A Survey on Programmable Logic Controller Vulnerabilities, Attacks, Detections, and Forensics
作者:Zibo Wang, Yaofang Zhang, Yilu Chen, Hongri Liu, Bailing Wang, Chonghua Wang · 发表于:Processes · 年份:2023 · DOI:10.3390/pr11030918 · 被引用次数:41 · 研究领域:Smart Grid Security and Resilience、Advanced Malware Detection Techniques、Physical Unclonable Functions (PUFs) and Hardware Security
Programmable Logic Controllers (PLCs), as specialized task-oriented embedded field devices, play a vital role in current industrial control systems (ICSs), which are composed of critical infrastructure. In order to meet increasing demands on cost-effectiveness while improving production efficiency, commercial-off-the-shelf software and hardware, and external networks such as the Internet, are integrated into the PLC-based control systems. However, it also provides opportunities for adversaries to launch malicious, targeted, and sophisticated cyberattacks. To that end, there is an urgent need to summarize ongoing work in PLC-based control systems on vulnerabilities, attacks, and security detection schemes for researchers and practitioners. Although surveys on similar topics exist, they are less involved in three key aspects, as follows: First and foremost, previous work focused more on system-level vulnerability analysis than PLC itself. Subsequently, it was not clear whether their work applied to the current systems or future ones, especially for security detection schemes. Finally, the prior surveys lacked a digital forensic research review of PLC-based control systems, which was significant for security analysis at different stages. As a result, we highlight vulnerability analysis at both a core component level and a system level, as well as attack models against availability, integrity, and confidentiality. Meanwhile, reviews of security detection schemes and digital foren...