Sorry, Shodan is not Enough! Assessing ICS Security via IXP Network Traffic Analysis

07/02/2020
by   Giovanni Barbieri, et al.
0

Modern Industrial Control Systems (ICSs) allow remote communication through the Internet using industrial protocols that were not designed to work with external networks. To understand security issues related to this practice, prior work usually relies on active scans by researchers or services such as Shodan. While such scans can identify public open ports, they are not able to provide details on configurations of the system related to legitimate Industrial Traffic passing the Internet (e.g., source-based filtering in Network Address Translation or Firewalls). In this work, we complement Shodan-only analysis with large-scale traffic analysis at a local Internet Exchange Point (IXP), based on sFlow sampling. This setup allows us to identify ICS endpoints actually exchanging Industrial Traffic over the Internet. Besides, we are able to detect scanning activities and what other type of traffic is exchanged by the systems (i.e., IT traffic). We find that Shodan only listed less than 2 Traffic. Even with manually triggered scans, Shodan only identified 7 as ICS hosts. This demonstrates that active scanning-based analysis is insufficient to understand current security practices in ICS communications. We show that 75.6 integrity protection, leaving those critical systems vulnerable to malicious attacks.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
01/14/2019

Uncovering Vulnerable Industrial Control Systems from the Internet Core

Industrial control systems (ICS) are managed remotely with the help of d...
research
08/12/2019

Identifying and characterizing ZMap scans: a cryptanalytic approach

Network scanning tools play a major role in Internet security. They are ...
research
11/09/2022

Detection of Sparse Anomalies in High-Dimensional Network Telescope Signals

Network operators and system administrators are increasingly overwhelmed...
research
11/12/2019

O Peer, Where Art Thou? Uncovering Remote Peering Interconnections at IXPs

Internet eXchange Points (IXPs) are Internet hubs that mainly provide th...
research
01/12/2023

LZR: Identifying Unexpected Internet Services

Internet-wide scanning is a commonly used research technique that has he...
research
09/02/2021

QUICsand: Quantifying QUIC Reconnaissance Scans and DoS Flooding Events

In this paper, we present first measurements of Internet background radi...
research
10/11/2021

Spoki: Unveiling a New Wave of Scanners through a Reactive Network Telescope

Large-scale Internet scans are a common method to identify victims of a ...

Please sign up or login with your details

Forgot password? Click here to reset