Betts, M., Stirland, J., Olajide, F. ORCID: 0000-0003-1627-6637, Jones, K. and Janicke, H., 2016. Developing a state of the art methodology and toolkit for ICS SCADA forensics. International Journal of Industrial Control Systems Security, 1 (2), pp. 44-56.
|
Text
1597713_Olajide.pdf - Published version Download (1MB) | Preview |
Abstract
Supervisory Control and Data Acquisition (SCADA) systems are used in different Critical National Infrastructure (CNI), including Electric Power, Oil & Gas, Manufacturing, Utility, Transportation services and others. The underpinning control systems have unique characteristics such as being real-time and safety critical. Therefore interference and disruption of the services from cyber attack poses a significant risk to; the environment, properties, economies and human lives. Responding to such events in not trivial, and recovering the required forensic evidence to understand the cause and consequence of such an event is key. Further, developing a suitable incident response methodology to identify evidential artefacts of the causes of disruption is crucial, should security mechanisms fail. In this paper we present the state of the art methodology forensic toolkit for cyber incident response on Industrial Control System (ICS) environment of SCADA plus evaluate the applicability of current IT forensic tools and the requirements of an 'ICS forensic toolbag'. The research work presents an experimental case study of a malware USB device based attack, a man in the middle attack and a remote access attack.
Item Type: | Journal article | ||||||
---|---|---|---|---|---|---|---|
Publication Title: | International Journal of Industrial Control Systems Security | ||||||
Creators: | Betts, M., Stirland, J., Olajide, F., Jones, K. and Janicke, H. | ||||||
Publisher: | Infonomics Society | ||||||
Date: | 6 December 2016 | ||||||
Volume: | 1 | ||||||
Number: | 2 | ||||||
Identifiers: |
|
||||||
Divisions: | Schools > School of Science and Technology | ||||||
Record created by: | Laura Ward | ||||||
Date Added: | 26 Sep 2022 10:42 | ||||||
Last Modified: | 26 Sep 2022 10:42 | ||||||
URI: | https://irep.ntu.ac.uk/id/eprint/47114 |
Actions (login required)
Edit View |
Views
Views per month over past year
Downloads
Downloads per month over past year