Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “industrial control systems”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

JTAG-based PLC memory acquisition framework for industrial control systems

In industrial control systems (ICS), programmable logic controllers (PLC) are the embedded devices that directly control and monitor critical industrial infrastructure processes such as nuclear plants and power grid stations. Cyberattacks often target PLCs to sabotage a physical process. A memory forensic analysis of a suspect PLC can answer questions about an attack, including compromised firmware and manipulation of PLC control logic code and I/O devices. Given physical access to a PLC, collecting forensic information from the PLC memory at the hardware-level is risky and challenging. It may cause the PLC to crash or hang since PLCs have proprietary, legacy hardware with heterogeneous architecture. This paper addresses this research problem and proposes a novel JTAG (Joint Test Action Group)-based framework, Kyros, for reliable PLC memory acquisition. Kyros systematically creates a JTAG profile of a PLC through hardware assessment, JTAG pins identification, memory map creation, and optimizing acquisition parameters. It also facilitates the community of interest (such as ICS owners, operators, and vendors) to develop the JTAG profiles of PLCs. Further, we present a case study of Kyros implementation over Allen-Bradley 1756-A10/B to help understand the framework's application on a real-world PLC used in industry settings. The sample PLC memory dumps are shared with the research community to facilitate further research.

Rais, Muhammad Haris↗

A Functional Reference Architecture and Assessment Thereof for the National Ignition Facility Industrial Controls Systems

The Industrial Control System (ICS) at the National Ignition Facility (NIF) has an effective, well-established architecture based off a conventional cyclical software paradigm focused on maintainability and the identification of issues. This architecture exhibits scalability in ensuring expansions of the system conform to the existing architecture, modularity enough to allow relatively easy integrations of such expansions and works as a successful tool to introduce control system engineers new to the NIF ICS to the structure of the system at each layer. This architecture, like most software architectures, is object-oriented, lending itself to ease of understanding by control systems engineers and software engineers familiar with an object-oriented perspective. There are occasions, however, where engineers of other disciplines require insight into the functionality and structure of the ICS for the purposes of understanding fundamentally how their own system is or will be governed by the ICS, without the need for the details of operation of the ICS or the object-oriented view. For this reason, a functional architecture of the ICS could be a potent tool for communicating this insight. Even more powerful, a generalization of this proposed functional ICS architecture in the form of a National Ignition Facility and Photon Science (NIF & PS) Industrial Controls Reference Architecture could communicate this insight not just to systems governed by the ICS in the NIF proper, but across entirety of the NIF & PS Principal Associate Directorate (PAD), anywhere an instance of the ICS architecture is present, such as the approximately 40 “small labs” distributed across the directorate. Such a tool will provide an alternative means of understanding the implementation of these control systems, conducive to a larger variety of engineering and scientific disciplines.

42 ENGINEERING↗

Attacking the IEC-61131 Logic Engine in Programmable Logic Controllers in Industrial Control Systems

In industrial control systems (ICS), programmable logic controllers (PLCs) directly monitor and control a physical process such as nuclear power plants, gas pipelines, and water treatment. They are equipped with a control logic written in IEC-61131 languages (e.g., ladder logic and structured text) that defines how a PLC should control a physical process. A PLC's control logic is a usual target of a cyberattack to sabotage a physical process. For instance, Stuxnet targets a control logic of a Siemens S7-300 PLC to damage a nuclear facility's centrifuges. The existing attacks in the literature generally focus only on injecting malicious control logic into a PLC. This paper presents a new dimension of control logic attacks that target the control logic engine (responsible for running a control logic) of a PLC. It demonstrates that a cyberattack can disable the control logic engine successfully by exploiting inherent PLC features such as program mode and starting/stopping engine. We develop two novel case studies on control logic engine attacks by employing the MITRE ATT\&CK knowledge base on the real-world PLCs used in industry settings, i.e., 1) Schweitzer Engineering Laboratory (SEL)'s Real-Time Automation Controller (SEL-3505 RTAC) equipped with security features such as encrypted traffic and device-level access control, and 2) traditional PLCs, i.e., Schneider Electric's Modicon M221, Allen-Bradley's MicroLogix 1400 and 1100 that do not have security features. The case studies present the internals of the logic engine attacks and facilitate the ICS research community and industry to understand the attack vectors on the control logic engine. We evaluate the effectiveness of the control engine attacks on a power substation, a 4-floor elevator, and a conveyor belt to demonstrate their real-world impact of halting a physical process.

