Side Channel Based Intrusion Detection for Industrial Control Systems

White Papers

Industrial control systems are under increased scrutiny. Their security is historically subpar, and although measures are being taken by the manufacturers to remedy this, the large installed base of legacy systems cannot easily be updated with state-of-the-art security measures.

 

We propose a system that uses electromagnetic side channel measurements to detect behavioral changes of the software running on industrial control systems. To demonstrate the feasibility of this method, we show it is possible to profile and distinguish between even small changes in programs on Siemens S7-317 PLCs, using methods from cryptographic side channel analysis.