Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Industrial Control”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Memory forensic analysis of a programmable logic controller in industrial control systems

In industrial control systems (ICS), programmable logic controllers (PLCs) are used to automate physical processes such as nuclear plants and power grid stations, and are often subject to cyber attacks. As in conventional IT domain, the memory analysis of the PLCs can help answer important forensic questions about the attack, such as the presence of malicious firmware, injection of modified control logic (the program running on the PLC), and manipulation of I/O devices (e.g., sensors and actuators). Unlike conventional IT domain, PLCs have heterogeneous hardware architecture, proprietary firmware and control software, making it challenging to employ a unified framework for their memory forensics. For merely extracting artifacts of forensic importance, reverse-engineering the firmware is a tedious task, and the effort needs to be repeated for every PLC model. As a community, a step-wise approach to tackle this challenge is to analyze the memory of specific PLCs, and subsequently find a generic framework applicable to all PLCs. Our work is a step forward in this direction. By following a methodology that focuses on the functional layer of PLCs instead of reverse engineering the firmware, we analyze the digital forensic artifacts available in a common PLC, Allen-Bradley ControlLogix 1756-L61. Before diving into the memory dump, we analyze the PLC control software to create a list of important artifacts that are sure to exist in the PLC memory dump. The approach employs a setup where PLC control software RSLogix-5000 is connected to the PLC, and the memory dump can be obtained as and when needed. We create test cases that sequentially highlight each category of artifacts, followed by an examination of the resultant impact on memory. After attaining the listed artifacts, we employ conventional string and known data searches to extract interesting information present in this PLC's memory. The memory analysis profile, presented as a Python library and shared with the community, can help a forensic investigator to readily extract forensic artifacts from the same model's controller. The adopted approach may help researchers in creating memory profile of other PLCs, and ultimately formulating a generic PLC memory analysis framework.

Rais, Muhammad Haris↗

A Functional Reference Architecture and Assessment Thereof for the National Ignition Facility Industrial Controls Systems

The Industrial Control System (ICS) at the National Ignition Facility (NIF) has an effective, well-established architecture based off a conventional cyclical software paradigm focused on maintainability and the identification of issues. This architecture exhibits scalability in ensuring expansions of the system conform to the existing architecture, modularity enough to allow relatively easy integrations of such expansions and works as a successful tool to introduce control system engineers new to the NIF ICS to the structure of the system at each layer. This architecture, like most software architectures, is object-oriented, lending itself to ease of understanding by control systems engineers and software engineers familiar with an object-oriented perspective. There are occasions, however, where engineers of other disciplines require insight into the functionality and structure of the ICS for the purposes of understanding fundamentally how their own system is or will be governed by the ICS, without the need for the details of operation of the ICS or the object-oriented view. For this reason, a functional architecture of the ICS could be a potent tool for communicating this insight. Even more powerful, a generalization of this proposed functional ICS architecture in the form of a National Ignition Facility and Photon Science (NIF & PS) Industrial Controls Reference Architecture could communicate this insight not just to systems governed by the ICS in the NIF proper, but across entirety of the NIF & PS Principal Associate Directorate (PAD), anywhere an instance of the ICS architecture is present, such as the approximately 40 “small labs” distributed across the directorate. Such a tool will provide an alternative means of understanding the implementation of these control systems, conducive to a larger variety of engineering and scientific disciplines.

42 ENGINEERING↗

JTAG-based PLC memory acquisition framework for industrial control systems

In industrial control systems (ICS), programmable logic controllers (PLC) are the embedded devices that directly control and monitor critical industrial infrastructure processes such as nuclear plants and power grid stations. Cyberattacks often target PLCs to sabotage a physical process. A memory forensic analysis of a suspect PLC can answer questions about an attack, including compromised firmware and manipulation of PLC control logic code and I/O devices. Given physical access to a PLC, collecting forensic information from the PLC memory at the hardware-level is risky and challenging. It may cause the PLC to crash or hang since PLCs have proprietary, legacy hardware with heterogeneous architecture. This paper addresses this research problem and proposes a novel JTAG (Joint Test Action Group)-based framework, Kyros, for reliable PLC memory acquisition. Kyros systematically creates a JTAG profile of a PLC through hardware assessment, JTAG pins identification, memory map creation, and optimizing acquisition parameters. It also facilitates the community of interest (such as ICS owners, operators, and vendors) to develop the JTAG profiles of PLCs. Further, we present a case study of Kyros implementation over Allen-Bradley 1756-A10/B to help understand the framework's application on a real-world PLC used in industry settings. The sample PLC memory dumps are shared with the research community to facilitate further research.

