loading
Documents

Research.Publish.Connect.

Paper

Authors: Anne Borcherding 1 ; Steffen Pfrang 1 ; Christian Haas 1 ; Albrecht Weiche 1 and Jürgen Beyerer 2

Affiliations: 1 Fraunhofer IOSB, Karlsruhe, Germany ; 2 Fraunhofer IOSB, Karlsruhe, Germany, Vision and Fusion Laboratory (IES), Karlsruhe Institute of Technology (KIT), Karlsruhe, Germany

ISBN: 978-989-758-446-6

Keyword(s): Industrial Control Systems, Black Box Security Testing, Web Application Scanners, Proxy, Usability.

Abstract: Web applications on industrial control systems (ICS) provide functionality such as obtaining status information or updating configurations. However, a web application possibly adds additional attack vectors to the ICS. In order to find existing vulnerabilities of web applications, automated black box web application scanners (WAS) can be used. Evaluations of existing scanners show similar limitations in their applicability. For example, ICS often crash during a scan. If the used scanner does not recognize and handle this issue, it is not able to finish the test. We present HelpMeICS which makes improvements available for different scanners without the need to adapt the specific scanner. It is implemented as a proxy-based solution which is transparent for the scanners and handles different aspects such as error-handling, authentication, and replacement of contents. Our evaluation with five different ICS shows an improvement of applicability as well as a reduction of additional limitati ons of WAS. As an example, our improvements increased the URL coverage from 8% to 100%. For one of the ICS, a complete scan was only made possible by HelpMeICS since the ICS crashed irrecoverably during the scans without HelpMeICS. (More)

PDF ImageFull Text

Download
CC BY-NC-ND 4.0

Sign In Guest: Register as new SciTePress user now for free.

Sign In SciTePress user: please login.

PDF ImageMy Papers

You are not signed in, therefore limits apply to your IP address 3.216.79.60

In the current month:
Recent papers: 100 available of 100 total
2+ years older papers: 200 available of 200 total

Paper citation in several formats:
Borcherding, A.; Pfrang, S.; Haas, C.; Weiche, A. and Beyerer, J. (2020). Helper-in-the-Middle: Supporting Web Application Scanners Targeting Industrial Control Systems.In Proceedings of the 17th International Joint Conference on e-Business and Telecommunications - Volume 3: SECRYPT, ISBN 978-989-758-446-6, pages 27-38. DOI: 10.5220/0009517800270038

@conference{secrypt20,
author={Anne Borcherding. and Steffen Pfrang. and Christian Haas. and Albrecht Weiche. and Jürgen Beyerer.},
title={Helper-in-the-Middle: Supporting Web Application Scanners Targeting Industrial Control Systems},
booktitle={Proceedings of the 17th International Joint Conference on e-Business and Telecommunications - Volume 3: SECRYPT,},
year={2020},
pages={27-38},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0009517800270038},
isbn={978-989-758-446-6},
}

TY - CONF

JO - Proceedings of the 17th International Joint Conference on e-Business and Telecommunications - Volume 3: SECRYPT,
TI - Helper-in-the-Middle: Supporting Web Application Scanners Targeting Industrial Control Systems
SN - 978-989-758-446-6
AU - Borcherding, A.
AU - Pfrang, S.
AU - Haas, C.
AU - Weiche, A.
AU - Beyerer, J.
PY - 2020
SP - 27
EP - 38
DO - 10.5220/0009517800270038

Login or register to post comments.

Comments on this Paper: Be the first to review this paper.