A Modbus command and control channel

2016 ANNUAL IEEE SYSTEMS CONFERENCE (SYSCON)(2016)

引用 36|浏览31
暂无评分
摘要
Since the discovery of Stuxnet, it is no secret that skilled adversaries target industrial control systems. To defend against this threat, defenders increasingly rely on intrusion detection and segmentation. As the security posture improves, it is likely that the attackers will move to stealthier approaches, such as covert channels. This paper presents a command and control (C&C) covert channel over the Modbus/TCP protocol that represents the next logical step for the attackers and evaluates its suitability. The channel stores information in the least significant bits of holding registers to carry information using Modbus read and write methods. This offers an explicit tradeoff between the bandwidth and stealth of the channel that can be set by the attacker.
更多
查看译文
关键词
Industrial control systems security, covert channel, command and control channel
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要