TUHH Open Research
Help
  • Log In
    New user? Click here to register.Have you forgotten your password?
  • English
  • Deutsch
  • Communities & Collections
  • Publications
  • Research Data
  • People
  • Institutions
  • Projects
  • Statistics
  1. Home
  2. TUHH
  3. Publication References
  4. PCaaD: Towards automated determination and exploitation of industrial systems
 
Options

PCaaD: Towards automated determination and exploitation of industrial systems

Publikationstyp
Journal Article
Date Issued
2021-11
Sprache
English
Author(s)
Green, Benjamin  
Derbyshire, Richard  
Krotofil, Marina  orcid-logo
Knowles, William  
Prince, Daniel  
Suri, Neeraj  
Institut
Sicherheit in verteilten Anwendungen E-15-H  
TORE-URI
http://hdl.handle.net/11420/10266
Journal
Computers & security  
Volume
110
Article Number
102424
Citation
Computers and Security 110: 102424 (2021-11)
Publisher DOI
10.1016/j.cose.2021.102424
Scopus ID
2-s2.0-85113645607
Over the last decade, Programmable Logic Controllers (PLCs) have been increasingly targeted by attackers to obtain control over industrial processes that support critical services. Such targeted attacks typically require detailed knowledge of system-specific attributes, including hardware configurations, adopted protocols, and PLC control-logic, i.e., process comprehension. The consensus from both academics and practitioners suggests stealthy process comprehension obtained from a PLC alone, to execute targeted attacks, is impractical. In contrast, we assert that current PLC programming practices open the door to a new vulnerability class, affording attackers an increased level of process comprehension. To support this, we propose the concept of Process Comprehension at a Distance (PCaaD), as a novel methodological and automatable approach towards the system-agnostic identification of PLC library functions. This leads to the targeted exfiltration of operational data, manipulation of control-logic behavior, and establishment of covert command and control channels through unused memory. We validate PCaaD on widely used PLCs through its practical application.
Subjects
C2
ICS
OT
PLC Programming Practices
Process Comprehension
Reconnaissance
SCADA
TUHH
Weiterführende Links
  • Contact
  • Send Feedback
  • Cookie settings
  • Privacy policy
  • Impress
DSpace Software

Built with DSpace-CRIS software - Extension maintained and optimized by 4Science
Design by effective webwork GmbH

  • Deutsche NationalbibliothekDeutsche Nationalbibliothek
  • ORCiD Member OrganizationORCiD Member Organization
  • DataCiteDataCite
  • Re3DataRe3Data
  • OpenDOAROpenDOAR
  • OpenAireOpenAire
  • BASE Bielefeld Academic Search EngineBASE Bielefeld Academic Search Engine
Feedback