I came, I saw, I hacked: Automated Generation of Process-independent Attacks for Industrial Control Systems


연구 분야: Infrastructure



학회: ASIA CCS '20: Proceedings of the 15th ACM Asia Conference on Computer and Communications Security


초록

Malicious manipulations on Industrial Control Systems (ICSs) endanger critical infrastructures, causing unprecedented losses. State-of-the-art research in the discovery and exploitation of vulnerability typically assumes full visibility and control of the industrial process, which in real-world scenarios is unrealistic. In this work, we investigate the possibility of an automated end-to-end attack for an unknown control process in the constrained scenario of infecting just one industrial computer. We create databases of human-machine interface images, and Programmable Logic Controller (PLC) binaries using publicly available resources to train machine-learning models for modular and granular fingerprinting of the ICS sectors and the processes, respectively. We then explore control-theoretic attacks on the process leveraging common/ubiquitous control algorithm modules like Proportional Integral Derivative blocks using a PLC binary reverse-engineering tool, causing stable or oscillatory deviations within the operational limits of the plant. We package the automated attack and evaluate it against a benchmark chemical process, demonstrating the feasibility of advanced attacks even in constrained scenarios.


Author Profile
Esha Sarkar

New York University New York City NY USA

United States
Author Profile
Hadjer Benkraouda

New York University Abu Dhabi Abu Dhabi UAE

정보 없음
Author Profile
Michail Maniatakos

New York University Abu Dhabi Abu Dhabi UAE

정보 없음

📄 논문 정보

발행 연도 2020년
인용수 13
출판 국가 United States
사이트 ACM
좋아요 수 0

연관 논문 목록 (198건)