A Survey on Industrial Control System Digital Forensics: Challenges, Advances and Future Directions

被引:4
|
作者
Cook, Marco [1 ]
Marnerides, Angelos [1 ]
Johnson, Chris [2 ]
Pezaros, Dimitrios [1 ]
机构
[1] Univ Glasgow, Sch Comp Sci, Glasgow G12 8QQ, Lanark, Scotland
[2] Queens Univ Belfast, Sch Elect Elect Engn & Comp Sci, Belfast BT7 1NN, North Ireland
来源
基金
英国工程与自然科学研究理事会;
关键词
Industrial control systems; ICS forensics; SCADA forensics; digital forensics; programmable logic con-trollers; PLC forensics; INTRUSION DETECTION; SCADA SYSTEMS; ANTI-FORENSICS; SECURITY; ATTACKS;
D O I
10.1109/COMST.2023.3264680
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Operational Technology (OT) systems have become increasingly interconnected and automated, consequently resulting in them becoming targets of cyber attacks, with the threat towards a range of critical national infrastructure (CNI) sectors becoming heightened. This is particularly the case for Industrial Control Systems (ICS), which control and operate the physical processes in CNI sectors such as water treatment, electrical generation and manufacturing. Unlike information technology (IT) systems, ICS have unique cyber-physical characteristics and related safety requirements, making them an attractive target for attacks given the physical consequences that can occur. As a result, the requirement to respond and learn from previous and new attacks is also increasing, with digital forensics playing a significant role in this process. The aim of this paper is to discuss the main issues and existing limitations related to ICS digital forensic. The field of ICS digital forensics is relatively under-developed and does not have the same levels of maturity as IT digital forensics. Although the amount of research on cyber security for ICS is increasing, many unique challenges still exist that pose as barriers to the development and deployment of ICS forensic capabilities. We provide an extensive discussion on these challenges, categorising them into technical, socio-technical, and operational and legal themes. Furthermore, the relationship between these challenge themes as well as the inter-challenge dependencies are also examined. Furthermore, this work discusses ICS forensic advances in relation to the digital forensics life chain, specifically forensic readiness and investigations. The areas of digital forensic training and processes models for ICS are given particular focus. Moreover, we assess the technologies and tools that have been either applied to or developed for ICS components and networks, giving special attention to forensic acquisition and analysis methods. An examination into the specific ICS digital forensic data sources and artefacts is also presented, highlighting that until recently, this was limited to descriptions of generic data formats. In addition, this paper provides an overview of several key ICS attacks, summarising the specific techniques used, data artefacts of interest, and proposing lessons learnt. Finally, this paper presents open discussions on future ICS digital forensics research directions and on-going issues, covering both short and long-term areas that can be addressed to improve the ICS digital forensics capability.
引用
收藏
页码:1705 / 1747
页数:43
相关论文
共 50 条
  • [31] RNA Therapeutics in Oncology: Advances, Challenges, and Future Directions
    MacLeod, A. Robert
    Crooke, Stanley T.
    [J]. JOURNAL OF CLINICAL PHARMACOLOGY, 2017, 57 (10): : S43 - S59
  • [32] Perspective on Lignin Oxidation: Advances, Challenges, and Future Directions
    Vangeel, Thijs
    Schutyser, Wouter
    Renders, Tom
    Sels, Bert F.
    [J]. TOPICS IN CURRENT CHEMISTRY, 2018, 376 (04)
  • [33] ENHANCING INDUSTRIAL CONTROL SYSTEM FORENSICS USING REPLICATION-BASED DIGITAL TWINS
    Dietz, Marietheres
    Englbrecht, Ludwig
    Pernul, Guenther
    [J]. ADVANCES IN DIGITAL FORENSICS XVII, 2021, 612 : 21 - 38
  • [34] Single-sensor imaging in consumer digital cameras: a survey of recent advances and future directions
    Rastislav Lukac
    [J]. Journal of Real-Time Image Processing, 2006, 1 : 45 - 52
  • [35] Single-sensor imaging in consumer digital cameras: a survey of recent advances and future directions
    Lukac, Rastislav
    [J]. JOURNAL OF REAL-TIME IMAGE PROCESSING, 2006, 1 (01) : 45 - 52
  • [36] Forensics in Industrial Control System: A Case Study
    Van Vliet, Pieter
    Kechadi, M. -T.
    Nhien-An Le-Khac
    [J]. Security of Industrial Control Systems and Cyber Physical Systems, 2016, 9588 : 147 - 156
  • [37] Blockchain Forensics: A Systematic Literature Review of Techniques, Applications, Challenges, and Future Directions
    Atlam, Hany F.
    Ekuri, Ndifon
    Azad, Muhammad Ajmal
    Lallie, Harjinder Singh
    [J]. ELECTRONICS, 2024, 13 (17)
  • [38] A survey of urban visual analytics: Advances and future directions
    Zikun Deng
    Di Weng
    Shuhan Liu
    Yuan Tian
    Mingliang Xu
    Yingcai Wu
    [J]. Computational Visual Media, 2023, 9 : 3 - 39
  • [39] Digital forensics and cyber forensics investigation: security challenges, limitations, open issues, and future direction
    Khan, Abdullah Ayub
    Shaikh, Aftab Ahmed
    Laghari, Asif Ali
    Dootio, Mazhar Ali
    Rind, M. Malook
    Awan, Shafique Ahmed
    [J]. INTERNATIONAL JOURNAL OF ELECTRONIC SECURITY AND DIGITAL FORENSICS, 2022, 14 (02) : 124 - 150
  • [40] A survey of urban visual analytics: Advances and future directions
    Deng, Zikun
    Weng, Di
    Liu, Shuhan
    Tian, Yuan
    Xu, Mingliang
    Wu, Yingcai
    [J]. COMPUTATIONAL VISUAL MEDIA, 2023, 9 (01) : 3 - 39