Ali qasim, Syed↗

Memory forensic analysis of a programmable logic controller in industrial control systems

In industrial control systems (ICS), programmable logic controllers (PLCs) are used to automate physical processes such as nuclear plants and power grid stations, and are often subject to cyber attacks. As in conventional IT domain, the memory analysis of the PLCs can help answer important forensic questions about the attack, such as the presence of malicious firmware, injection of modified control logic (the program running on the PLC), and manipulation of I/O devices (e.g., sensors and actuators). Unlike conventional IT domain, PLCs have heterogeneous hardware architecture, proprietary firmware and control software, making it challenging to employ a unified framework for their memory forensics. For merely extracting artifacts of forensic importance, reverse-engineering the firmware is a tedious task, and the effort needs to be repeated for every PLC model. As a community, a step-wise approach to tackle this challenge is to analyze the memory of specific PLCs, and subsequently find a generic framework applicable to all PLCs. Our work is a step forward in this direction. By following a methodology that focuses on the functional layer of PLCs instead of reverse engineering the firmware, we analyze the digital forensic artifacts available in a common PLC, Allen-Bradley ControlLogix 1756-L61. Before diving into the memory dump, we analyze the PLC control software to create a list of important artifacts that are sure to exist in the PLC memory dump. The approach employs a setup where PLC control software RSLogix-5000 is connected to the PLC, and the memory dump can be obtained as and when needed. We create test cases that sequentially highlight each category of artifacts, followed by an examination of the resultant impact on memory. After attaining the listed artifacts, we employ conventional string and known data searches to extract interesting information present in this PLC's memory. The memory analysis profile, presented as a Python library and shared with the community, can help a forensic investigator to readily extract forensic artifacts from the same model's controller. The adopted approach may help researchers in creating memory profile of other PLCs, and ultimately formulating a generic PLC memory analysis framework.

Rais, Muhammad Haris↗

Smart Semi-Supervised Accumulation of Large Repositories for Industrial Control Systems Device Information

Industrial Control Systems device manufacturers frequently add new features to improve their product performance. Oftentimes, these changes are mainly vendor-driven initiatives, and customers may not be aware of the full impact of these new capabilities on their cybersecurity posture. In the energy sector, this can lead to considerable dissonance between vendor-provided cybersecurity claims and a customer’s responsibility for Operation Technology cybersecurity compliance. Thus, the resulting dynamic verification burden is shifted towards the customer and may pose a significant cybersecurity risk to the energy sector landscape. We found that there is very limited research into cybersecurity auditing for Operational Technology. However, a solution is needed for vetting the vendor-supplied feature claims and their adherence to cybersecurity requirements and standards. We are presently engaged in an effort to develop such a system. This paper demonstrates one vital aspect of this effort in proposing an end-to-end framework to accumulate a large repository of ICS device information for this vetting system, curate the dataset, and conduct extensive processing. This framework is designed to use web scraping, data analytics and Natural Language Processing (NLP) techniques to identify vendor websites, automate the collection of website-accessible documents and automatically derive metadata from them for identification of product documents relevant to the repository. We have found that this automated approach to vendor identification, document extraction into a product repository, and NLP pre-processing is unique and has not been previously presented in the literature. The preliminary work shows that this is feasible and can produce reliable results with minimum supervision. Future work will be built upon this foundation in order to achieve semi-supervised vetting of device technical information – a vital capability for ensuring that vendor-claimed device cybersecurity capabilities match industry requirements.

Ameri, Kimia↗

Portable Industrial Control Systems Simulator (Final Report)

Industrial Control Systems (ICS) are more integrated than they have ever been before, but also the division between IT (Information Technology) and OT (Operational Technology) is becoming a grey area. As the integration of IT and OT occurs more often, cyber attack will also increase. Cyber attacks on Critical Infrastructure can be highly detrimental to society, notably via compromised Industrial Control Systems (ICS). Virtual and physical simulation has been used in medical fields, mathematics, architecture, aeronautics, space, and many more. Virtualization & Simulation in a lab environment is ideal because there is a need for the ability to test theories and designs is a safe and cost-effective way without risking equipment damage or, more importantly, human life. Furthermore, OT and ICS are some of the most difficult systems to use for research and development. They are either committed to operations or widely expensive to set up in a life-like environment. Virtualization and simulation will allow these otherwise accessible systems to be a test bed for the training, development, and research of SRNL customers or engineers and scientists at SRNL. This will allow the testbed to fit into a small form factor and interact with a simulator with minimum hardware components for easy transports and replication effort within the environment.

