Scaphy: Detecting Modern ICS Attacks by Correlating Behaviors in SCADA and PHYsical
Moses Ike, Kandy Phan, Keaton Sadoski, Romuald Valme, Wenke Lee
摘要
Modern Industrial Control Systems (ICS) attacks evade existing tools by using knowledge of ICS processes to blend their activities with benign Supervisory Control and Data Acquisition (SCADA) operation, causing physical world damages. We present Scaphy to detect ICS attacks in SCADA by leveraging the unique execution phases of SCADA to identify the limited set of legitimate behaviors to control the physical world in different phases, which differentiates from attacker’s activities. For example, it is typical for SCADA to setup ICS device objects during initialization, but anomalous during process-control. To extract unique behaviors of SCADA execution phases, Scaphy first leverages open ICS conventions to generate a novel physical process dependency and impact graph (PDIG) to identify disruptive physical states. Scaphy then uses PDIG to inform a physical process-aware dynamic analysis, whereby code paths of SCADA process-control execution is induced to reveal API call behaviors unique to legitimate process-control phases. Using this established behavior, Scaphy selectively monitors attacker’s physical world-targeted activities that violates legitimate process-control behaviors. We evaluated Scaphy at a U.S. national lab ICS testbed environment. Using diverse ICS deployment scenarios and attacks across 4 ICS industries, Scaphy achieved 95% accuracy & 3.5% false positives (FP), compared to 47.5% accuracy and 25% FP of existing work. We analyze Scaphy’s resilience to futuristic attacks where attacker knows our approach.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper10
- QSYM : A Practical Concolic Execution Engine Tailored for Hybrid FuzzingInsu Yun, Sangho Lee, Meng Xu, Yeongjin Jang 等USENIX Security 2018 · 被引用 537 次
- Limiting the Impact of Stealthy Attacks on Industrial Control SystemsDavid I. Urbina, Jairo Alonso Giraldo, Alvaro A. Cárdenas, Nils Ole Tippenhauer 等CCS 2016 · 被引用 351 次
- BlackIoT: IoT Botnet of High Wattage Devices Can Disrupt the Power GridSaleh Soltan, Prateek Mittal, H. Vincent PoorUSENIX Security 2018 · 被引用 348 次
- Hey, My Malware Knows Physics! Attacking PLCs with Physical Model Aware RootkitLuis Garcia, Ferdinand Brasser, Mehmet Hazar Cintuglu, Ahmad-Reza Sadeghi 等NDSS 2017 · 被引用 205 次
- Truth Will Out: Departure-Based Process-Level Detection of Stealthy Attacks on Control SystemsWissam Aoudi, Mikel Iturbe, Magnus AlmgrenCCS 2018 · 被引用 110 次
相关 Paper
- ICSREF: A Framework for Automated Reverse Engineering of Industrial Control Systems BinariesAnastasis Keliris, Michail ManiatakosNDSS 2019 · 被引用 90 次
- Fuzzing the Physical Space: Physics-Aware Testing of Black-Box Industrial Control SystemsBurak Sahin, David Oygenblik, Mingxuan Yao, Yizhi Huang 等S&P 2026 · 被引用 3 次
- RuleTwin: Physics-Constrained Rule Induction for Anomaly Detection in Industrial Multivariate Time SerieJingzheng Mao, Runjie Pu, Zhen Song, Yanbin Sun 等KDD 2026
- Towards Automated Safety Vetting of PLC Code in Real-World PlantsMu Zhang, Chien-Ying Chen, Bin-Chou Kao, Yassine Qamsane 等S&P 2019 · 被引用 64 次
- A Systematic Framework to Generate Invariants for Anomaly Detection in Industrial Control SystemsCheng Feng, Venkata Reddy Palleti, Aditya Mathur, Deeph ChanaNDSS 2019 · 被引用 135 次
