• Home
  • Search
  • Application: Protecting Industrial Control Systems
  • Cite Icon1
  • https://doi.org/10.1017/9781316888513.009Copy DOI Icon

Application: Protecting Industrial Control Systems

  • Apr 1, 2017
  • John Robertson +6 more
Show More
  • Abstract
  • Literature Map
  • Citations
  • Similar Papers
Abstract

Introduction In the last chapter, we explored how to determine a cyber-attacker's optimal strategy for attacking a computer system based on malware and exploits available on the darkweb. In this chapter, we look at the case where the attacker is focused on industrial control systems (ICS): IT infrastructure that controls physical systems (electricity, water, industrial machinery, etc.). A critical feature of these complex ICS systems is the interdependencies among various components. However, despite the prevalence of markets for malware and exploits, and their potential threat to ICS, existing paradigms, including the framework presented in the previous chapter, do not account for the complex nature of ICS systems consisting of multiple interconnected components. In particular, it would prove useful to simulate a cyber-attack on a model of an existing system, to assess its degree of vulnerability. Such a model would also prove useful for automated cybersecurity systems that can learn defense and contingency strategies based on the model's simulations. This chapter takes the first steps toward addressing this need. In particular, we introduce a framework that allows for modeling of ICS systems with highly interconnected components (Section 7.3) and study this model through the lens of lattice theory [57]. We then turn our attention to the problem of determining the optimal/most dangerous strategy for a cyber-adversary with respect to this model and find it to be an NPComplete problem (Section 7.4). Next, we present a suite of algorithms for this problem based on A* search and introduce provably correct algorithms (Section 7.5). Our intuition is that these algorithms will obtain satisfactory performance in practice due to heuristic functions (for which we show admissibility). We demonstrate the performance of these algorithms by implementing them and performing a suite of experiments using both simulated and actual vulnerability data (Section 7.6). This chapter also includes some background on ICS (Section 7.2) and a brief overview of related work (Section 7.7). Background Contemporary cyber threat actors rely on a variety of malware and exploits purchased through various channels such as the darkweb [99] in order to carry out their attacks. The trend toward automation of industrial control systems (ICS) and toward “smart” utilities [50] has made understanding such adversarialbehavior directed against ICS a priority. For instance, code from the infamous Stuxnet [97] attack against Iranian nuclear facilities is available for public download.

Similar Papers
  • Book Chapter
  • Citations24

Forensics in Industrial Control System: A Case Study

  • Jan 01, 2016
  • Pieter Van Vliet +2
  • PDF
  • Research Article
  • Citations7

Detecting Flooding Attacks in Communication Protocol of Industrial Control Systems

  • Jan 01, 2020
  • International Journal of Advanced Computer Science and Applications
  • Rajesh L +1
  • Conference Article
  • Citations25

Encryption in ICS networks: A blessing or a curse?

  • Oct 01, 2017
  • Davide Fauri +5
  • Conference Article
  • Citations1

The conception of Quasi-PLC and its application in industrial control system

  • Jun 01, 2010
  • Jiaming Zhang +3
  • Research Article
  • Citations67

Detecting cyberattacks in industrial control systems using online learning algorithms

  • Jul 19, 2019
  • Neurocomputing
  • Guangxia Li +6
  • Research Article
  • Citations3

The Security Issue of ICS: The Use of IT Infrastructure

  • May 28, 2021
  • Journal of Robotics, Networking and Artificial Life
  • I-Hsien Liu +2
  • Conference Article
  • Citations2

Development of Protection Object Model – Industrial Control System Using System Analysis

  • Sep 01, 2018
  • Irina Mashkina +1
  • Conference Article
  • Citations64

Towards High-Interaction Virtual ICS Honeypots-in-a-Box

  • Oct 28, 2016
  • Daniele Antonioli +2
  • PDF
  • Research Article
  • Citations86

Multivariate Abnormal Detection for Industrial Control Systems Using 1D CNN and GRU

  • Jan 01, 2020
  • IEEE Access
  • Xin Xie +3
  • Research Article
  • Citations119

Hybrid Statistical-Machine Learning for Real-Time Anomaly Detection in Industrial Cyber–Physical Systems

  • May 08, 2021
  • IEEE Transactions on Automation Science and Engineering
  • Weijie Hao +2
  • Conference Article
  • Citations29

Agent-based cyber control strategy design for resilient control systems: Concepts, architecture and methodologies

  • Aug 01, 2012
  • Craig Rieger +2
  • Conference Article

Enhancing Resilience in Industrial Control Systems: Rapid Attack Detection, Recovery, and Monotonicity Preservation Through STL-GT Online Monitoring

  • Nov 12, 2025
  • Chidi Agbo +1
  • Conference Article
  • Citations8

An Industrial Control Systems incident response decision framework

  • Sep 01, 2015
  • Ying He +3
  • PDF
  • Research Article
  • Citations5

Protecting Chiller Systems from Cyberattack Using a Systems Thinking Approach

  • Nov 02, 2022
  • Network
  • Shaharyar Khan +1
  • Book Chapter
  • Citations7

Characterizing Internet-Scale ICS Automated Attacks Through Long-Term Honeypot Data

  • Jan 01, 2020
  • Jianzhou You +5
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.