42 ENGINEERING↗

Industrial Control Systems Network Protocol Parsers

Industrial Control Systems protocol parsers plugins for the Zeek network security monitoring framework. Currently we have four fully developed protocol parsers but we plan on adding more in the future. The protocol parsers we currently have developed are for BACnet, DNP3, Ethernet/IP, and Modbus.

Rasmussen, BrettD↗

Evolution and Trends of Industrial Control System Cyber Incidents since 2017

The industrial control systems (ICSs) that manage our critical infrastructure are increasingly converging with corporate networks and the Internet as technology and businesses prioritize digital connectivity. These connections make them more vulnerable and available to malicious cyber actors who traditionally targeted the companies’ more public-facing information technology (IT) networks. This paper will review select publicly reported cyber incidents to highlight the continued and growing threat to ICS devices and operational technology (OT) environments. It will summarize the incident and when available, will provide information on the cyber actors, the vulnerabilities they exploited, and any publications the U.S. Government (USG) provided in response. Data belonging to the Department of Homeland Security (DHS) will be used to highlight quantitative trends concerning ICS incidents. This paper builds on “History of Industrial Control System Cyber Incidents” (Hemsley & Fisher 2018), a paper that highlighted select noteworthy threats and incidents to ICS systems up to 2017. This paper will similarly review select incidents occurring after the last previously reviewed incident, Triton/HatMan, December 2017, and will note ICS incident trends including IT/OT convergence and advances in cyber-threat actors’ capabilities in observed in the examined incidents.

99 GENERAL AND MISCELLANEOUS↗

A Systems Engineering Analysis of National Ignition Facility Industrial Controls Systems and Safety Interlock Systems Remote Input/Output Networking Migration from ControlNet to EtherNet/IP

The ControlNet industrial communications protocol and modules used in the Industrial Control System (ICS) and Safety Interlock System (SIS) at the National Ignition Facility (NIF) are no longer necessary and the ICS and SIS would be better served by migrating the communications structure to use EtherNet/Industrial Protocol (IP) and EtherNet bridge modules instead. By the admission of the vendor of ControlNet hardware, Rockwell Automation, in literature by Bill Petro [1], “Moving forward, customers will be able to optimize their asset utilization better using EtherNet/IP protocol than with ControlNet.” The NIF is one of the key elements of the Inertial Confinement Fusion (ICF) program at Lawrence Livermore National Laboratory (LLNL), a federally funded research and development center (FFRDC). The NIF contains the systems and provides the operational capacity to perform ICF, high energy density (HED), and discovery science experiments utilizing 192 individual beamlines, a host of diagnostics, and all the industrial systems required to facilitate these beamlines and diagnostics. The industrial systems are governed by the ICS and SIS, with the ICS providing control and the SIS providing monitoring and permissives. Construction on the NIF began in 1997 and was certified complete in 2009 and, as a result, the ICS and SIS were developed during this time using the tools that were available then. This includes the communications structure and protocols for these systems, much of which was, and still is, ControlNet. ControlNet, particularly during the time that the ICS and SIS were being built, has several attractive features. ControlNet hardware is exclusive to Rockwell Automation, which was the automation hardware chosen for the ICS and SIS. One feature that could be considered an advantage or a disadvantage depending on the communication needs of the system is that ControlNet also utilizes no active network components, excluding repeaters which are not always necessary. According to the architect of the ICS system at the NIF, Gordon Lau, one of the most attractive features of the ControlNet protocol during development of the ICS and SIS was that it is deterministic, providing timing of data transfer that is executed exactly as it is defined by the developer.

42 ENGINEERING↗

Towards Provable Security in Industrial Control Systems Via Dynamic Protocol Attestation

Industrial control systems (ICSs) increasingly rely on digital technologies vulnerable to cyber attacks. Cyber attackers can infiltrate ICSs and execute malicious actions. Individually, each action seems innocuous. But taken together, they cause the system to enter an unsafe state. These attacks have resulted in dramatic consequences such as physical damage, economic loss, and environmental catastrophes. This paper introduces a methodology that restricts actions using protocols. These protocols only allow safe actions to execute. Protocols are written in a domain specific language we have embedded in an interactive theorem prover (ITP). The ITP enables formal, machine-checked proofs to ensure protocols maintain safety properties. We use dynamic attestation to ensure ICSs conform to their protocol even if an adversary compromises a component. Since protocol conformance prevents unsafe actions, the previously mentioned cyber attacks become impossible. We demonstrate the effectiveness of our methodology using an example from the Fischertechnik Industry 4.0 platform. We measure dynamic attestation's impact on latency and throughput. Our approach is a starting point for studying how to combine formal methods and protocol design to thwart attacks intended to cripple ICSs.

