Title
An Internet-wide view of ICS devices.
Abstract
Industrial control systems have become ubiquitous, enabling the remote, electronic control of physical equipment and sensors. Originally designed to operate on closed networks, the protocols used by these devices have no built-in security. However, despite this, an alarming number of systems are connected to the public Internet and an attacker who finds a device often can cause catastrophic damage to physical infrastructure. We consider two aspects of ICS security in this work: (1) what devices have been inadvertently exposed on the public Internet, and (2) who is searching for vulnerable systems. First, we implement five common SCADA protocols in ZMap and conduct a survey of the public IPv4 address space finding more than 60K publicly accessible systems. Second, we use a large network telescope and high-interaction honeypots to find and profile actors searching for devices. We hope that our findings can both motivate and inform future work on securing industrial control systems.
Year
Venue
Field
2016
2016 14TH ANNUAL CONFERENCE ON PRIVACY, SECURITY AND TRUST (PST)
Network telescope,Honeypot,Computer science,Computer security,Industrial control system,SCADA,Iec standards,The Internet,IPv4 address exhaustion
DocType
ISSN
Citations 
Conference
1712-364X
0
PageRank 
References 
Authors
0.34
0
11
Name
Order
Citations
PageRank
Ariana Mirian11217.26
Zane Ma200.34
David Adrian322211.07
Matthew Tischer4181.75
Thasphon Chuenchujit500.34
Timothy M. Yardley6847.27
Robin Berthier727518.99
Joshua Mason81089.79
Zakir Durumeric993548.86
J. Alex Halderman102301149.67
Michael Bailey11133578.22