ICSREF: A Framework for Automated Reverse Engineering of Industrial Control Systems Binaries
Anastasis Keliris, Michail Maniatakos
Abstract
The security of Industrial Control Systems (ICS) has been attracting increased attention over the past years, following the discovery of real threats targeting industrial environments. Despite this attention, automation of the reverse engineering process of ICS binaries for programmable logic controllers remains an open problem, mainly due to the use of proprietary compilers by ICS vendors. Such automation could be a double-edged sword; on the one hand it could accelerate digital forensic investigations and incident response actions, while on the other hand it could enable dynamic generation of malicious ICS payloads. In this work, we propose a structured methodology that automates the reverse engineering process for ICS binaries taking into account their unique domain-specific characteristics. We apply this methodology to develop the modular Industrial Control Systems Reverse Engineering Framework (ICSREF), and instantiate ICSREF modules for reversing binaries compiled with CODESYS, a widely used software stack and compiler for PLCs. To evaluate our framework we create a database of samples by collecting real PLC binaries from public code repositories, as well as developing binaries in-house. Our results demonstrate that ICSREF can successfully handle diverse PLC binaries from varied industry sectors, irrespective of the programming language used. Furthermore, we deploy ICSREF on a commercial smartphone which orchestrates and launches a completely automated process-aware attack against a chemical process testbed. This example of dynamic payload generation showcases how ICSREF can enable sophisticated attacks without any prior knowledge.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext bd10f586-fc79-4e02-a080-a4d8738810c8Cited by top-tier papers9
- HoneyPLC: A Next-Generation Honeypot for Industrial Control SystemsEfrén López-Morales, Carlos E. Rubio-Medrano, Adam Doupé, Yan Shoshitaishvili et al.CCS 2020 · 82 citations
- ICSFuzz: Manipulating I/Os and Repurposing Binary Code to Enable Instrumented Fuzzing in ICS Control ApplicationsDimitrios Tychalas, Hadjer Benkraouda, Michail ManiatakosUSENIX Security 2021 · 42 citations
- AntiFuzz: Impeding Fuzzing Audits of Binary ExecutablesEmre Güler, Cornelius Aschermann, Ali Abbasi, Thorsten HolzUSENIX Security 2019 · 34 citations
- A Tale of Two Industroyers: It was the Season of DarknessLuis E. Salazar, Sebastián R. Castro, Juan Lozano, Keerthi Koneru et al.S&P 2024 · 22 citations
- SoK: Security of Programmable Logic ControllersEfrén López-Morales, Ulysse Planta, Carlos E. Rubio-Medrano, Ali Abbasi et al.USENIX Security 2024 · 10 citations
Builds on3
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens et al.S&P 2016 · 1,085 citations
- Driller: Augmenting Fuzzing Through Selective Symbolic ExecutionNick Stephens, John Grosen, Christopher Salls, Andrew Dutcher et al.NDSS 2016 · 1,021 citations
- Hey, My Malware Knows Physics! Attacking PLCs with Physical Model Aware RootkitLuis Garcia, Ferdinand Brasser, Mehmet Hazar Cintuglu, Ahmad-Reza Sadeghi et al.NDSS 2017 · 205 citations
Related papers
- Reverse Engineering Industrial Protocols Driven By Control FieldsZhen Qin, Zeyu Yang, Yangyang Geng, Xin Che et al.INFOCOM 2024 · 17 citations
- CoToRu: Automatic Generation of Network Intrusion Detection Rules from CodeHeng Chuan Tan, Carmen Cheh, Binbin ChenINFOCOM 2022 · 12 citations
- SAIN: Improving ICS Attack Detection Sensitivity via State-Aware InvariantsSyed Ghazanfar Abbas, Muslum Ozgur Ozmen, Abdulellah Alsaheel, Arslan Khan et al.USENIX Security 2024 · 9 citations
- ICEPRE: ICS Protocol Reverse Engineering via Data-Driven Concolic ExecutionYibo Qu, Dongliang Fang, Zhen Wang, Jiaxing Cheng et al.ISSTA 2025 · 2 citations
- Towards Automated Safety Vetting of PLC Code in Real-World PlantsMu Zhang, Chien-Ying Chen, Bin-Chou Kao, Yassine Qamsane et al.S&P 2019 · 64 citations
