Watch Me, but Don't Touch Me! Contactless Control Flow Monitoring via Electromagnetic Emanations
Yi Han, Sriharsha Etigowni, Hua Li, Saman Zonouz, Athina Petropulu

TL;DR
Zeus is a contactless, electromagnetic emission-based security monitor for industrial PLCs that ensures control flow integrity without performance overhead, providing a secure air-gap and high accuracy in real-world scenarios.
Contribution
This paper introduces Zeus, a novel contactless monitoring system using electromagnetic emissions and neural networks to verify PLC control flow integrity in real-time.
Findings
Achieved 98.9% accuracy in distinguishing legitimate and malicious executions
Zero overhead on PLC execution due to contactless monitoring
Successfully implemented and tested on a commercial industrial PLC
Abstract
Trustworthy operation of industrial control systems depends on secure and real-time code execution on the embedded programmable logic controllers (PLCs). The controllers monitor and control the critical infrastructures, such as electric power grids and healthcare platforms, and continuously report back the system status to human operators. We present Zeus, a contactless embedded controller security monitor to ensure its execution control flow integrity. Zeus leverages the electromagnetic emission by the PLC circuitry during the execution of the controller programs. Zeus's contactless execution tracking enables non-intrusive monitoring of security-critical controllers with tight real-time constraints. Those devices often cannot tolerate the cost and performance overhead that comes with additional traditional hardware or software monitoring modules. Furthermore, Zeus provides an air-gap…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