97 MATHEMATICS AND COMPUTING↗

Design Choices in Anomaly Detection for Industrial Control Systems: Insights from Gas Pipeline Data

Industrial control systems (ICS) remain vulnerable to increasingly sophisticated cyberattacks, yet evaluating anomaly detection models in these environments is challenging due to temporal dependencies, missing-not-at-random patterns, and extremely imbalanced datasets. These factors make common practices—especially random data splits and naïve imputation—prone to severe temporal leakage, which can inflate reported performance and obscure real-world limitations. In this work, we systematically examine classical machine learning models, temporal deep learning architecture, and tensor-decomposition–based methods on a gas-pipeline dataset using a fully temporally separated evaluation pipeline designed to mimic realistic deployment conditions. Our findings show that proper temporal handling and MNAR-aware preprocessing significantly alter the relative performance of popular anomaly-detection methods, providing practical guidance for designing reliable, leakage-resistant ICS intrusion-detection systems.

97 MATHEMATICS AND COMPUTING↗

International Space Agency CIO Forum Industrial Control System (ICS) and Cyber

This briefing covers Industrial Control System (ICS) best practices for enhancing cyber protection. The briefing provides a very high-level overview of best practices currently being pursued by NASA as well as by other US government agencies such as NIST and DHS ICS-CERT. All information presented in this slide deck is publicly available and no sensitive information is provided in these slides. These slides will be used to generate discussion around best practices within the international community in the area of ICS cyber protections.

Powell, Robert↗

Device Classification for Industrial Control Systems Using Predicted Traffic Features

To achieve a secure interconnected Industrial Control System (ICS) architecture, security practitioners depend on accurate identification of network host behavior. However, accurate machine learning based host identification methods depends on the availability of significant quantities of network traffic data, which can be difficult to obtain due to system constraints such as network security, data confidentiality, and physical location. In this work, we propose a network traffic feature prediction method based on a generative model, which achieves high host identification accuracy. Furthermore, we develop a joint training algorithm to improve host identification performance compared to separate training of the generative model and the classifier responsible for host identification.

97 MATHEMATICS AND COMPUTING↗

The Role of Timing in Industrial Control Systems: A Primer

Accurate and synchronized time is an important dependency within an industrial control system. Manipulation or degradation of timing can result in varying impacts based on the critical infrastructure sector. As control systems continue to be digitized and automated, they require more precise timing elements which increases the potential impact of a cyber-attack on timing elements.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Industrial control system device classification using network traffic features and neural network embeddings

Characterization of modern cyber–physical Industrial Control System (ICS) devices is critical to the evaluation of their security posture and an understanding of the underlying industrial processes with which they interact. In this work, we address two related ICS device identification tasks: (1) separating ICS from non-ICS devices and (2) identifying specific ICS device types. We propose two distinct methods (one based on the existing IP2Vec method, and a novel traffic-features-based method) for achieving the first task. For transferability of the first task between two datasets, the traffic-features-based method performs significantly better (75% overall accuracy) compared to IP2Vec (22.5% overall accuracy). We further propose a novel method called DNP2Vec to address the second task. DNP2Vec is evaluated on two different datasets and achieves perfect multi-class classification accuracy (100%) for both datasets.

42 ENGINEERING↗

ManiPIO - Manipulate Process I/O for Industrial Control Systems

The Manipulate Process Input/Output (IO) (ManiPIO) program allows users to develop custom scripts to execute Industrial Control System (ICS) manipulations. The driving development principles of ManiPIO are modularity and ease of use. Currently the program can utilize the Modbus TCP communication protocol, but its modular programming structure allows other protocols to be quickly and easily implemented. Additional functionality can be added to fit specific user needs, due to the usage of Python classes. The input configuration instructions are human readable and allow the user to create a complex series of control system manipulations.

97 MATHEMATICS AND COMPUTING↗