IFFSET: In-Field Fuzzing of Industrial Control Systems using System Emulation

被引:0
|
作者
Tychalas, Dimitrios [1 ]
Maniatakos, Michail [2 ]
机构
[1] NYU, Tandon Sch Engn, Elect & Comp Engn, Brooklyn, NY 11201 USA
[2] New York Univ Abu Dhabi, Elect & Comp Engn, Abu Dhabi, U Arab Emirates
来源
PROCEEDINGS OF THE 2020 DESIGN, AUTOMATION & TEST IN EUROPE CONFERENCE & EXHIBITION (DATE 2020) | 2020年
关键词
Industrial Control; Emulation; Fuzzing;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Industrial Control Systems (ICS) have evolved in the last decade, shifting from proprietary software/hardware to contemporary embedded architectures paired with open-source operating systems. In contrast to the IT world, where continuous updates and patches are expected, decommissioning always-on ICS for security assessment can incur prohibitive costs to their owner. Thus, a solution for routinely assessing the cybersecurity posture of diverse ICS without affecting their operation is essential. Therefore, in this paper we introduce IFFSET, a platform that leverages full system emulation of Linux-based ICS firmware and utilizes fuzzing for security evaluation. Our platform extracts the file system and kernel information from a live ICS device, building an image which is emulated on a desktop system through QEMU. We employ fuzzing as a security assessment tool to analyze ICS specific libraries and find potential security threatening conditions. We test our platform with commercial PLCs, showcasing potential threats with no interruption to the control process.
引用
收藏
页码:662 / 665
页数:4
相关论文
共 12 条
  • [1] Emulation of control-in-the-field - Testing field control system with Foundation Fieldbus
    Hoernicke, Mario
    Bauer, Philipp
    ATP EDITION, 2012, (04): : 42 - 49
  • [2] Applicability of Using Internal GPGPUs in Industrial Control Systems
    Lindgren, Markus
    Sandstrom, Kristian
    Nolte, Thomas
    Hallmans, Daniel
    2014 IEEE EMERGING TECHNOLOGY AND FACTORY AUTOMATION (ETFA), 2014,
  • [3] Analyzing the Impact of Cyberattacks on Industrial Control Systems using Timed Automata
    Jawad, Alvi
    Jaskolka, Jason
    2021 IEEE 21ST INTERNATIONAL CONFERENCE ON SOFTWARE QUALITY, RELIABILITY AND SECURITY (QRS 2021), 2021, : 966 - 977
  • [4] Security Verification of Industrial Control Systems using Partial Model Checking
    Kulik, Tomas
    Boudjadar, Jalil
    Tran-Jorgensen, Peter W. V.
    2020 IEEE/ACM 8TH INTERNATIONAL CONFERENCE ON FORMAL METHODS IN SOFTWARE ENGINEERING, FORMALISE, 2020, : 98 - 108
  • [5] Detecting Cybersecurity Threats for Industrial Control Systems Using Machine Learning
    Choi, Woohyun
    Pandey, Suman
    Kim, Jongwon
    IEEE ACCESS, 2024, 12 : 153550 - 153563
  • [6] Monitoring and Control System Using ETAP Real-Time on Generation Plant Emulation Using OPAL-RT
    Gomez Luna, Eduardo
    Franco Manrique, Rafael
    Palacios Bocanegra, Leinyker
    2018 IEEE ANDESCON, 2018,
  • [7] Evaluation of the control performance of hydronic radiant heating systems based on the emulation using hardware-in-the-loop simulation
    Rhee, Kyu Nam
    Yeo, Myoung Souk
    Kim, Kwang Woo
    BUILDING AND ENVIRONMENT, 2011, 46 (10) : 2012 - 2022
  • [8] Estimation of Hammerstein nonlinear systems with noises using filtering and recursive approaches for industrial control
    Zhang, Mingguang
    Li, Feng
    Yu, Yang
    Cao, Qingfeng
    FRONTIERS OF INFORMATION TECHNOLOGY & ELECTRONIC ENGINEERING, 2024, 25 (02) : 260 - 271
  • [9] Multivariate Abnormal Detection for Industrial Control Systems Using 1D CNN and GRU
    Xie, Xin
    Wang, Bin
    Wan, Tiancheng
    Tang, Wenliang
    IEEE ACCESS, 2020, 8 (08): : 88348 - 88359
  • [10] A Novel Hybrid Model Detection of Security Vulnerabilities in Industrial Control Systems and IoT Using GCN plus LSTM
    Koca, Murat
    Avci, Isa
    IEEE ACCESS, 2024, 12 : 143343 - 143351