Exploiting and securing programmable logic controllers

dc.contributor.authorMorales, Efrén López
dc.contributor.authorRubio-Medrano, Carlos
dc.date.accessioned2022-05-05T14:10:58Z
dc.date.available2022-05-05T14:10:58Z
dc.date.issued2022-04
dc.description.abstractMillions of people rely on vital utility infrastructure such as oil pipelines and water treatment plants. This makes them valuable targets for cyberattacks, and the security of the systems that manage this infrastructure, otherwise known as Industrial Control Systems (ICS), becomes ever more important. ICS are comprised of multiple control components, e.g., electrical, that work together to achieve an industrial goal, e.g., energy, transportation. One crucial component of ICS are Programmable Logic Controllers or PLCs. What makes PLCs a prime target for cyberattacks is their unique capacity to bridge the cyber and physical worlds. In 2021 a cyberattack that targeted the Colonial Pipeline ICS caused fuel shortages across several US states. Thus, it is worth asking: What are the attacks that adversaries can leverage to exploit PLCs? What are the available fortifications that can be used to ensure PLCs remain secure? In this research project, we conduct the first wide-scale systematization of knowledge that categorizes both cyber-attacks and defense- focused approaches for PLCs. Our methodology considers criteria such as attack complexity and defense effectiveness and considers an updated model of the attack surfaces of the PLC. We apply our methodology to several research papers from the past 20 years with the aim to discover trends and patterns. Preliminary results show that there are important research gaps. For example, we found that there are far more attack methods than defense methods. This leaves many attacks unchallenged. Properly identifying and addressing these research gaps may lead to new defense methods for previously unknown vulnerabilities, thus ultimately preventing the occurrence of future cyberattacks affecting vital infrastructure.en_US
dc.identifier.urihttps://hdl.handle.net/1969.6/90553
dc.language.isoen_USen_US
dc.rightsAttribution 4.0 International*
dc.rights.urihttp://creativecommons.org/licenses/by/4.0/*
dc.subjectnetworken_US
dc.subjectcpsen_US
dc.subjecticsen_US
dc.subjectcybersecurityen_US
dc.subjectplcen_US
dc.titleExploiting and securing programmable logic controllersen_US
dc.typePresentationen_US

Files

Original bundle

Now showing 1 - 1 of 1
No Thumbnail Available
Name:
Poster - TAMUCC Spring Research Symposium_Efren Lopez Morales.pptx
Size:
2.25 MB
Format:
Microsoft Powerpoint XML
Description:
Poster

License bundle

Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.72 KB
Format:
Item-specific license agreed upon to submission
Description: