Validation of ICS Vulnerability Related to TCP/IP Protocol Implementation in Allen-Bradley Compact Logix PLC Controller

Jaime Pavesi, Thamara Villegas, Alexey Perepechko, Eleazar Aguirre, Lorena Galeazzi

Producción científica: Capítulo del libro/informe/acta de congresoContribución a la conferenciarevisión exhaustiva

2 Citas (Scopus)

Resumen

Industrial Control Systems (ICS) research and testing process was implemented to validate the existence of a well known security vulnerability in a Rockwell Automation Allen-Bradley Compact Logix PLC controller. The study was conducted considering a public advisory from the manufacturer, which includes a large list of families of affected products by the vulnerability. The established hypothesis of the study considered the existence of the vulnerability in a specific available PLC model, included by Rockwell Automation manufacturer in the list of affected products. An exploit was developed and multiple testing was performed to trigger the vulnerability. Testing methodology and results indicates there is sufficient evidence to establish that Rockwell Automation Allen-Bradley Compact Logix 5370 L2 controllers, are not affected by the same type of Improper Input Validation vulnerability, than the Compact Logix 5370 L3 controllers, as it was stated by the manufacturer in a public advisory.

Idioma originalInglés
Título de la publicación alojadaTelematics and Computing - 8th International Congress, WITCOM 2019, Proceedings
EditoresMiguel Felix Mata-Rivera, Roberto Zagal-Flores, Cristian Barría-Huidobro
EditorialSpringer
Páginas355-364
Número de páginas10
ISBN (versión impresa)9783030332280
DOI
EstadoPublicada - 2019
Evento8th International Congress on Telematics and Computing, WITCOM 2019 - Merida, México
Duración: 4 nov. 20198 nov. 2019

Serie de la publicación

NombreCommunications in Computer and Information Science
Volumen1053 CCIS
ISSN (versión impresa)1865-0929
ISSN (versión digital)1865-0937

Conferencia

Conferencia8th International Congress on Telematics and Computing, WITCOM 2019
País/TerritorioMéxico
CiudadMerida
Período4/11/198/11/19

Huella

Profundice en los temas de investigación de 'Validation of ICS Vulnerability Related to TCP/IP Protocol Implementation in Allen-Bradley Compact Logix PLC Controller'. En conjunto forman una huella única.

Citar esto