论文标题

在梯子逻辑下行走:PLC-VBS,PLC控制逻辑漏洞发现工具

Walking Under the Ladder Logic: PLC-VBS, a PLC Control Logic Vulnerability Discovery Tool

论文作者

Maesschalck, Sam, Staves, Alexander, Derbyshire, Richard, Green, Benjamin, Hutchison, David

论文摘要

网络安全风险评估为理解现有风险暴露的关键起点提供了一个关键的起点,可以通过其中形成适当的缓解策略。在将风险视为威胁,脆弱性和影响的产物的地方,理解每个要素的重要性是同等重要的。在工业控制系统(ICS)环境中,这可能是一个挑战,在这种环境中,采用的技术通常不仅是定制的,而且与物理世界直接互动。迄今为止,现有的漏洞识别集中在传统漏洞类别上。尽管这为风险评估者提供了基线的理解,并且能够假设潜在的影响,但它是高水平的,以一种抽象的水平运行,在传统信息系统环境中被视为不完整。本文介绍的工作使对ICS设备的脆弱性更进一步。它提供了一个工具PLC-VB,可帮助识别可编程逻辑控制器(PLC)漏洞,特别是在用于监视,控制和自动化操作过程的逻辑中。 PLC-VBS为风险评估者提供了有关利用确定漏洞的潜在影响的更连贯的图片;这特别适用于操作过程元素。

Cyber security risk assessments provide a pivotal starting point towards the understanding of existing risk exposure, through which suitable mitigation strategies can be formed. Where risk is viewed as a product of threat, vulnerability, and impact, understanding each element is of equal importance. This can be a challenge in Industrial Control System (ICS) environments, where adopted technologies are typically not only bespoke, but interact directly with the physical world. To date, existing vulnerability identification has focused on traditional vulnerability categories. While this provides risk assessors with a baseline understanding, and the ability to hypothesize on potential resulting impacts, it is high level, operating at a level of abstraction that would be viewed as incomplete within a traditional information system context. The work presented in this paper takes the understanding of ICS device vulnerabilities one step further. It offers a tool, PLC-VBS, that helps identify Programmable Logic Controller (PLC) vulnerabilities, specifically within logic used to monitor, control, and automate operational processes. PLC-VBS gives risk assessors a more coherent picture about the potential impact should the identified vulnerabilities be exploited; this applies specifically to operational process elements.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源