Testing of PLCs used in Nuclear Installations by Bug Fuzzing Search for Cyber Vulnerabilities
- 1. National Centre for Nuclear Research (Poland)
- 2. ComCERT Poland (Poland)
Description
Full text: Fuzzing is a software testing technique, that involves providing invalid, unexpected, or random data to the inputs of a computer program and has been commonly used to test software or computer systems. Nowadays, more and more industrial control systems (ICS) are interconnected with Ethernet or directly connected to Internet, which greatly improve the efficiency of data sharing but introduce security threats at the same time. The important components of critical infrastructure (like nuclear installations), if attacked, will behave abnormal and may result in disasters to society and economy. In particular, PLCs which operate hardware used in nuclear environments or in devices using ionizing radiations, should be well tested for possible vulnerabilities. This same applies to used protocols and the software environment used for programming and monitoring PLCs. Fuzzing programs fall into two different categories. Mutation-based fuzzers mutate existing data samples to create test data while generation-based fuzzers define new test data based on models of the input. The simplest form of fuzzing is sending a stream of random commands to PLC. However, the most successful fuzzers have detailed understanding of the format or protocol being tested. This understanding can be based on a PLC specification. It involves writing the entire array of specifications into the tool, and then using model-based test generation techniques in walking through the specifications and adding anomalies in the data contents, structures, messages, and sequences. This ''smart fuzzing'' technique is also known as robustness versus vulnerability testing. The objective of this research is to develop a procedure and a set of parameters for active testing of nuclear security relevant programmable logic controllers (PLCs) by fuzzing them, studying their response and setting corresponding criteria and limits. The possibility and the effectiveness of the incident response process will be determined by the capability of the proper analysis of the potential vulnerabilities in the protected system. Stable and continuous process of the vulnerability checking gives a valuable input to the system of the incident response by the continuous tuning of the attack recognition patterns based on the vulnerability checking outcomes. The project will research, develop and demonstrate how fuzzing techniques can be used to detect the presence of undesired functionality inserted in the supply-chain. This knowhow can be used in designing new nuclear systems as well as give hints how to restore the integrity of the compromised nuclear safety or nuclear security system or component. The project will develop methods of testing commonly used in nuclear facilities PLCs for possible security vulnerabilities. Both PLCs themselves, as well as the software tools used to program them, will be tested using bug fuzzing techniques. The project will tackle following issues: 1. Protocol and PLC fuzzing: Different PLC vendors implement ICS protocols differently (ex. not all functions are taken into account). Fuzzing is a relatively inexpensive way to find these differences and the potential unexpected behavior (f.ex. if the protocol expects an integer, what will be the reaction if a floating point number is sent instead) of connected devices (f. ex. PLC). In particular protocol fuzzing will be applied to few typical PLCs, used in nuclear technologies in order to develop methodology of testing PLCs for security vulnerabilities. This experience will be later used to draft the concept of specialized laboratory for fuzzing-like testing of PLCs for the emerging NPP programme. 2. SCADA and HMI fuzzing: SCADA and HMI are applications for monitoring processes in industrial control systems. Nowadays they are usually created using standard web technologies, what makes them possibly vulnerable to the the common web vulnerabilities. 3. Fuzzing Development Environment for PLC: Computer of an engineer responsible for PLC programming is often the easiest vector of attack in separated industrial environment. Fuzzing development environment applications, including the software tools to program PLCs, may lead to discovery of vulnerabilities that could be used to infect his computer, for example by crafted input file for such a development environment. (author)
Additional details
Identifiers
Publishing Information
- Publisher
- IAEA
- Imprint Place
- Vienna (International Atomic Energy Agency (IAEA))
- ISBN
- 978-92-0-107017-3
- Imprint Title
- International Conference on Nuclear Security: Commitments and Actions. Summary of an International Conference. Companion CD-ROM
- Imprint Pagination
- [1 CD-ROM]
- Series
- Proceedings Series
- Journal Page Range
- 2 p.
- ISSN
- 0074-1884
Conference
- Title
- Commitments and Actions
- Acronym
- International Conference on Nuclear Security
- Dates
- 5-9 Dec 2016
- Place
- Vienna (Austria)
INIS
- Country of Publication
- International Atomic Energy Agency (IAEA)
- Country of Input or Organization
- International Atomic Energy Agency (IAEA)
- INIS RN
- 50017506
- Subject category
- S98: NUCLEAR DISARMAMENT, SAFEGUARDS AND PHYSICAL PROTECTION;
- Resource subtype / Literary indicator
- Conference
- Descriptors DEI
- ACCIDENTS; COMPUTER CODES; CONTROL SYSTEMS; IONIZING RADIATIONS; MONITORING; RADIATION PROTECTION; SECURITY; VULNERABILITY
- Descriptors DEC
- RADIATIONS
Optional Information
- Secondary number(s)
- IAEA-CN--244/118