PROCEEDINGS OF THE 16TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS 2021)(2021)
US Air Force
被引用0|浏览0
摘要
CADA (Supervisory Control and Data Acquisition) networks have historically been in isolated locations and thought unassailable. In a post-Stuxnet world this assertion has been shown to not be true. Stuxnet exploited the Siemens Step7 programming software to perform a Control-logic injection attack, inserting malicious code into the programming traffic for end devices controlling centrifuges. This attack methodology poses serious risks to Industrial Control Systems (ICS). One forensic security tool, used for incident response and real-time monitoring, captures, and inspects network packets to identify potential malicious activity. As Programmable Logic Controller (PLC) manufacturers move from plain text protocols to more secure alternatives, care must be taken to protect the integrity and availability of the control commands in the network activity while still enabling the forensic process. In this work, we present an analysis of the programming protocol of the SEL-3505 Real Time Automation Controller and a process to extract the control logic program from the captured encrypted network traffic for forensic investigators. The results show that control traffic can be secure as it traverses the network but still successfully be used for a forensic investigation or continuous auditing purposes.