Abstract
MODBUS is the most common protocol in industrial control systems for relaying commands and fetching data. Still, the protocol has zero built‐in security. Thus, modern implementations want to control remote units through the internet to maximize utility, they often implement MODBUS over TCP/IP connections. To cope with the inherent vulnerabilities, trending implementations of MODBUS‐TCP utilize encryption on TCP packets to protect the commands and data being transferred. Still, side characteristics can be exploited to break the confidentiality of these command executions. In this article, we present attacks that leak what is being executed on a real‐world Supervisory Controls and Data Acquisition (SCADA) system running MODBUS, even if commands are encrypted over a TCP/IP channel. Presented scenario attacks use network traffic sniffed from a hardware‐in‐the‐loop simulated Power Grid Industrial Control System. We also show that command execution can be leaked no matter when the attacker starts sniffing traffic, provided he has some prior knowledge on how the SCADA system works. Only restriction is that the configuration must use unpadded encryption; something that proved to be more common than expected.
Cite
CITATION STYLE
Stergiopoulos, G., Kapetanas, N., Vasilellis, E., & Gritzalis, D. (2020). Leaking supervisory controls and data acquisition commands over unpadded TCP/IP encryption through differential packet size analysis. SECURITY AND PRIVACY, 3(4). https://doi.org/10.1002/spy2.82
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.