arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.06306cs.CR

MARS:检测多应用PLC运行时中的未授权变量操纵

MARS: Detecting Unauthorized Variable Manipulations in Multi-Application PLC Runtimes

Syed Ghazanfar Abbas, Dongyan Xu

首次发表
浏览论文内容

中文总结 AI 辅助

MARS通过隔离虚拟PLC画像和影子vPLC归因,检测多应用PLC运行时中未授权变量操纵并识别责任应用,无需插桩生产控制器。

中文摘要 AI 辅助

可编程逻辑控制器(PLC)日益在主要控制程序之外运行多个应用程序,并共享访问PLC变量。然而,工业控制系统(ICS)的防御措施主要通过检查变量值是否违反预期边界来检测恶意更新,而不考虑执行更新的应用程序。恶意应用程序可以利用这一漏洞,在正常边界内修改变量,同时仍将物理过程推向不安全状态。即使检测到此类操纵,操作员也无法识别负责的应用程序,因为PLC不会将变量更新与应用程序身份关联。我们提出了MARS,一个用于PLC变量操纵的应用程序级授权和归因的自动化框架。MARS在隔离的虚拟PLC(vPLC)上对应用程序进行画像,以推导特定于应用程序的变量访问策略,并在运行期间使用影子vPLC将生产PLC的更新归因于各个应用程序,而无需对生产控制器进行插桩。MARS还检测仅发生在生产PLC上、因此在影子vPLC上没有对应更新的操纵。我们在制造、化工和水处理系统上评估了MARS,针对未授权应用程序在正常边界内操纵PLC变量的攻击。结果表明,MARS能检测这些操纵并识别负责的应用程序。

英文摘要

Programmable Logic Controllers (PLCs) increasingly run multiple applications alongside the main control program, with shared access to PLC variables. Yet, Industrial Control System (ICS) defenses primarily detect malicious updates by checking whether variable values violate expected bounds, without considering which application performed the update. A malicious application can exploit this gap by modifying variables within normal bounds while still driving the physical process toward an unsafe state. Even when such manipulation is detected, operators cannot identify the responsible application because PLCs do not associate variable updates with application identity. We present MARS, an automated framework for application-level authorization and attribution of PLC variable manipulations. MARS profiles applications on an isolated virtual PLC (vPLC) to derive application-specific variable-access policies and uses a shadow vPLC during operation to attribute production-PLC updates to individual applications without instrumenting the production controller. MARS also detects manipulations that occur only on the production PLC and therefore have no corresponding update on the shadow vPLC. We evaluate MARS on manufacturing, chemical, and water-treatment systems against attacks in which unauthorized applications manipulate PLC variables while remaining within normal bounds. Our results show that MARS detects these manipulations and identifies the responsible application.

发表机构

  • Purdue University(普渡大学)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