Exposed Infrastructures: Discovery, Attacks and Remediation of Insecure ICS Remote Management Devices
Takayuki Sasaki, Akira Fujita, Carlos Hernandez Gañán, Michel van Eeten, Katsunari Yoshioka, Tsutomu Matsumoto
Abstract
Geographically distributed infrastructures, such as buildings, dams, and solar power plants, are commonly maintained via Internet-connected remote management devices. Previous studies on detecting and securing industrial control systems (ICS) have overlooked these remote management devices, as they do not expose ICS-specific services like Modbus and BACnet and thus do not show up in Internet-wide scans for such services. In this paper, we implement and validate a discovery method for these devices via their Web User Interface (WebUI) and detect 890 devices in Japan alone. We also show that many of these devices are highly insecure. Many allow access to the status or even the control over industrial systems without proper authentication. Taking a closer look at three prevalent remote management devices, we discovered 13 0-day vulnerabilities, several of which were rated as medium or high severity. They have been responsibly disclosed to the manufacturers. By using honeypots that imitate these systems, we show that over time, only a small number of attackers enter these systems, but some do change critical parameters. Attackers appear to interact more with the system when more facility information is displayed on the WebUI. Finally, we notified operators of 317 vulnerable remote management devices by email and telephone. We reached 212 persons in charge of the devices and received confirmation that our method had correctly identified the device. 50% of the persons in charge of the devices stated that they mitigated or will mitigate the problem. We confirmed their actions via a followup scan for vulnerable devices and found that measures were taken for 58% of the devices when we could reach the persons in charge of the device.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers11
- SoK: Security of Programmable Logic ControllersEfrén López-Morales, Ulysse Planta, Carlos E. Rubio-Medrano, Ali Abbasi et al.USENIX Security 2024 · 10 citations
- Release the Hounds! Automated Inference and Empirical Security Evaluation of Field-Deployed PLCs Using Active Network DataRyan Pickren, Animesh Chhotaray, Frank Li, Saman A. Zonouz et al.CCS 2024 · 5 citations
- Revealing the Black Box of Device Search Engine: Scanning Assets, Strategies, and Ethical ConsiderationMengying Wu, Geng Hong, Jinsong Chen, Qi Liu et al.NDSS 2025
- Compromising Industrial Processes using Web-Based Programmable Logic Controller MalwareRyan Pickren, Tohid Shekari, Saman A. Zonouz, Raheem BeyahNDSS 2024
- Grid Trouble in Paradise: Uncovering Vulnerable Distributed Energy Resources and Their Grid-Level RisksAnna Raymaker, Samuel Talkington, Zeezoo Ryu, Richard Asiamah et al.CCS 2026
Related papers
- Am I Infected? Lessons from Operating a Large-Scale IoT Security Diagnostic ServiceTakayuki Sasaki, Tomoya Inazawa, Youhei Yamaguchi, Simon Parkin et al.USENIX Security 2025
- Who Left the Door Open? Investigating the Causes of Exposed IoT Devices in an Academic NetworkTakayuki Sasaki, Takaya Noma, Yudai Morii, Toshiya Shimura et al.S&P 2024 · 3 citations
- ChargePrint: A Framework for Internet-Scale Discovery and Security Analysis of EV Charging Management SystemsTony Nasr, Sadegh Torabi, Elias Bou-Harb, Claude Fachkha et al.NDSS 2023
- Responsible Disclosure is a Two-Way Street: Empirically Measuring the Responsible Disclosure Contract in the Firmware EcosystemHui Jun Tay, Souradip Nath, Arvind S. Raj, Abhay Bhat et al.S&P 2026
- Game of Hide-and-Seek: Exposing Hidden Interfaces in Embedded Web Applications of IoT DevicesWei Xie, Jiongyi Chen, Zhenhua Wang, Chao Feng et al.WWW 2022 · 26 citations