Rais, Muhammad Haris↗

Portable Industrial Control Systems Simulator (Final Report)

Industrial Control Systems (ICS) are more integrated than they have ever been before, but also the division between IT (Information Technology) and OT (Operational Technology) is becoming a grey area. As the integration of IT and OT occurs more often, cyber attack will also increase. Cyber attacks on Critical Infrastructure can be highly detrimental to society, notably via compromised Industrial Control Systems (ICS). Virtual and physical simulation has been used in medical fields, mathematics, architecture, aeronautics, space, and many more. Virtualization & Simulation in a lab environment is ideal because there is a need for the ability to test theories and designs is a safe and cost-effective way without risking equipment damage or, more importantly, human life. Furthermore, OT and ICS are some of the most difficult systems to use for research and development. They are either committed to operations or widely expensive to set up in a life-like environment. Virtualization and simulation will allow these otherwise accessible systems to be a test bed for the training, development, and research of SRNL customers or engineers and scientists at SRNL. This will allow the testbed to fit into a small form factor and interact with a simulator with minimum hardware components for easy transports and replication effort within the environment.

42 ENGINEERING↗

Evolution and Trends of Industrial Control System Cyber Incidents since 2017

The industrial control systems (ICSs) that manage our critical infrastructure are increasingly converging with corporate networks and the Internet as technology and businesses prioritize digital connectivity. These connections make them more vulnerable and available to malicious cyber actors who traditionally targeted the companies’ more public-facing information technology (IT) networks. This paper will review select publicly reported cyber incidents to highlight the continued and growing threat to ICS devices and operational technology (OT) environments. It will summarize the incident and when available, will provide information on the cyber actors, the vulnerabilities they exploited, and any publications the U.S. Government (USG) provided in response. Data belonging to the Department of Homeland Security (DHS) will be used to highlight quantitative trends concerning ICS incidents. This paper builds on “History of Industrial Control System Cyber Incidents” (Hemsley & Fisher 2018), a paper that highlighted select noteworthy threats and incidents to ICS systems up to 2017. This paper will similarly review select incidents occurring after the last previously reviewed incident, Triton/HatMan, December 2017, and will note ICS incident trends including IT/OT convergence and advances in cyber-threat actors’ capabilities in observed in the examined incidents.

99 GENERAL AND MISCELLANEOUS↗

Towards Provable Security in Industrial Control Systems Via Dynamic Protocol Attestation

Industrial control systems (ICSs) increasingly rely on digital technologies vulnerable to cyber attacks. Cyber attackers can infiltrate ICSs and execute malicious actions. Individually, each action seems innocuous. But taken together, they cause the system to enter an unsafe state. These attacks have resulted in dramatic consequences such as physical damage, economic loss, and environmental catastrophes. This paper introduces a methodology that restricts actions using protocols. These protocols only allow safe actions to execute. Protocols are written in a domain specific language we have embedded in an interactive theorem prover (ITP). The ITP enables formal, machine-checked proofs to ensure protocols maintain safety properties. We use dynamic attestation to ensure ICSs conform to their protocol even if an adversary compromises a component. Since protocol conformance prevents unsafe actions, the previously mentioned cyber attacks become impossible. We demonstrate the effectiveness of our methodology using an example from the Fischertechnik Industry 4.0 platform. We measure dynamic attestation's impact on latency and throughput. Our approach is a starting point for studying how to combine formal methods and protocol design to thwart attacks intended to cripple ICSs.

97 MATHEMATICS AND COMPUTING↗

Virtualizing Industrial Control Networks for Cyber Resilience Experiments

Industrial control systems (ICS) networks are undergoing constant shifts to accommodate new security measures. It is challenging to test varying network configurations and security tools with physical systems as they typically include large, expensive equipment. Not only this, but researchers often do not have access to this type of equipment for development of new security tools and techniques. As a solution to these issues, this work presents a set of tools for utilizing GNS3 and Docker as a virtual ICS network. Additionally, the virtual network can be attached to physical devices including network switches, hardware simulations, and intelligent electronic devices (IEDs). Two case studies showcase a relatively complex automatically generated network and an attack on a simple ICS network with an example mitigation.

42 ENGINEERING↗

Design Choices in Anomaly Detection for Industrial Control Systems: Insights from Gas Pipeline Data

Industrial control systems (ICS) remain vulnerable to increasingly sophisticated cyberattacks, yet evaluating anomaly detection models in these environments is challenging due to temporal dependencies, missing-not-at-random patterns, and extremely imbalanced datasets. These factors make common practices—especially random data splits and naïve imputation—prone to severe temporal leakage, which can inflate reported performance and obscure real-world limitations. In this work, we systematically examine classical machine learning models, temporal deep learning architecture, and tensor-decomposition–based methods on a gas-pipeline dataset using a fully temporally separated evaluation pipeline designed to mimic realistic deployment conditions. Our findings show that proper temporal handling and MNAR-aware preprocessing significantly alter the relative performance of popular anomaly-detection methods, providing practical guidance for designing reliable, leakage-resistant ICS intrusion-detection systems.

