Taking Control: Design and Implementation of Botnets for Cyber-Physical Attacks with CPSBot

02/01/2018
by   Daniele Antonioli, et al.
0

Recently, botnets such as Mirai and Persirai targeted IoT devices on a large scale. We consider attacks by botnets on cyber-physical systems (CPS), which require advanced capabilities such as controlling the physical processes in real-time. Traditional botnets are not suitable for this goal mainly because they lack process control capabilities, are not optimized for low latency communication, and bots generally do not leverage local resources. We argue that such attacks would require cyber-physical botnets. A cyber-physical botnet needs coordinated and heterogeneous bots, capable of performing adversarial control strategies while subject to the constraints of the target CPS. In this work, we present CPSBot, a framework to build cyber-physical botnets. We present an example of a centralized CPSBot targeting a centrally controlled system and a decentralized CPSBot targeting a system distributed control. We implemented the former CPSBot using MQTT for the C&C channel and Modbus/TCP as the target network protocol and we used it to launch several attacks on real and simulated Water Distribution. We evaluate our implementation with distributed reply and distributed impersonation attacks on a CPS, and show that malicious control with negligible latency is possible.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
06/27/2018

Towards a formal notion of impact metric for cyber-physical attacks (full version)

Industrial facilities and critical infrastructures are transforming into...
research
02/15/2021

Securing Connected Vehicle Applications with an Efficient Dual Cyber-Physical Blockchain Framework

While connected vehicle (CV) applications have the potential to revoluti...
research
07/07/2023

Generation of Time-Varying Impedance Attacks Against Haptic Shared Control Steering Systems

The safety-critical nature of vehicle steering is one of the main motiva...
research
10/14/2022

Let's Talk Through Physics! Covert Cyber-Physical Data Exfiltration on Air-Gapped Edge Devices

Although organizations are continuously making concerted efforts to hard...
research
04/30/2018

Checking is Believing: Event-Aware Program Anomaly Detection in Cyber-Physical Systems

Securing cyber-physical systems (CPS) against malicious attacks is of pa...
research
05/26/2023

CyPhERS: A Cyber-Physical Event Reasoning System providing real-time situational awareness for attack and fault response

Cyber-physical systems (CPSs) constitute the backbone of critical infras...
research
06/12/2023

Residual-Based Detection of Attacks in Cyber-Physical Inverter-Based Microgrids

This paper discusses the challenges faced by cyber-physical microgrids (...

Please sign up or login with your details

Forgot password? Click here to reset