A Digital Forensic Taxonomy For Programmable Logic Controller Data Artefacts

Research output: Chapter in Book/Report/Conference proceedingConference Contribution (Conference Proceeding)

4 Citations (Scopus)
23 Downloads (Pure)

Abstract

The growing complexity of industrial control systems (ICS) and increasing cyber attacks targeting critical infrastructures demand bespoke forensics techniques for Programmable Logic Controllers (PLCs). As they control their critical physical processes, PLCs form the backbone of many ICS. However, due to their unique characteristics and constraints, which include heterogeneous architectures, proprietary technologies and stringent real-time operational requirements, traditional digital forensic techniques may not be directly applicable.PLCs are intricate embedded devices with numerous distinct internal data artefacts, ranging from proprietary firmware to logic codes, safety logs, and process I/O values. Therefore, those tasked with PLC investigation must understand these intricacies and their underlying implications to effectively answer the forensic questions in the aftermath of an incident.To address this need, our paper presents the first tailored taxonomy for digital forensics on PLCs, systematically categorizing the various characteristics, forensic processes and considerations based on the stages involved in a forensic investigation. Furthermore, we employ our developed taxonomy to establish mappings between identified PLC data artefacts and their corresponding attributes, offering a contextualised interrelationships between these artefacts and the PLC forensic investigation steps.
Original languageEnglish
Title of host publication2023 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)
PublisherInstitute of Electrical and Electronics Engineers (IEEE)
Pages320-328
Number of pages9
ISBN (Electronic)9798350327205
ISBN (Print)9798350327212
DOIs
Publication statusPublished - 31 Jul 2023

Publication series

NameIEEE European Symposium on Security and Privacy Workshops (EuroS&PW)
PublisherIEEE
ISSN (Print)2768-0649
ISSN (Electronic)2768-0657

Keywords

  • PLC Forensics
  • ICS Security
  • Cyber forensics

Fingerprint

Dive into the research topics of 'A Digital Forensic Taxonomy For Programmable Logic Controller Data Artefacts'. Together they form a unique fingerprint.

Cite this