KIT | KIT-Bibliothek | Impressum | Datenschutz

Show Me What You Got: Vulnerabilities of Industrial Components Revealed by Automated Blackbox Testing:

Borcherding, Anne 1; Giraud, Mark 1; Tzigiannis, Laura 1
1 Fraunhofer-Institut für Optronik, Systemtechnik und Bildauswertung (IOSB)

Abstract:

Operational Technology Components (OTCs) that control and monitor industrial processes are a valuable target for attackers. Reducing the likelihood of successful attacks requires identifying, assessing, and mitigating vulnerabilities in those components. To achieve this, blackbox penetration testing can be applied. However, traditional approaches to penetration testing do not take the specificities of OTCs, such as their focus on availability and their resource constraints, into account. Thus, we describe a test strategy specifically targeting OTCs, and consequently apply this strategy to ten OTCs. Our experiments reveal findings for all considered OTCs, including crashes, hangs, and information on outdated software. Most crashes or hangs are concerned with SNMP and TCP (6,418 and 2,864 findings in total, respectively). We analyzed some of the more severe crashes and found that they were caused either by overload or unexpected TCP options. Moreover, we identified limitations of the u sed tools with respect to fingerprinting, severity assessment, and crash detection.


Download
Originalveröffentlichung
DOI: 10.5220/0014355200004061
Zugehörige Institution(en) am KIT Institut für Anthropomatik und Robotik (IAR)
Institut für Informationssicherheit und Verlässlichkeit (KASTEL)
Publikationstyp Proceedingsbeitrag
Publikationsjahr 2026
Sprache Englisch
Identifikator ISBN: 978-989-758-800-6
KITopen-ID: 1000192090
HGF-Programm 46.23.01 (POF IV, LK 01) Methods for Engineering Secure Systems
Weitere HGF-Programme 46.23.04 (POF IV, LK 01) Engineering Security for Production Systems
Erschienen in Proceedings of the 12th International Conference on Information Systems Security and Privacy
Veranstaltung 12th International Conference on Information Systems Security and Privacy (ICISSP 2026), Marbella, Spanien, 04.03.2026 – 06.03.2026
Verlag SciTePress
Seiten 240–251
Externe Relationen Siehe auch
Schlagwörter Operational Technology, Vulnerability Scanning, Fuzzing
Nachgewiesen in OpenAlex
KIT – Die Universität in der Helmholtz-Gemeinschaft
KITopen Landing Page