategy is that the attackers just send malicious network traffic of industrial control protocols (ICPs) to change the controller variables of PLCs. To defend against this attack, a lot of countermeasures have been proposed to detect anomalies in network traffic based on the semantic analysis. However, the proprietary nature of ICPs poses a challenge to extracting the required semantics for evaluating the controller variables. In this paper, we propose a novel framework named SePanner to extract the semantics of controller variables from proprietary ICPs based on network traffic. Specifically, SePanner conducts the multi-state comparison to locate the semantic fields directly, then removes the interfering fields by the single-state comparison and filtering criteria. Our experiments demonstrate that SePanner can precisely extract the semantics of controller variables from proprietary ICPs, providing protection for PLCs while remaining compatible with various proprietary binary protocols.


Author Profile
Jianying Zhou

Singapore University of Technology and Design Singapore

Andorra
Author Profile
Jie Meng

State Key Laboratory of Industrial Control Technology and College of Control Science and Engineering Zhejiang University China

Andorra
Author Profile
Zeyu Yang

State Key Laboratory of Industrial Control Technology and College of Control Science and Engineering Zhejiang University China

Andorra

📄 논문 정보

발행 연도 2023년
인용수 4
출판 국가 Andorra, China
사이트 ACM
좋아요 수 0

연관 논문 목록 (212건)