A Survey on Industrial Control System Digital Forensics: Challenges, Advances and Future Directions

被引:4
|
作者
Cook, Marco [1 ]
Marnerides, Angelos [1 ]
Johnson, Chris [2 ]
Pezaros, Dimitrios [1 ]
机构
[1] Univ Glasgow, Sch Comp Sci, Glasgow G12 8QQ, Lanark, Scotland
[2] Queens Univ Belfast, Sch Elect Elect Engn & Comp Sci, Belfast BT7 1NN, North Ireland
来源
基金
英国工程与自然科学研究理事会;
关键词
Industrial control systems; ICS forensics; SCADA forensics; digital forensics; programmable logic con-trollers; PLC forensics; INTRUSION DETECTION; SCADA SYSTEMS; ANTI-FORENSICS; SECURITY; ATTACKS;
D O I
10.1109/COMST.2023.3264680
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Operational Technology (OT) systems have become increasingly interconnected and automated, consequently resulting in them becoming targets of cyber attacks, with the threat towards a range of critical national infrastructure (CNI) sectors becoming heightened. This is particularly the case for Industrial Control Systems (ICS), which control and operate the physical processes in CNI sectors such as water treatment, electrical generation and manufacturing. Unlike information technology (IT) systems, ICS have unique cyber-physical characteristics and related safety requirements, making them an attractive target for attacks given the physical consequences that can occur. As a result, the requirement to respond and learn from previous and new attacks is also increasing, with digital forensics playing a significant role in this process. The aim of this paper is to discuss the main issues and existing limitations related to ICS digital forensic. The field of ICS digital forensics is relatively under-developed and does not have the same levels of maturity as IT digital forensics. Although the amount of research on cyber security for ICS is increasing, many unique challenges still exist that pose as barriers to the development and deployment of ICS forensic capabilities. We provide an extensive discussion on these challenges, categorising them into technical, socio-technical, and operational and legal themes. Furthermore, the relationship between these challenge themes as well as the inter-challenge dependencies are also examined. Furthermore, this work discusses ICS forensic advances in relation to the digital forensics life chain, specifically forensic readiness and investigations. The areas of digital forensic training and processes models for ICS are given particular focus. Moreover, we assess the technologies and tools that have been either applied to or developed for ICS components and networks, giving special attention to forensic acquisition and analysis methods. An examination into the specific ICS digital forensic data sources and artefacts is also presented, highlighting that until recently, this was limited to descriptions of generic data formats. In addition, this paper provides an overview of several key ICS attacks, summarising the specific techniques used, data artefacts of interest, and proposing lessons learnt. Finally, this paper presents open discussions on future ICS digital forensics research directions and on-going issues, covering both short and long-term areas that can be addressed to improve the ICS digital forensics capability.
引用
收藏
页码:1705 / 1747
页数:43
相关论文
共 50 条
  • [1] A comprehensive survey on digital video forensics: Taxonomy, challenges, and future directions
    Javed, Abdul Rehman
    Jalil, Zunera
    Zehra, Wisha
    Gadekallu, Thippa Reddy
    Suh, Doug Young
    Piran, Md Jalil
    [J]. ENGINEERING APPLICATIONS OF ARTIFICIAL INTELLIGENCE, 2021, 106
  • [2] Industrial Internet of Things Ecosystems Security and Digital Forensics: Achievements, Open Challenges, and Future Directions
    Kebande, Victor R.
    Awad, Ali Ismail
    [J]. ACM COMPUTING SURVEYS, 2024, 56 (05)
  • [3] A Systematic Survey on Cloud Forensics Challenges, Solutions, and Future Directions
    Manral, Bharat
    Somani, Gaurav
    Choo, Kim-Kwang Raymond
    Conti, Mauro
    Gaur, Manoj Singh
    [J]. ACM COMPUTING SURVEYS, 2020, 52 (06)
  • [4] IoT Ignorance is Digital Forensics Research Bliss: A Survey to Understand IoT Forensics Definitions, Challenges and Future Research Directions
    Wu, Tina
    Breitinger, Frank
    Baggili, Ibrahim
    [J]. 14TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES 2019), 2019,
  • [5] Technical challenges and directions for digital forensics
    Mohay, G
    [J]. FIRST INTERNATIONAL WORKSHOP ON SYSTEMATIC APPROACHES TO DIGITAL FORENSIC ENGINEERING, PROCEEDINGS, 2005, : 155 - 161
  • [6] Application of Artificial Intelligence to Network Forensics: Survey, Challenges and Future Directions
    Rizvi, Syed
    Scanlon, Mark
    McGibney, Jimmy
    Sheppard, John
    [J]. IEEE ACCESS, 2022, 10 : 110362 - 110384
  • [7] Digital Hadith authentication: Recent advances, open challenges, and future directions
    Hakak, Saqib
    Kamsin, Amirrudin
    Khan, Wazir Zada
    Zakari, Abubakar
    Imran, Muhammad
    bin Ahmad, Khadher
    Gilkar, Gulshan Amin
    [J]. TRANSACTIONS ON EMERGING TELECOMMUNICATIONS TECHNOLOGIES, 2022, 33 (06)
  • [8] ENF Based Digital Multimedia Forensics: Survey, Application, Challenges and Future Work
    Ngharamike, Ericmoore
    Ang, Li-Minn
    Seng, Kah Phooi
    Wang, Mingzhong
    [J]. IEEE ACCESS, 2023, 11 : 101241 - 101272
  • [9] Evidence and Forensics in the Cloud: Challenges and Future Research Directions
    Choo, Kim-Kwang Raymond
    Esposito, Christian
    Castiglione, Aniello
    [J]. IEEE CLOUD COMPUTING, 2017, 4 (03): : 14 - 19
  • [10] A survey on quantum data mining algorithms: challenges, advances and future directions
    Han Qi
    Liyuan Wang
    Changqing Gong
    Abdullah Gani
    [J]. Quantum Information Processing, 23