Skip to main navigation Skip to search Skip to main content

Snapshotter: Lightweight intrusion detection and prevention system for industrial control systems

Research output: Chapter in Book / Report / Conference proceedingConference contributionAcademicpeer-review

Abstract

© 2018 IEEE.In recent years, security aspects of industrial control systems (ICS) have become a center of interest in cyberwarfare and engineering research, especially after the rise of advanced and sophisticated malware (e.g., Stuxnet) specifically designed to target such systems for different malicious purposes including industrial espionage, physical damage, financial gains, etc. Of special interest to us are programmable logic controllers (PLC) which play a major role in ICS for process control purposes in different industries such as telecommunications, chemical processing, etc. A successful compromise of such controllers provides a malefic adversary the capability to inject arbitrary (malicious) code into the system in hopes of industrial process steering. Therefore, we investigate how a forward secure logging mechanism can be used for intrusion detection and prevention purposes in such cases. The proposed defense mechanism can be summarized in security-related information gathering and fast forward-secure logging by an intrusion detection agent, in addition to log analysis, incident identification and response by a trusted server. We implemented our proposal on the OpenPLC framework as the proof of concept and we show how our proposed scheme can be effective in order to detect and prevent adversaries from running arbitrary code on the controllers. The performance overhead we measured on our platform is at most 54 μs per scan cycle, which confirms how lightweight the presented solution is.
Original languageEnglish
Title of host publicationProceedings - 2018 IEEE Industrial Cyber-Physical Systems, ICPS 2018
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages824-829
ISBN (Electronic)9781538665312
DOIs
Publication statusPublished - 15 Jun 2018
Externally publishedYes
Event1st IEEE International Conference on Industrial Cyber-Physical Systems, ICPS 2018 - Saint Petersburg, Russian Federation
Duration: 15 May 201818 May 2018

Conference

Conference1st IEEE International Conference on Industrial Cyber-Physical Systems, ICPS 2018
Country/TerritoryRussian Federation
CitySaint Petersburg
Period15/05/1818/05/18

Funding

The authors would like to thank Thiago Alves and Mason Ginter for the helpful discussion. This project was supported in part by the AFOSR MURI under award number FA9550-14-1-0351, and in part funded by an NSF grant CNS-1617774“Self-Recovering Certificate Authorities using Backward and Forward Secure Key Management”.

FundersFunder number
AFOSR MURIFA9550-14-1-0351
National Science FoundationCNS-1617774

    Fingerprint

    Dive into the research topics of 'Snapshotter: Lightweight intrusion detection and prevention system for industrial control systems'. Together they form a unique fingerprint.

    Cite this