Control Logic Injection Attacks on Industrial Control Systems

Control Logic Injection Attacks on Industrial Control Systems
复制标题

对工业控制系统的控制逻辑注入攻击

DOI:
--
复制
发表时间:
2019
期刊:
IFIP International Information Security Conference
影响因子:
--
通讯作者:
Irfan Ahmed
Irfan Ahmed
中科院分区:
--
文献类型:
--
作者:
Hyunguk Yoo;Irfan Ahmed

文献摘要

被引文献

相似文献

可编程逻辑控制器(PLC)上的远程控制逻辑注入攻击对工业控制系统(ICS)环境构成严重威胁。例如,Stuxnet病毒感染了西门子S7-300 PLC的控制逻辑,从而破坏了核电站。过去已经研究了几种控制逻辑注入攻击。然而,他们专注于PLC控制逻辑的开发和影响,而没有考虑通过网络将逻辑传输到PLC的秘密方法。本文是第一次努力探索控制逻辑的数据包操作,以实现隐形,而无需修改PLC固件,以支持新的(混淆)功能。它提出了两种新的控制逻辑注入攻击:(1)数据执行和(2)分段和噪声填充。数据执行攻击通过将控制逻辑转移到PLC的数据块来破坏签名(基于数据包报头字段),然后改变PLC的系统控制流以执行攻击者的逻辑。分段和噪声填充攻击通过在控制逻辑数据包中附加一系列填充字节来破坏深度数据包检测(DPI),同时保持数据包有效载荷中攻击者逻辑的大小非常小。我们实现了对两个不同厂商的工业级PLC的攻击,并证明这些攻击可以成功地颠覆入侵检测方法,如基于签名的入侵检测和基于Anagram的DPI。我们还发布了训练和攻击数据集,以促进这一方向的研究。
Remote control-logic injection attacks on programmable logic controllers (PLCs) impose critical threats to industrial control system (ICS) environments. For instance, Stuxnet infects the control logic of a Siemens S7-300 PLC to sabotage nuclear plants. Several control logic injection attacks have been studied in the past. However, they focus on the development and infection of PLC control logic and do not consider the stealthy methods of transferring the logic to a PLC over the network. This paper is the first effort to explore the packet manipulation of control logic to achieve stealthiness without modifying PLC firmware to support new (obfuscation) functionality. It presents two new control logic injection attacks: (1) Data Execution and (2) Fragmentation and Noise Padding. Data Execution attack subverts signatures (based-on packet-header fields) by transferring control logic to the data blocks of a PLC and then, changes the PLC’s system control flow to execute the attacker’s logic. Fragmentation and Noise Padding attack subverts deep packet inspection (DPI) by appending a sequence of padding bytes in control logic packets while keeping the size of the attacker’s logic in packet payloads significantly small. We implement the attacks on two industry-scale PLCs of different vendors and demonstrate that these attacks can subvert intrusion detection methods successfully, such as signature-based intrusion detection and Anagram-based DPI. We also release the training and attack datasets to facilitate research in this direction.