BayesImposter: Bayesian Estimation Based .bss Imposter Attack on Industrial Control Systems
Anomadarshi Barua, Lelin Pan, and Mohammad Abdullah Al Faruque

TL;DR
BayesImposter introduces a Bayesian estimation-based attack on industrial control systems that efficiently duplicates memory pages, enabling predictive false command injection and adversarial control with severe real-world consequences.
Contribution
This work presents a novel, domain-specific attack primitive using Bayesian estimation to efficiently duplicate memory pages in ICS cloud settings, improving over brute-force methods.
Findings
BayesImposter reduces memory usage to 4 KB from GB and attack time to 13 minutes from hours.
It successfully predicts and injects false commands into ICS PLCs, causing equipment damage.
The attack demonstrates potential for adversarial control leading to severe safety hazards.
Abstract
Over the last six years, several papers used memory deduplication to trigger various security issues, such as leaking heap-address and causing bit-flip in the physical memory. The most essential requirement for successful memory deduplication is to provide identical copies of a physical page. Recent works use a brute-force approach to create identical copies of a physical page that is an inaccurate and time-consuming primitive from the attacker's perspective. Our work begins to fill this gap by providing a domain-specific structured way to duplicate a physical page in cloud settings in the context of industrial control systems (ICSs). Here, we show a new attack primitive - \textit{BayesImposter}, which points out that the attacker can duplicate the .bss section of the target control DLL file of cloud protocols using the \textit{Bayesian estimation} technique. Our approach results in…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsCloud Data Security Solutions · Security and Verification in Computing · Digital and Cyber Forensics
