BayesImposter: Bayesian Estimation Based.bss Imposter Attack on Industrial Control Systems

BayesImposter: Bayesian Estimation Based.bss Imposter Attack on Industrial Control Systems
复制标题

DOI:
10.1145/3564625.3564638
复制
发表时间:
2022-10
期刊:
Proceedings of the 38th Annual Computer Security Applications Conference
影响因子:
--
通讯作者:
Anomadarshi Barua;Lelin Pan;M. A. Faruque
Anomadarshi Barua;Lelin Pan;M. A. Faruque
中科院分区:
其他
文献类型:
--
作者:
Anomadarshi Barua;Lelin Pan;M. A. Faruque

文献摘要

相似文献

在过去的六年中,有几篇论文使用内存重复数据删除来触发各种安全问题,例如泄漏堆地址和导致物理内存中的位翻转。成功的内存重复数据删除最基本的要求是提供物理页面的相同副本。最近的作品使用蛮力的方法来创建物理页面的相同副本,从攻击者的角度来看,这是一个不准确和耗时的原语。我们的工作开始填补这一空白,提供了一种特定于域的结构化方式,在工业控制系统(ICS)的环境中复制云设置中的物理页面。在这里,我们展示了一个新的攻击原语- BayesImposter,它指出攻击者可以使用贝叶斯估计技术复制云协议的目标控制DLL文件的. xml部分。我们的方法导致更少的内存(即,4 KB与GB相比)和时间(即,13分钟相比小时)相比,蛮力的方法在最近的作品。我们指出,ICS可以表示为状态空间模型,因此,贝叶斯估计是一个理想的选择,结合内存重复数据删除在云环境中的成功攻击。为了展示BayesImposter的实力,我们使用缩小的自动化高架仓库和西门子工业级SIMATIC S7-1500 PLC作为目标ICS创建了一个真实的自动化平台。我们证明了贝叶斯冒名顶替者可以预测性地注入错误的命令到PLC中,可能会导致设备损坏与机器故障的目标ICS。此外,我们表明,贝叶斯冒名顶替者能够对抗控制目标ICS,导致严重的后果,如杀死一个人,但使它看起来像一个事故。因此,我们也提供了防止攻击的对策。
Over the last six years, several papers used memory deduplication to trigger various security issues, such as leaking heap-address and causing bit-flip in the physical memory. The most essential requirement for successful memory deduplication is to provide identical copies of a physical page. Recent works use a brute-force approach to create identical copies of a physical page that is an inaccurate and time-consuming primitive from the attacker’s perspective. Our work begins to fill this gap by providing a domain-specific structured way to duplicate a physical page in cloud settings in the context of industrial control systems (ICSs). Here, we show a new attack primitive - BayesImposter, which points out that the attacker can duplicate the.bss section of the target control DLL file of cloud protocols using the Bayesian estimation technique. Our approach results in less memory (i.e., 4 KB compared to GB) and time (i.e., 13 minutes compared to hours) compared to the brute-force approach used in recent works. We point out that ICSs can be expressed as state-space models; hence, the Bayesian estimation is an ideal choice to be combined with memory deduplication for a successful attack in cloud settings. To demonstrate the strength of BayesImposter, we create a real-world automation platform using a scaled-down automated high-bay warehouse and industrial-grade SIMATIC S7-1500 PLC from Siemens as a target ICS. We demonstrate that BayesImposter can predictively inject false commands into the PLC that can cause possible equipment damage with machine failure in the target ICS. Moreover, we show that BayesImposter is capable of adversarial control over the target ICS resulting in severe consequences, such as killing a person but making it looks like an accident. Therefore, we also provide countermeasures to prevent the attack.