Return
AIAF: An Automated ICP-Based Attack Framework for Industrial Control Systems
DOI:10.1109/JIOT.2025.3639897.png)
Abstract
En 中文
Recently reported attacks against programmable logic controllers (PLCs) have shown that the exploitation of industrial control protocols (ICPs), i.e., ICP-based attacks, poses significant threats to industrial control systems (ICSs). ICP-based attacks include two essential steps: generating tailored attack payloads and breaking through the session-ID-based PLC defenses. Traditional approaches to performing the two steps rely on laborious manual analysis. To analyze the threats posed by ICP-based attacks to commercial-off-the-shelf PLCs, we propose <monospace xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">AIAF</monospace>, an Automated ICP-based Attack Framework leveraging proprietary binary protocols, which operates automatically through an offline construction of effective attack payloads and an online ICP-based attack test. We have evaluated <monospace xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">AIAF</monospace> with nine mainstream PLCs, covering nine protocols, showing that <monospace xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">AIAF</monospace> can reverse engineer 12 kinds of session-ID negotiation (six value-changed ones and six value-same ones), generate attack payloads, and execute 35 ICP-based attacks with a 94.29% success rate. Our further Internet-wide evaluation reveals that over 28k PLCs exposed to the Internet are vulnerable to ICP-based attacks.
Keywords:
Industrial control protocol (ICP)-based attack
industrial control system (ICS) security
programmable logic controllers (PLCs)
protocol reverse engineering
Journal
IF:
8.9
Papers:
1.4W
Citations:
7.8W

