Characterizing and Modeling Patching Practices of Industrial Control Systems

Characterizing and Modeling Patching Practices of Industrial Control Systems
复制标题

工业控制系统修补实践的表征和建模

DOI:
10.1145/3084455
复制
发表时间:
2017
期刊:
Proceedings of the ACM on Measurement and Analysis of Computing Systems
影响因子:
--
通讯作者:
Zubair Shafiq
Zubair Shafiq
中科院分区:
--
文献类型:
--
作者:
Brandon Wang;Xiaoye Li;L. P. D. Aguiar;D. Menasché;Zubair Shafiq

文献摘要

被引文献

相似文献

工业控制系统 (ICS) 广泛部署在制造、能源和运输等关键任务基础设施中。 ICS 设备的关键任务性质给 ICS 供应商和资产所有者带来了重要的安全挑战。特别是,ICS 设备的修补通常会推迟到计划的生产中断时,以防止关键系统潜在的运行中断。不幸的是,传闻证据表明 ICS 设备充满了未及时修补的安全漏洞,这使得它们容易受到黑客、民族国家和黑客活动组织的利用。在本文中,我们介绍了 ICS 修补行为的纵向测量和表征研究的结果。我们的研究基于 Shodan 在三年内收集的 500 多种已知工业 ICS 协议和产品的 IP 扫描数据。我们的纵向测量揭示了漏洞披露对 ICS 修补的影响。我们对超过 10 万个暴露在互联网上的 ICS 设备的分析表明,大约 50% 的设备在漏洞披露后 60 天内升级到更新的修补版本。基于我们的测量和分析,我们进一步提出了 Bass 模型的变体来预测 ICS 设备的修补行为。评估表明,与传统的 ARIMA 时间序列预测模型相比,我们提出的模型具有相当的预测精度,同时需要较少的参数并且易于直接物理解释。
Industrial Control Systems (ICS) are widely deployed in mission critical infrastructures such as manufacturing, energy, and transportation. The mission critical nature of ICS devices poses important security challenges for ICS vendors and asset owners. In particular, the patching of ICS devices is usually deferred to scheduled production outages so as to prevent potential operational disruption of critical systems. Unfortunately, anecdotal evidence suggests that ICS devices are riddled with security vulnerabilities that are not patched in a timely manner, which leaves them vulnerable to exploitation by hackers, nation states, and hacktivist organizations. In this paper, we present the results from our longitudinal measurement and characterization study of ICS patching behavior. Our study is based on IP scan data collected from Shodan over the duration of three years for more than 500 known industrial ICS protocols and products. Our longitudinal measurements reveal the impact of vulnerability disclosures on ICS patching. Our analysis of more than 100 thousand Internet-exposed ICS devices reveals that about 50% upgrade to newer patched versions within 60 days of a vulnerability disclosure. Based on our measurement and analysis, we further propose a variation of the Bass model to forecast the patching behavior of ICS devices. The evaluation shows that our proposed models have comparable prediction accuracy when contrasted against traditional ARIMA timeseries forecasting models, while requiring less parameters and being amenable to direct physical interpretation.