Compromising Industrial Processes using Web-Based Programmable Logic Controller Malware
Ryan Pickren, Tohid Shekari, Saman A. Zonouz, Raheem Beyah
Abstract
—We present a novel approach to developing programmable logic controller (PLC) malware that proves to be more flexible, resilient, and impactful than current strategies. While previous attacks on PLCs infect either the control logic or firmware portions of PLC computation, our proposed malware exclusively infects the web application hosted by the emerging embedded webservers within the PLCs. This strategy allows the malware to stealthily attack the underlying real-world machinery using the legitimate web application program interfaces (APIs) exposed by the admin portal website. Such attacks include falsifying sensor readings, disabling safety alarms, and manipulating physical actuators. Furthermore, this approach has significant advantages over existing PLC malware techniques (control logic and firmware) such as platform independence, ease-of-deployment, and higher levels of persistence. Our research shows that the emergence of web technology in industrial control environments has introduced new security concerns that are not present in the IT domain or consumer IoT devices. Depending on the industrial process being controlled by the PLC, our attack can potentially cause catastrophic incidents or even loss of life. We verified these claims by performing a Stuxnet-style attack using a prototype implementation of this malware on a widely-used PLC model by exploiting zero-day vulnerabilities that we discovered during our research 1 . Our investigation reveals that every major PLC vendor (80% of global market share [1]) produces a PLC that is vulnerable to our proposed attack vector. Lastly, we discuss potential countermeasures and mitigations.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 284a4dc0-915d-472a-bf9a-6d6472bb62aeCited by top-tier papers2
- SoK: Security of Programmable Logic ControllersEfrén López-Morales, Ulysse Planta, Carlos E. Rubio-Medrano, Ali Abbasi et al.USENIX Security 2024 · 10 citations
- Release the Hounds! Automated Inference and Empirical Security Evaluation of Field-Deployed PLCs Using Active Network DataRyan Pickren, Animesh Chhotaray, Frank Li, Saman A. Zonouz et al.CCS 2024 · 5 citations
Builds on3
- Hey, My Malware Knows Physics! Attacking PLCs with Physical Model Aware RootkitLuis Garcia, Ferdinand Brasser, Mehmet Hazar Cintuglu, Ahmad-Reza Sadeghi et al.NDSS 2017 · 205 citations
- Exposed Infrastructures: Discovery, Attacks and Remediation of Insecure ICS Remote Management DevicesTakayuki Sasaki, Akira Fujita, Carlos Hernandez Gañán, Michel van Eeten et al.S&P 2022 · 41 citations
- Wobfuscator: Obfuscating JavaScript Malware via Opportunistic Translation to WebAssemblyAlan Romano, Daniel Lehmann, Michael Pradel, Weihang WangS&P 2022 · 40 citations
Related papers
- A Wily Hare Has Three Havens: Combating Programmable Logic Controller Attacks via Virtualization RedundancyWenjie Wang, Yazhe Wang, Lei RenFSE 2026
- ICSREF: A Framework for Automated Reverse Engineering of Industrial Control Systems BinariesAnastasis Keliris, Michail ManiatakosNDSS 2019 · 90 citations
- HoneyPLC: A Next-Generation Honeypot for Industrial Control SystemsEfrén López-Morales, Carlos E. Rubio-Medrano, Adam Doupé, Yan Shoshitaishvili et al.CCS 2020 · 82 citations
- ICSFuzz: Manipulating I/Os and Repurposing Binary Code to Enable Instrumented Fuzzing in ICS Control ApplicationsDimitrios Tychalas, Hadjer Benkraouda, Michail ManiatakosUSENIX Security 2021 · 42 citations
- Game of Hide-and-Seek: Exposing Hidden Interfaces in Embedded Web Applications of IoT DevicesWei Xie, Jiongyi Chen, Zhenhua Wang, Chao Feng et al.WWW 2022 · 26 citations
