首页> 外文会议>IFIP WG 11.9 International Conference on Digital Forensics >A FORENSIC LOGGING SYSTEM FOR SIEMENS PROGRAMMABLE LOGIC CONTROLLERS
【24h】

A FORENSIC LOGGING SYSTEM FOR SIEMENS PROGRAMMABLE LOGIC CONTROLLERS

机译:西门子可编程逻辑控制器的法务记录系统

获取原文

摘要

Critical infrastructure assets are monitored and managed by industrial control systems. In recent years, these systems have evolved to adopt common networking standards that expose them to cyber attacks. Since programmable logic controllers are core components of industrial control systems, forensic examinations of these devices are vital during responses to security incidents. However, programmable logic controller forensics is a challenging task because of the lack of effective logging systems. This chapter describes the design and implementation of a novel programmable logic controller logging system. Several tools are available for generating programmable logic controller audit logs; these tools monitor and record the values of programmable logic controller memory variables for diagnostic purposes. However, the logged information is inadequate for forensic investigations. To address this limitation, the logging system extracts data from Siemens S7 communications protocol traffic for forensic purposes. The extracted data is saved in an audit log file in an easy-to-read format that enables a forensic investigator to efficiently examine the activity of a programmable logic controller.
机译:关键基础设施资产由工业控制系统监控和管理。近年来,这些系统已发展为采用使它们容易受到网络攻击的通用网络标准。由于可编程逻辑控制器是工业控制系统的核心组件,因此在响应安全事件时,对这些设备进行法医检查至关重要。然而,由于缺乏有效的记录系统,可编程逻辑控制器取证是一项具有挑战性的任务。本章描述了新型可编程逻辑控制器日志记录系统的设计和实现。有几种工具可用于生成可编程逻辑控制器审核日志。这些工具监视并记录可编程逻辑控制器存储器变量的值以用于诊断目的。但是,记录的信息不足以进行法医调查。为了解决此限制,日志记录系统从西门子S7通信协议流量中提取数据以进行取证。提取的数据以易于阅读的格式保存在审核日志文件中,使法医研究人员可以有效地检查可编程逻辑控制器的活动。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号