Title
Forensic Readiness for SCADA/ICS Incident Response.
Abstract
The actions carried out following any cyber-attack are vital in limiting damage, regaining control and determining the cause and those responsible. Within SCADA and ICS environments there is certainly no exception. Critical National Infrastructure (CNI) relies heavily on SCADA systems to monitor and control critical processes. Many of these systems span huge geographical areas and contain thousands of individual devices, across an array of asset types. When an incident occurs, those assets contain forensic artefacts, which can be thought of as any data that provides explanation to the current state of the SCADA system. Knowing what devices exist within the network and the tools and methods to retrieve data from them are some of the biggest challenges for incident response within CNI. This paper aims to identify those assets and their forensic value whilst providing the tools needed to perform data acquisition in a forensically sound manner. It will also discuss the key stages in which the incident response process can be managed.
Year
DOI
Venue
2016
10.14236/ewic/ICS2016.16
ICS-CSR
DocType
Citations 
PageRank 
Conference
0
0.34
References 
Authors
4
7
Name
Order
Citations
PageRank
Peter Eden131.12
Andrew Blyth2165.13
peter burnap328437.02
Yulia Cherdantseva4876.30
Kevin Jones593.48
Hugh Soulsby600.34
Kristan Stoddart730.78