File Download

There are no files associated with this item.

Conference Paper: PLC Forensics Based On Control Program Logic Change Detection

TitlePLC Forensics Based On Control Program Logic Change Detection
Authors
KeywordsPLC forensics
SCADA security
Ladder Logic Programming
Issue Date2015
Citation
10th International Conference on Systematic Approaches to Digital Forensic Engineering (SADFE 2015), Málaga, Spain, 30 September-2 October 2015 How to Cite?
AbstractSupervisory Control and Data Acquisition (SCADA) system is an industrial control automated system. It is built with multiple Programmable Logic Controllers (PLCs). PLC is a special form of microprocessor-based controller with proprietary operating system. Due to the unique architecture of PLC, traditional digital forensic tools are difficult to be applied. In this paper, we propose a program called Control Program Logic Change Detector (CPLCD), it works with a set of Detection Rules (DRs) to detect and record undesired incidents on interfering normal operations of PLC. In order to prove the feasibility of our solution, we set up two experiments for detecting two common PLC attacks. Moreover, we illustrate how CPLCD and network analyzer Wireshark could work together for performing digital forensic investigation on PLC.
DescriptionSession 3: PLC Forensics
Persistent Identifierhttp://hdl.handle.net/10722/219207

 

DC FieldValueLanguage
dc.contributor.authorYau, KKK-
dc.contributor.authorChow, KP-
dc.date.accessioned2015-09-18T07:17:32Z-
dc.date.available2015-09-18T07:17:32Z-
dc.date.issued2015-
dc.identifier.citation10th International Conference on Systematic Approaches to Digital Forensic Engineering (SADFE 2015), Málaga, Spain, 30 September-2 October 2015-
dc.identifier.urihttp://hdl.handle.net/10722/219207-
dc.descriptionSession 3: PLC Forensics-
dc.description.abstractSupervisory Control and Data Acquisition (SCADA) system is an industrial control automated system. It is built with multiple Programmable Logic Controllers (PLCs). PLC is a special form of microprocessor-based controller with proprietary operating system. Due to the unique architecture of PLC, traditional digital forensic tools are difficult to be applied. In this paper, we propose a program called Control Program Logic Change Detector (CPLCD), it works with a set of Detection Rules (DRs) to detect and record undesired incidents on interfering normal operations of PLC. In order to prove the feasibility of our solution, we set up two experiments for detecting two common PLC attacks. Moreover, we illustrate how CPLCD and network analyzer Wireshark could work together for performing digital forensic investigation on PLC.-
dc.languageeng-
dc.relation.ispartofJournal of Digital Forensics, Security and Law (JDFSL)-
dc.subjectPLC forensics-
dc.subjectSCADA security-
dc.subjectLadder Logic Programming-
dc.titlePLC Forensics Based On Control Program Logic Change Detection-
dc.typeConference_Paper-
dc.identifier.emailYau, KKK: kenyaukk@hku.hk-
dc.identifier.emailChow, KP: kpchow@hkucc.hku.hk-
dc.identifier.authorityChow, KP=rp00111-
dc.identifier.hkuros254958-

Export via OAI-PMH Interface in XML Formats


OR


Export to Other Non-XML Formats