CRSYMay 21, 2019

Two Decades of SCADA Exploitation: A Brief History

arXiv:1905.08902v170 citations
Originality Synthesis-oriented
AI Analysis

It addresses security vulnerabilities in industrial control systems for stakeholders in critical infrastructure, but is incremental as it compiles and reviews existing attack data.

The paper analyzes known attacks on industrial SCADA systems by investigating publicly available exploits, reviewing different attack types and entry points, and introducing trends in exploitation and targeted campaigns.

Since the early 1960, industrial process control has been applied by electric systems. In the mid 1970's, the term SCADA emerged, describing the automated control and data acquisition. Since most industrial and automation networks were physically isolated, security was not an issue. This changed, when in the early 2000's industrial networks were opened to the public internet. The reasons were manifold. Increased interconnectivity led to more productivity, simplicity and ease of use. It decreased the configuration overhead and downtimes for system adjustments. However, it also led to an abundance of new attack vectors. In recent time, there has been a remarkable amount of attacks on industrial companies and infrastructures. In this paper, known attacks on industrial systems are analysed. This is done by investigating the exploits that are available on public sources. The different types of attacks and their points of entry are reviewed in this paper. Trends in exploitation as well as targeted attack campaigns against industrial enterprises are introduced.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes