Snapshotter: Lightweight intrusion detection and prevention system for industrial control systems
Chenglu Jin, Saeed Valizadeh, Marten van Dijk · 2018
In recent years, security aspects of industrial control systems (ICS) have become a center of interest in cyberwarfare and engineering research, especially after the rise of advanced and sophisticated malware (e.g., Stuxnet) specifically designed to target such systems for different malicious purposes including industrial espionage, physical damage, financial gains, etc. Of special interest to us are programmable logic controllers (PLC) which play a major role in ICS for process control purposes in different industries such as telecommunications, chemical processing, etc. A successful compromise of such controllers provides a malefic adversary the capability to inject arbitrary (malicious) code into the system in hopes of industrial process steering. Therefore, we investigate how a forward secure logging mechanism can be used for intrusion detection and prevention purposes in such cases. The proposed defense mechanism can be summarized in security-related information gathering and fast forward-secure logging by an intrusion detection agent, in addition to log analysis, incident identification and response by a trusted server. We implemented our proposal on the OpenPLC framework as the proof of concept and we show how our proposed scheme can be effective in order to detect and prevent adversaries from running arbitrary code on the controllers. The performance overhead we measured on our platform is at most 54 μs per scan cycle, which confirms how lightweight the presented solution is.