Usability Study of Security Features in Programmable Logic Controllers
Karen Li, Kopo M. Ramokapane, Awais Rashid

TL;DR
This study investigates the usability challenges in configuring security features of Programmable Logic Controllers (PLCs), revealing that complex interfaces and misconceptions hinder effective security management in industrial environments.
Contribution
First empirical usability study on PLC security configuration highlighting design issues and providing recommendations for improved security usability in industrial control systems.
Findings
Unfamiliar labels and misleading terminology complicate security setup.
Misperceptions about security controls are common among users.
Design constraints like safety and infrequent updates pose usability challenges.
Abstract
Programmable Logic Controllers (PLCs) drive industrial processes critical to society, for example, water treatment and distribution, electricity and fuel networks. Search engines, e.g., Shodan, have highlighted that PLCs are often left exposed to the Internet, one of the main reasons being the misconfigurations of security settings. This leads to the question - why do these misconfigurations occur and, specifically, whether usability of security controls plays a part. To date, the usability of configuring PLC security mechanisms has not been studied. We present the first investigation through a task based study and subsequent semi-structured interviews (N=19). We explore the usability of PLC connection configurations and two key security mechanisms (i.e., access levels and user administration). We find that the use of unfamiliar labels, layouts and misleading terminology exacerbates an…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsPrivacy, Security, and Data Protection · Information and Cyber Security · Advanced Malware Detection Techniques
