PLC-SEIFF: A programmable logic controller security incident forensics framework based on automatic construction of security constraints

Computers & Security(2020)

引用 9|浏览95
暂无评分
摘要
Over the past two decades, with the SCADA systems connected to corporate networks or the Internet, the programmable logic controller (PLC) have suffered a large-scale and catastrophic network attacks for the controlling and monitoring physical industrial and infrastructure processes in the industrial control networks, due to their crucial character and safe characteristic. However, the PLC‘s inferior computing power, restricted storage capacity, “scan-cycle” operating mode, and client’s violent private demand has made it challenging to find forensics framework with the capacity to depress the storage requirement and enhance practicality and robustness strikingly. In an effort to address these challenges, through the establishing the attack model against PLC in a view of the security incident forensics, this paper proposed a PLC security incident forensics framework named PLC-SEIFF. This framework implemented the automatic construction of security constraints rules from PLC control logic STL program, filtering and identifying of irrelevant incident records according by correlation analysis on the basis of multi-sources data.
更多
查看译文
关键词
PLC,Security incidents,Security constraints,Control logic program,Forensics
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要