Detection of Vulnerabilities in the Perimeter of the ICS Network Infrastructure Using TCP/IP Protocols
Aleksandr M. Boger, Alexander N. Sokolov · 2023
The use of vulnerability scanners, as a rule, is aimed at finding vulnerabilities in the network infrastructure of industrial networks for their subsequent elimination. In automated mode, scanners implement several targeted malicious actions to evaluate the response of protection systems. As a rule, common scanners are aimed at checking protection against effective attacking influences, while checking for protection against simple but working attacks is not carried out. The aim of the study is to develop a tool for scanning vulnerabilities in the ICS network infrastructure that implements "simple" attacks. The tool presented in the work generates 4 groups of influences using standard means of network exchange via TCP/IP protocols. The results of experiments on a laboratory stand showed that a specialized industrial network protection tool could not detect some "simple" malicious effects. This indicates the need to protect the network infrastructure of APCS from "simple" malicious influences when building information security systems.