97 MATHEMATICS AND COMPUTING↗

The Role of Timing in Industrial Control Systems: A Primer

Accurate and synchronized time is an important dependency within an industrial control system. Manipulation or degradation of timing can result in varying impacts based on the critical infrastructure sector. As control systems continue to be digitized and automated, they require more precise timing elements which increases the potential impact of a cyber-attack on timing elements.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Industrial control system device classification using network traffic features and neural network embeddings

Characterization of modern cyber–physical Industrial Control System (ICS) devices is critical to the evaluation of their security posture and an understanding of the underlying industrial processes with which they interact. In this work, we address two related ICS device identification tasks: (1) separating ICS from non-ICS devices and (2) identifying specific ICS device types. We propose two distinct methods (one based on the existing IP2Vec method, and a novel traffic-features-based method) for achieving the first task. For transferability of the first task between two datasets, the traffic-features-based method performs significantly better (75% overall accuracy) compared to IP2Vec (22.5% overall accuracy). We further propose a novel method called DNP2Vec to address the second task. DNP2Vec is evaluated on two different datasets and achieves perfect multi-class classification accuracy (100%) for both datasets.

42 ENGINEERING↗

Device Classification for Industrial Control Systems Using Predicted Traffic Features

To achieve a secure interconnected Industrial Control System (ICS) architecture, security practitioners depend on accurate identification of network host behavior. However, accurate machine learning based host identification methods depends on the availability of significant quantities of network traffic data, which can be difficult to obtain due to system constraints such as network security, data confidentiality, and physical location. In this work, we propose a network traffic feature prediction method based on a generative model, which achieves high host identification accuracy. Furthermore, we develop a joint training algorithm to improve host identification performance compared to separate training of the generative model and the classifier responsible for host identification.

97 MATHEMATICS AND COMPUTING↗

A Systems Engineering Analysis of National Ignition Facility Industrial Controls Systems and Safety Interlock Systems Remote Input/Output Networking Migration from ControlNet to EtherNet/IP

The ControlNet industrial communications protocol and modules used in the Industrial Control System (ICS) and Safety Interlock System (SIS) at the National Ignition Facility (NIF) are no longer necessary and the ICS and SIS would be better served by migrating the communications structure to use EtherNet/Industrial Protocol (IP) and EtherNet bridge modules instead. By the admission of the vendor of ControlNet hardware, Rockwell Automation, in literature by Bill Petro [1], “Moving forward, customers will be able to optimize their asset utilization better using EtherNet/IP protocol than with ControlNet.” The NIF is one of the key elements of the Inertial Confinement Fusion (ICF) program at Lawrence Livermore National Laboratory (LLNL), a federally funded research and development center (FFRDC). The NIF contains the systems and provides the operational capacity to perform ICF, high energy density (HED), and discovery science experiments utilizing 192 individual beamlines, a host of diagnostics, and all the industrial systems required to facilitate these beamlines and diagnostics. The industrial systems are governed by the ICS and SIS, with the ICS providing control and the SIS providing monitoring and permissives. Construction on the NIF began in 1997 and was certified complete in 2009 and, as a result, the ICS and SIS were developed during this time using the tools that were available then. This includes the communications structure and protocols for these systems, much of which was, and still is, ControlNet. ControlNet, particularly during the time that the ICS and SIS were being built, has several attractive features. ControlNet hardware is exclusive to Rockwell Automation, which was the automation hardware chosen for the ICS and SIS. One feature that could be considered an advantage or a disadvantage depending on the communication needs of the system is that ControlNet also utilizes no active network components, excluding repeaters which are not always necessary. According to the architect of the ICS system at the NIF, Gordon Lau, one of the most attractive features of the ControlNet protocol during development of the ICS and SIS was that it is deterministic, providing timing of data transfer that is executed exactly as it is defined by the developer.

42 ENGINEERING↗

Evaluating Named Data Networking for Industrial Control System [Slides]

Current proposed work is: See if the inherent security that comes with Named Networking (NDN) can be applied to Industrial Control Systems; and, Every packet is required to be cryptographically signed which makes every single piece of data communicated in the system secure and authenticated.

42 ENGINEERING↗

Strengthening Cybersecurity for Industrial Control Systems: Innovations in Protecting PLC-Based Infrastructure

In this paper, we propose two new approaches aimed at enhancing the security of industrial control systems (ICS) that utilize programmable logic controllers (PLCs) for the control of critical processes. The first approach involves the addition of a unique digital watermark to the PWM control that adjusts the motor speed to control the critical process. This enables efficient detection and identification of any unauthorized modifications to the sensor signals responsible for controlling the plant. The second approach focuses on monitoring the input current (i.e power) drawn by the PLC during the execution of critical process control tasks. Malicious intrusions to change the PLC parameters and/or unauthorized firmware updates can be rapidly detected. Both approaches demonstrate a substantial improvement in the security of ICS, effectively safeguarding against potential cyber-attacks. Experimental results from a laboratory scale water tank level controlled via PLC showcases rapid intrusion detection capabilities.

Huang, Peng-Hao↗

Toward Common Weakness Enumerations in Industrial Control Systems

Here, the storyline of MITRE’s common weakness enumeration framework illustrates how the security and privacy technical community can collaborate/cooperate with policy makers to advance policy, giving it specifics and filling gaps of technical knowledge to improve security and resilience of critical infrastructure.

42 ENGINEERING↗