June 10, 2016
Faculty, graduate and undergraduate students,
You are cordially invited to my Masters thesis defense.
Title: Leveraging PLC ladder logic for signature based IDS rule generation
When: Thursday, June 23, 2016 at 2:30 PM
Where: Simrall Hall, Room 228
Candidate: Drew Richey
Degree: Masters, Electrical and Computer Engineering
Committee:
Dr. Sherif Abdelwahed
(Major Professor)
Dr. Thomas H. Morris
(Committee Member)
Dr. David A. Dampier
(Committee Member)
Abstract:
Industrial Control Systems (ICS) play a critical part in our world’s economy, supply chain and critical infrastructure. Securing the various types of ICS is of the utmost importance and has been a focus of much research for the last several years. At the heart of many defense in depth strategies is the signature based intrusion detection system (IDS). The signatures that define an IDS determine the effectiveness of the system. Existing methods for IDS signature creation do not leverage the information contained within the PLC ladder logic file. The ladder logic file is a rich source of information about the PLC control system. This thesis describes a method for parsing PLC ladder logic to extract address register information, data types and usage that can be used to better define the normal operation of the control system which will allow for rules to be created to detect abnormal activity.
Best Regards,
Drew Richey