Rogue 7 : Rogue Engineering-Station attacks on S 7 Simatic PLCs

Rogue 7 : Rogue Engineering-Station attacks on S 7 Simatic PLCs
复制标题

Rogue 7:Rogue 工程师站对 S 7 Simatic PLC 进行攻击

DOI:
--
复制
发表时间:
2019
期刊:
影响因子:
--
通讯作者:
A. Wool
A. Wool
中科院分区:
--
文献类型:
--
作者:
E. Biham;Sara Bitan;Aviad Carmel;Alon Dankner;Uriel Malin;A. Wool

文献摘要

被引文献

相似文献

西门子工业控制系统架构由 Simatic S7 PLC 组成,一侧与 TIA 工程师站和 SCADA HMI 通信,另一侧控制工业系统。该架构的较新版本据称可以抵御复杂的攻击者,因为它们使用先进的加密原语和协议。在本文中,我们表明即使是最新版本的设备和协议仍然容易受到攻击。对加密协议进行逆向工程后,我们能够创建一个恶意工程师站,它可以伪装成 PLC 的 TIA 并注入任何有利于攻击者的消息。作为第一个示例,我们将可以远程启动或停止 PLC 的攻击扩展到最新的 S7-1500 PLC。我们的主要攻击可以将攻击者选择的控制逻辑下载到远程 PLC。我们最强的攻击——隐形程序注入攻击——可以分别修改运行代码和源代码,并将其下载到PLC。这使得我们能够修改PLC的控制逻辑,同时保留PLC呈现给工程师站的源代码。因此,我们可以创建一种情况,其中 PLC 的功能与工程师可见的控制逻辑不同。
The Siemens industrial control systems architecture consists of Simatic S7 PLCs which communicate with a TIA engineering station and SCADA HMI on one side, and control industrial systems on the other side. The newer versions of the architecture are claimed to be secure against sophisticated attackers, since they use advanced cryptographic primitives and protocols. In this paper we show that even the latest versions of the devices and protocols are still vulnerable. After reverseengineering the cryptographic protocol, we are able to create a rogue engineering station which can masquerade as the TIA to the PLC and inject any messages favourable to the attacker. As a first example we extend attacks that can remotely start or stop the PLC to the latest S7-1500 PLCs. Our main attack can download control logic of the attacker’s choice to a remote PLC. Our strongest attack – the stealth program injection attack – can separately modify the running code and the source code, which are both downloaded to the PLC. This allows us to modify the control logic of the PLC while retaining the source code the PLC presents to the engineering station. Thus, we can create a situation where the PLC’s functionality is different from the control logic visible to the engineer.