Recovering Process Variables from Industrial Network Traffic via Search-Based Optimization
Chuan Sheng, Shan Jiang, Jianming Zhao, Yu Yao
摘要
Process variables (PVs) provide the process evidence needed for process-aware security monitoring in industrial cyber-physical systems (CPSs). However, existing supervisory infrastructures expose only the subset of PV values recorded by historians, leaving many additional runtime PV values unobserved. To address this incomplete process visibility, we study the problem of recovering PV fields and their semantics directly from raw industrial network traffic through protocol reverse engineering (PRE). In this setting, existing PRE methods face two practical challenges: PV-carrying communication is mixed with heterogeneous runtime traffic, and PV-carrying payloads are often long and deployment-specific. Mixed runtime traffic obscures the PV-carrying communication paths, while long payloads create a vast segmentation space in which early segmentation errors can propagate and corrupt the recovery of later fields under sequential inference. In this paper, we formulate the recovery of PV fields from raw network traffic as a search-based optimization problem. Our key insight is that non-sequentially identifying correct segmentations in such a vast segmentation space can be cast as an optimization problem and addressed by searching for near-optimal solutions. We propose PVParser to approach this goal. PVParser first reduces the search space by identifying the PV-carrying payloads from network traffic via a periodic pattern detection mechanism. It then employs a modified Monte Carlo Tree Search to explore near-optimal segmentations, reducing error propagation from incorrect early boundary decisions. Experiments on three representative industrial CPS datasets demonstrate that PV-Parser achieves high accuracy and F1-score in PV-carrying payload localization and PV field inference, outperforming six state-of-theart PRE approaches by a significant margin. We further demonstrate that recovering missing process visibility can strengthen downstream attack detection in process-aware security monitoring.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper16
- Limiting the Impact of Stealthy Attacks on Industrial Control SystemsDavid I. Urbina, Jairo Alonso Giraldo, Alvaro A. Cárdenas, Nils Ole Tippenhauer 等CCS 2016 · 被引用 351 次
- Truth Will Out: Departure-Based Process-Level Detection of Stealthy Attacks on Control SystemsWissam Aoudi, Mikel Iturbe, Magnus AlmgrenCCS 2018 · 被引用 110 次
- Conformal Autoregressive Generation: Beam Search with Coverage GuaranteesNicolas Deutschmann, Marvin Alberts, María Rodríguez MartínezAAAI 2024 · 被引用 21 次
- Reverse Engineering Industrial Protocols Driven By Control FieldsZhen Qin, Zeyu Yang, Yangyang Geng, Xin Che 等INFOCOM 2024 · 被引用 17 次
- SAIN: Improving ICS Attack Detection Sensitivity via State-Aware InvariantsSyed Ghazanfar Abbas, Muslum Ozgur Ozmen, Abdulellah Alsaheel, Arslan Khan 等USENIX Security 2024 · 被引用 9 次
相关 Paper
- NetPlier: Probabilistic Network Protocol Reverse Engineering from Message TracesYapeng Ye, Zhuo Zhang, Fei Wang, Xiangyu Zhang 等NDSS 2021
- ICEPRE: ICS Protocol Reverse Engineering via Data-Driven Concolic ExecutionYibo Qu, Dongliang Fang, Zhen Wang, Jiaxing Cheng 等ISSTA 2025 · 被引用 2 次
- ICSREF: A Framework for Automated Reverse Engineering of Industrial Control Systems BinariesAnastasis Keliris, Michail ManiatakosNDSS 2019 · 被引用 90 次
- Breaking the Traffic Barrier: Unveiling Multi-Format of Protocols via Autonomous Program ExplorationDingzhao Xue, Yibo Qu, Bowen Jiang, Xin Chen 等ASE 2025
- Real-Time Attack-Recovery for Cyber-Physical Systems Using Linear ApproximationsLin Zhang, Xin Chen, Fanxin Kong, Alvaro A. CárdenasRTSS 2020 · 被引用 59 次
