• DocumentCode
    3781541
  • Title

    A framework for incident response in industrial control systems

  • Author

    Roman Schlegel;Ana Hristova;Sebastian Obermeier

  • Author_Institution
    ABB Switzerland Ltd., Corporate Research, Baden-Dä
  • Volume
    4
  • fYear
    2015
  • fDate
    7/1/2015 12:00:00 AM
  • Firstpage
    178
  • Lastpage
    185
  • Abstract
    Industrial control systems are used to control and supervise plants and critical infrastructures. They are crucial for operation of many industries and even society at large. However, despite efforts to secure such systems, there are frequent reports of incidents that lead to problems because of human error (e.g., installing unauthorized software on a mission-critical machine) or even cyber attacks. While such incidents should be prevented in the first place, it is not feasible to achieve 100% security; therefore, operators should be prepared to deal with incidents promptly and efficiently if they occur. In this paper, we present a general methodology and framework for investigating incidents in industrial control systems. The methodology is supported by a tool to automate an investigation, especially to efficiently determine the state of files on a device after an incident. This enables faster recovery from incidents by being able to identify suspicious files and focus on the files that have been modified compared to the initially installed files, or a previously taken baseline. An evaluation confirms the applicability of the methodology for an embedded industrial controller and for an industrial control system.
  • Keywords
    "Forensics","Industrial control","Data mining","Security","Computers","Software","Control systems"
  • Publisher
    ieee
  • Conference_Titel
    e-Business and Telecommunications (ICETE), 2015 12th International Joint Conference on
  • Type

    conf

  • Filename
    7518035