Published September 2017 | Version v1
Book

Testing of PLCs used in Nuclear Installations by Bug Fuzzing Search for Cyber Vulnerabilities

  • 1. National Centre for Nuclear Research (Poland)
  • 2. ComCERT Poland (Poland)

Description

Full text: Fuzzing is a software testing technique, that involves providing invalid, unexpected, or random data to the inputs of a computer program and has been commonly used to test software or computer systems. Nowadays, more and more industrial control systems (ICS) are interconnected with Ethernet or directly connected to Internet, which greatly improve the efficiency of data sharing but introduce security threats at the same time. The important components of critical infrastructure (like nuclear installations), if attacked, will behave abnormal and may result in disasters to society and economy. In particular, PLCs which operate hardware used in nuclear environments or in devices using ionizing radiations, should be well tested for possible vulnerabilities. This same applies to used protocols and the software environment used for programming and monitoring PLCs. Fuzzing programs fall into two different categories. Mutation-based fuzzers mutate existing data samples to create test data while generation-based fuzzers define new test data based on models of the input. The simplest form of fuzzing is sending a stream of random commands to PLC. However, the most successful fuzzers have detailed understanding of the format or protocol being tested. This understanding can be based on a PLC specification. It involves writing the entire array of specifications into the tool, and then using model-based test generation techniques in walking through the specifications and adding anomalies in the data contents, structures, messages, and sequences. This ''smart fuzzing'' technique is also known as robustness versus vulnerability testing. The objective of this research is to develop a procedure and a set of parameters for active testing of nuclear security relevant programmable logic controllers (PLCs) by fuzzing them, studying their response and setting corresponding criteria and limits. The possibility and the effectiveness of the incident response process will be determined by the capability of the proper analysis of the potential vulnerabilities in the protected system. Stable and continuous process of the vulnerability checking gives a valuable input to the system of the incident response by the continuous tuning of the attack recognition patterns based on the vulnerability checking outcomes. The project will research, develop and demonstrate how fuzzing techniques can be used to detect the presence of undesired functionality inserted in the supply-chain. This knowhow can be used in designing new nuclear systems as well as give hints how to restore the integrity of the compromised nuclear safety or nuclear security system or component. The project will develop methods of testing commonly used in nuclear facilities PLCs for possible security vulnerabilities. Both PLCs themselves, as well as the software tools used to program them, will be tested using bug fuzzing techniques. The project will tackle following issues: 1. Protocol and PLC fuzzing: Different PLC vendors implement ICS protocols differently (ex. not all functions are taken into account). Fuzzing is a relatively inexpensive way to find these differences and the potential unexpected behavior (f.ex. if the protocol expects an integer, what will be the reaction if a floating point number is sent instead) of connected devices (f. ex. PLC). In particular protocol fuzzing will be applied to few typical PLCs, used in nuclear technologies in order to develop methodology of testing PLCs for security vulnerabilities. This experience will be later used to draft the concept of specialized laboratory for fuzzing-like testing of PLCs for the emerging NPP programme. 2. SCADA and HMI fuzzing: SCADA and HMI are applications for monitoring processes in industrial control systems. Nowadays they are usually created using standard web technologies, what makes them possibly vulnerable to the the common web vulnerabilities. 3. Fuzzing Development Environment for PLC: Computer of an engineer responsible for PLC programming is often the easiest vector of attack in separated industrial environment. Fuzzing development environment applications, including the software tools to program PLCs, may lead to discovery of vulnerabilities that could be used to infect his computer, for example by crafted input file for such a development environment. (author)

Part of:
International Conference on Nuclear Security: Commitments and Actions. Summary of an International Conference. Companion CD-ROM

Additional details

Publishing Information

Publisher
IAEA
Imprint Place
Vienna (International Atomic Energy Agency (IAEA))
ISBN
978-92-0-107017-3
Imprint Title
International Conference on Nuclear Security: Commitments and Actions. Summary of an International Conference. Companion CD-ROM
Imprint Pagination
[1 CD-ROM]
Series
Proceedings Series
Journal Page Range
2 p.
ISSN
0074-1884

Conference

Title
Commitments and Actions
Acronym
International Conference on Nuclear Security
Dates
5-9 Dec 2016
Place
Vienna (Austria)

INIS

Country of Publication
International Atomic Energy Agency (IAEA)
Country of Input or Organization
International Atomic Energy Agency (IAEA)
INIS RN
50017506
Subject category
S98: NUCLEAR DISARMAMENT, SAFEGUARDS AND PHYSICAL PROTECTION;
Resource subtype / Literary indicator
Conference
Descriptors DEI
ACCIDENTS; COMPUTER CODES; CONTROL SYSTEMS; IONIZING RADIATIONS; MONITORING; RADIATION PROTECTION; SECURITY; VULNERABILITY
Descriptors DEC
RADIATIONS

Optional Information

Secondary number(s)
IAEA-CN--244/118