首页> 外文OA文献 >Watch Me, but Don't Touch Me! Contactless Control Flow Monitoring via Electromagnetic Emanations
【2h】

Watch Me, but Don't Touch Me! Contactless Control Flow Monitoring via Electromagnetic Emanations

机译:看着我,但不要碰我!非接触式控制流量监测   电磁辐射

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Trustworthy operation of industrial control systems depends on secure andreal-time code execution on the embedded programmable logic controllers (PLCs).The controllers monitor and control the critical infrastructures, such aselectric power grids and healthcare platforms, and continuously report back thesystem status to human operators. We present Zeus, a contactless embeddedcontroller security monitor to ensure its execution control flow integrity.Zeus leverages the electromagnetic emission by the PLC circuitry during theexecution of the controller programs. Zeus's contactless execution trackingenables non-intrusive monitoring of security-critical controllers with tightreal-time constraints. Those devices often cannot tolerate the cost andperformance overhead that comes with additional traditional hardware orsoftware monitoring modules. Furthermore, Zeus provides an air-gap between themonitor (trusted computing base) and the target (potentially compromised) PLC.This eliminates the possibility of the monitor infection by the same attackvectors. Zeus monitors for control flow integrity of the PLC program execution.Zeus monitors the communications between the human-machine interface and thePLC, and captures the control logic binary uploads to the PLC. Zeus exercisesits feasible execution paths, and fingerprints their emissions using anexternal electromagnetic sensor. Zeus trains a neural network for legitimatePLC executions, and uses it at runtime to identify the control flow based onPLC's electromagnetic emissions. We implemented Zeus on a commercial AllenBradley PLC, which is widely used in industry, and evaluated it on real-worldcontrol program executions. Zeus was able to distinguish between differentlegitimate and malicious executions with 98.9% accuracy and with zero overheadon PLC execution by design.
机译:工业控制系统的可靠运行取决于嵌入式可编程逻辑控制器(PLC)上安全,实时的代码执行。这些控制器监视和控制关键基础设施(例如电网和医疗保健平台),并不断向操作员报告系统状态。我们提出了Zeus,一种非接触式嵌入式控制器安全监控器,以确保其执行控制流程的完整性。Zeus在执行控制器程序的过程中利用了PLC电路的电磁辐射。宙斯(Zeus)的非接触式执行跟踪功能可以对具有严格实时限制的安全关键型控制器进行非侵入式监控。这些设备通常无法承受其他传统硬件或软件监视模块所带来的成本和性能开销。此外,宙斯(Zeus)在监视程序(受信任的计算基础)和目标PLC(可能受到威胁)之间提供了一个空隙,从而消除了监视程序被相同攻击向量感染的可能性。 Zeus监视PLC程序执行的控制流完整性。Zeus监视人机界面与PLC之间的通信,并捕获上传到PLC的控制逻辑二进制文件。宙斯行使其可行的执行路径,并使用外部电磁传感器对它们的发射进行指纹识别。宙斯(Zeus)为合法的PLC执行训练一个神经网络,并在运行时使用它来基于PLC的电磁辐射识别控制流。我们在商业上广泛使用的商业AllenBradley PLC上实现了Zeus,并在实际控制程序执行中对其进行了评估。通过设计,Zeus能够以98.9%的准确度区分合法的和恶意的执行,而PLC执行的开销为零。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号