Walking Under the Ladder Logic: PLC-VBS, a PLC Control Logic Vulnerability Discovery Tool
Sam Maesschalck, Alexander Staves, Richard Derbyshire, Benjamin Green,, David Hutchison

TL;DR
This paper introduces PLC-VBS, a tool designed to identify vulnerabilities in PLC control logic within industrial control systems, enhancing risk assessment accuracy by focusing on operational process vulnerabilities.
Contribution
The paper presents a novel vulnerability discovery tool, PLC-VBS, specifically targeting PLC control logic in ICS environments, which improves understanding of operational process risks.
Findings
PLC-VBS effectively identifies PLC control logic vulnerabilities.
The tool enhances risk assessment by focusing on operational process impacts.
It provides detailed insights into potential exploitation consequences.
Abstract
Cyber security risk assessments provide a pivotal starting point towards the understanding of existing risk exposure, through which suitable mitigation strategies can be formed. Where risk is viewed as a product of threat, vulnerability, and impact, understanding each element is of equal importance. This can be a challenge in Industrial Control System (ICS) environments, where adopted technologies are typically not only bespoke, but interact directly with the physical world. To date, existing vulnerability identification has focused on traditional vulnerability categories. While this provides risk assessors with a baseline understanding, and the ability to hypothesize on potential resulting impacts, it is high level, operating at a level of abstraction that would be viewed as incomplete within a traditional information system context. The work presented in this paper takes the…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSmart Grid Security and Resilience · Information and Cyber Security · Risk and Safety Analysis
