Special Session: Potentially Leaky Controller: Examining Cache Side-Channel Attacks in Programmable Logic Controllers
Dimitrios Tychalas, Michail Maniatakos · 2020
Industrial Control Systems (ICS) have evolved during the last decade following a new paradigm in the fourth industrial revolution, defined by the flexibility provided from open-source software such as Embedded Linux. In the same time-span, cache side-channel attacks have been identified as a prominent threat to any kind of computer system, facilitating highly stealthy confidentiality compromising attacks that enable information exfiltration. Given their crucial position in the systems they facilitate, ICS can be exploited to extract highly sensitive information that can compromise the system itself and, by extension, the infrastructure they belong to. Thus, in this paper we will examine the threat cache side-channel attacks pose in modern ICS. We will introduce the current landscape of side-channel threats that can target processors found in ICS, the potentially vulnerable points for information extraction across an ICS system stack as well as the nature of the information itself, and discuss viable countermeasures.