Development of a Tailored Methodology and Forensic Toolkit for Industrial Control Systems Incident Response

Abstract

This thesis presents a methodology for incident response to identify anomalies and malicious adversary persistence within the networks responsible for the reliable operation of modern society s critical infrastructure. The chapters provide relevant background on the historical development and function of industrial control systems (ICS) and their unique security issues. The study of public technical data from intrusions into control systems produces a set of known adversary tactics for incorporation into the methodology. This work further documents the development of a repeatable technique to collect digital forensic artifacts from production control systems that is compatible with the strict operational constraints of these critical networks. The technique is then applied with a proof-of-concept hostand network-based toolkit for incident response that is tested against real-world data. The goal of the methodology and the supplementary toolkit is to elicit valuable, previously-unavailable findings with which to assess the scope of malicious intrusions into critical ICS networks.

Open PDF

Document Details

Document Type
Technical Report
Publication Date
Jun 01, 2014
Accession Number
ADA606880

Entities

People

  • Nicholas B. Carr

Organizations

  • Naval Postgraduate School

Tags

Communities of Interest

  • Cyber
  • Energy and Power Technologies
  • Engineered Resilient Systems
  • Space

DTIC Thesaurus Topics

  • Application Protocols
  • Application Software
  • Communication Channels
  • Computer Network Security
  • Computer Networks
  • Computer Programming
  • Computers
  • Control Systems
  • Cybersecurity
  • Digital Communications
  • Electronic Mail
  • Intrusion Detection
  • Intrusion Detectors
  • Network Computing
  • Network Protocols
  • Operating Systems
  • Scada

Fields of Study

  • Computer science

Readers

  • Business Analytics
  • Cybersecurity.
  • Systems Analysis and Design