首页> 外文会议>IEEE International Symposium on Technologies for Homeland Security >Cracking a Continuous Flow Reactor: A Vulnerability Assessment for Chemical Additive Manufacturing Devices
【24h】

Cracking a Continuous Flow Reactor: A Vulnerability Assessment for Chemical Additive Manufacturing Devices

机译:裂开连续流量反应堆:化学添加剂制造装置的漏洞评估

获取原文

摘要

The proliferation of additive manufacturing devices such as 3D-printers and chemical Continuous Flow Reactors (CFR) have commoditized the creation of complex physical and liquid products. CFR machines are computer controlled pumps and mixers designed to synthesize industrial and medical chemical compounds. Similar to many new digital products, CFRs often lack standard forms of access control and are vulnerable to physical and network-based attacks. This paper reviews the common attack vectors and vulnerabilities associated with Supervisory Control and Data Acquisition (SCADA) systems and uses these lessons to inform an initial analysis and security test of the Cole-Parmer Masterflex CFR. Using standard penetration testing techniques, we show that the Masterflex CFR is susceptible to multiple types of remote and local attack including query flooding, malformed ping attacks, and firmware retrieval via an “Evil Maid Attack”. These attacks are trivial to perform and can potentially harm the device, nearby operators, or the users of manufactured products via cyber- physical attack. We believe that these findings in the Cole-Parmer Masterflex are indicative of similar vulnerabilities in other CFR models.
机译:添加剂制造装置的增殖如3D打印机和化学连续流量反应器(CFR)已经商品化了复杂的物理和液体产品的产生。 CFR机器是计算机控制泵和搅拌机,旨在合成工业和医疗化学化合物。类似于许多新型数字产品,CFR常常缺乏标准的访问控制形式,并且容易受到物理和基于网络的攻击。本文审查了与监督控制和数据采集(SCADA)系统相关的常见攻击向量和漏洞,并使用这些课程通知COLE-PARMER MasterFlex CFR的初始分析和安全测试。使用标准的渗透测试技术,我们显示MasterFlex CFR易受多种类型的远程和本地攻击,包括查询洪水,畸形Ping攻击和通过“邪恶的女仆攻击”。这些攻击是微不足道的,并且可以通过网络物理攻击造成设备,附近运营商或制造产品的用户。我们认为,COLE-PARMER MasterFlex中的这些发现表明其他CFR模型中的漏洞。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号