Release the Hounds! Automated Inference and Empirical Security Evaluation of Field-Deployed PLCs Using Active Network Data
Ryan Pickren, Animesh Chhotaray, Frank Li, Saman A. Zonouz, Raheem Beyah
Abstract
Surveying field-deployed Industrial Control System (ICS) equipment has numerous security applications, including attack-surface management and measuring the adoption of vulnerability patches. However, discovering real-world devices using massive Internetscale scan datasets is tedious and error-prone. We introduce PL-CHound, a novel ICS asset discovery solution designed to automatically reveal elusive ICS devices hiding in network data collected by Internet-scale scanners such as Censys or Shodan. Our solution systematically uncovers indirect evidence of controllers using subtle network-based indicators and temporally-resistant signatures that are often overlooked in prior work. We present PLCHound's architecture, experimentally verify its accuracy, and explore the security advantages of enhanced device discovery. We also use PL-CHound to perform the largest comprehensive examination of the publicly-reachable population of ICS devices by popular vendors. Our results reveal that the industry-accepted estimations and latest published papers undercount the true number of public devices by up to 37x. We also find that 95.88% of devices expose protocols that cause them to be remotely vulnerable to recent critical CVEs. CCS Concepts • Networks → Network protocols; • Security and privacy → Network security; • General and reference → Measurement.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e2941755-937f-49ed-9b52-98752c981ab3Cited by top-tier papers2
- Grid Trouble in Paradise: Uncovering Vulnerable Distributed Energy Resources and Their Grid-Level RisksAnna Raymaker, Samuel Talkington, Zeezoo Ryu, Richard Asiamah et al.CCS 2026
- Batten the Hatches: Cybersecurity with Military MarinersRyan Von Brock, Anna Raymaker, Animesh Chhotaray, Frank Li et al.CCS 2026
Builds on4
- Thou Shalt Not Depend on Me: Analysing the Use of Outdated JavaScript Libraries on the WebTobias Lauinger, Abdelberi Chaabane, Sajjad Arshad, William Robertson et al.NDSS 2017 · 183 citations
- You've Got Vulnerability: Exploring Effective Vulnerability NotificationsFrank Li, Zakir Durumeric, Jakub Czyz, Mohammad Karami et al.USENIX Security 2016 · 149 citations
- Exposed Infrastructures: Discovery, Attacks and Remediation of Insecure ICS Remote Management DevicesTakayuki Sasaki, Akira Fujita, Carlos Hernandez Gañán, Michel van Eeten et al.S&P 2022 · 41 citations
- Compromising Industrial Processes using Web-Based Programmable Logic Controller MalwareRyan Pickren, Tohid Shekari, Saman A. Zonouz, Raheem BeyahNDSS 2024
Related papers
- Trust but Verify: An Assessment of Vulnerability Tagging ServicesSzu-Chun Huang, Harm Griffioen, Max van der Horst, Georgios Smaragdakis et al.USENIX Security 2025
- All Things Considered: An Analysis of IoT Devices on Home NetworksDeepak Kumar, Kelly Shen, Benton Case, Deepali Garg et al.USENIX Security 2019 · 189 citations
- Landing Reinforcement Learning onto Smart Scanning of The Internet of ThingsJian Qu, Xiaobo Ma, Wenmao Liu, Hongqing Sang et al.INFOCOM 2022 · 9 citations
- Patchy Performance? Uncovering the Vulnerability Management Practices of IoT-Centric VendorsSandra Rivera Pérez, Michel van Eeten, Carlos Hernandez GañánS&P 2024 · 3 citations
- Revealing the Black Box of Device Search Engine: Scanning Assets, Strategies, and Ethical ConsiderationMengying Wu, Geng Hong, Jinsong Chen, Qi Liu et al.NDSS 2025
