Identifying CIP-centric Attacks in CPS
Praneeta K. Maganti, Rajib Ranjan Maiti, Sridhar Adepu · 2025
In this paper, we present our efforts to address the problem of efficiently addressing cyber attacks on an operational CPS by quarantining the network traffic. We have considered network traffic containing packets of industrial protocols, like ENIP/CIP, as a representative of a real-world CPS assuming that an attacker can launch cyber attacks via these protocols. Our approach involves deep analysis and inspection of the protocol standard and its implementation, including its header and payload, of ENIP/CIP in SWaT (an operational CPS testbed) as a case study. Intuitively, a cyber attack targeting a specific set of sensors or actuators in a CPS when launched via an industrial protocol by a remote attacker can leave certain traits that can lead to construct a set of signatures so that a similar set of future attacks can be efficiently addressed by a security operation center, e.g., detecting attacks at the routers much before reaching the actual target components. In our case study, we have first discovered the exact ENIP/CIP packets that carry the payloads of a complex attack, called "disrupt sensor and actuators", on SWaT and then identified the precise signatures in the payload of these packets. We have transformed these signatures into a set of rules in Suricata NIDS and show that the alert logs in this NIDS have zero false positives and false negatives.