USENIX Security2021Top-tier venue
ICSFuzz: Manipulating I/Os and Repurposing Binary Code to Enable Instrumented Fuzzing in ICS Control Applications
Dimitrios Tychalas, Hadjer Benkraouda, Michail Maniatakos
Abstract
Industrial Control Systems (ICS) have seen a rapid proliferation in the last decade amplified by the advent of the 4th Industrial Revolution. At the same time, several notable cybersecurity incidents in industrial environments have underlined the lack of depth in security evaluation of industrial devices such as Programmable Logic Controllers (PLC). Modern PLCs are based on widely used microprocessors and deploy commodity operating systems (e.g., ARM on Linux). Thus, threats from the information technology domain can be readily ported to industrial environments. PLC application binaries in particular have never been considered as regular programs able to introduce traditional security threats, such as buffer overflows. In this work, we investigate the feasibility of exploiting PLC binaries as well as their surrounding PLC-specific environment. We examine binaries produced by all available IEC 61131-3 control system programming languages for compilation-based differences and introduced vulnerabilities. Driven by this analysis, we develop a fuzzing framework to perform security evaluation of the PLC binaries along with the host functions they interact with. Fuzzing such non-executable binaries is non-trivial, as they operate with real-time constraints and receive their inputs from peripherals. To prove the correctness of our fuzzing tool, we use a database of in-house developed binaries in addition to functional control applications collected from online repositories. We showcase the efficacy of our technique by demonstrating uncovered vulnerabilities in both control application binaries and their runtime system. Furthermore, we demonstrate an exploitation methodology for an in-house as well as a regular control binary, based on the uncovered vulnerabilities.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext db92d28b-ec03-40b3-ada2-46fed67c0233Cited by top-tier papers5
- Collapse Like A House of Cards: Hacking Building Automation System Through FuzzingYue Zhang, Zhen Ling, Michael Cash, Qiguang Zhang et al.CCS 2024 · 3 citations
- Discovering Blind-Trust Vulnerabilities in PLC Binaries via State Machine RecoveryFangzhou Dong, Arvind S. Raj, Efrén López-Morales, Siyu Liu et al.NDSS 2026 · 1 citation
- ICSPatch: Automated Vulnerability Localization and Non-Intrusive Hotpatching in Industrial Control Systems using Data Dependence GraphsPrashant Hari Narayan Rajput, Constantine Doumanidis, Michail ManiatakosUSENIX Security 2023
- ICSQuartz: Scan Cycle-Aware and Vendor-Agnostic Fuzzing for Industrial Control SystemsCorban Villa, Constantine Doumanidis, Hithem Lamri, Prashant Hari Narayan Rajput et al.NDSS 2025
- You Can't Judge a Binary by Its Header: Data-Code Separation for Non-Standard ARM Binaries Using Pseudo LabelsHadjer Benkraouda, Nirav Diwan, Gang WangS&P 2025
Builds on6
- Limiting the Impact of Stealthy Attacks on Industrial Control SystemsDavid I. Urbina, Jairo Alonso Giraldo, Alvaro A. Cárdenas, Nils Ole Tippenhauer et al.CCS 2016 · 351 citations
- FIRM-AFL: High-Throughput Greybox Fuzzing of IoT Firmware via Augmented Process EmulationYaowen Zheng, Ali Davanian, Heng Yin, Chengyu Song et al.USENIX Security 2019 · 279 citations
- Hey, My Malware Knows Physics! Attacking PLCs with Physical Model Aware RootkitLuis Garcia, Ferdinand Brasser, Mehmet Hazar Cintuglu, Ahmad-Reza Sadeghi et al.NDSS 2017 · 205 citations
- RVFuzzer: Finding Input Validation Bugs in Robotic Vehicles through Control-Guided TestingTaegyu Kim, Chung Hwan Kim, Junghwan Rhee, Fan Fei et al.USENIX Security 2019 · 92 citations
- ICSREF: A Framework for Automated Reverse Engineering of Industrial Control Systems BinariesAnastasis Keliris, Michail ManiatakosNDSS 2019 · 90 citations
Related papers
- An LLM-Driven Fuzzing Framework for Detecting Logic Instruction Bugs in PLCsJiaxing Cheng, Ming Zhou, Haining Wang, Xin Chen et al.NDSS 2026 · 3 citations
- Fuzzing the Physical Space: Physics-Aware Testing of Black-Box Industrial Control SystemsBurak Sahin, David Oygenblik, Mingxuan Yao, Yizhi Huang et al.S&P 2026 · 3 citations
- P2IM: Scalable and Hardware-independent Firmware Testing via Automatic Peripheral Interface ModelingBo Feng, Alejandro Mera, Long LuUSENIX Security 2020
- Watch Me, but Don't Touch Me! Contactless Control Flow Monitoring via Electromagnetic EmanationsYi Han, Sriharsha Etigowni, Hua Liu, Saman A. Zonouz et al.CCS 2017 · 110 citations
- PGFUZZ: Policy-Guided Fuzzing for Robotic VehiclesHyungsub Kim, Muslum Ozgur Ozmen, Antonio Bianchi, Z. Berkay Celik et al.NDSS 2021
