🤖 AI Summary
This study addresses the security blind spots in industrial control systems (ICS) arising from an overemphasis on detection over recovery, wherein attacks exhaust recovery margins prior to detection. To this end, it proposes the concept of TLTR vulnerabilities and constructs an automated auditing framework. Methodologically, this work pioneers a joint audit of detection and recovery mechanisms by integrating static and dynamic analysis to model PLC logic, detection strategies, recovery procedures, and runtime behaviors, thereby automatically generating and validating attack scenarios. Experimental evaluations demonstrate that the proposed framework identifies 392 TLTR attacks on a testbed, significantly outperforming existing tools. Furthermore, critical vulnerabilities are validated in a real-world factory environment. This research effectively bridges the gap in assessing ICS recovery capabilities.
📝 Abstract
The security of industrial control systems (ICS) is important. Yet most ICS security efforts focus on the detection of ICS attacks, with much less attention to the recovery after detection. In this paper, we address this underexplored area by jointly auditing the detection and recovery of ICS. Specifically, we define the too-late-to-recover (TLTR) vulnerability, which allows an attack to drain the available recovery margin before being detected, such that the subsequent recovery procedure will fail to bring the ICS back to a safe state due to the insufficient margin. To audit an ICS for TLTR vulnerabilities, we develop RISK, an automated framework that discovers and validates possible TLTR attack scenarios. RISK holistically models and analyzes, statically and dynamically, the PLC control logic, attack detection policies, recovery procedures, and operational behaviors of an ICS to generate TLTR attack scenarios with concrete attack parameters. We evaluate RISK on three ICS testbeds as well as a real-world fertilizer production plant. Across the three testbeds, a total of 392 TLTR attacks are generated and confirmed, whereas only a small fraction of them can be discovered by existing ICS vetting tools. In the real-world plant, RISK identified a critical TLTR vulnerability which was validated by plant engineers.