{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,24]],"date-time":"2026-06-24T15:03:19Z","timestamp":1782313399948,"version":"3.54.5"},"publisher-location":"Cham","reference-count":28,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030220372","type":"print"},{"value":"9783030220389","type":"electronic"}],"license":[{"start":{"date-parts":[[2019,1,1]],"date-time":"2019-01-01T00:00:00Z","timestamp":1546300800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2019]]},"DOI":"10.1007\/978-3-030-22038-9_6","type":"book-chapter","created":{"date-parts":[[2019,6,9]],"date-time":"2019-06-09T23:02:31Z","timestamp":1560121351000},"page":"109-132","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":19,"title":["Overshadow PLC to Detect Remote Control-Logic Injection Attacks"],"prefix":"10.1007","author":[{"given":"Hyunguk","family":"Yoo","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sushma","family":"Kalle","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jared","family":"Smith","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Irfan","family":"Ahmed","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2019,6,6]]},"reference":[{"key":"6_CR1","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"274","DOI":"10.1007\/3-540-36084-0_15","volume-title":"Recent Advances in Intrusion Detection","author":"T Toth","year":"2002","unstructured":"Toth, T., Kruegel, C.: Accurate buffer overflow detection via abstract pay load execution. In: Wespi, A., Vigna, G., Deri, L. (eds.) RAID 2002. LNCS, vol. 2516, pp. 274\u2013291. Springer, Heidelberg (2002). https:\/\/doi.org\/10.1007\/3-540-36084-0_15"},{"key":"6_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"203","DOI":"10.1007\/978-3-540-30143-1_11","volume-title":"Recent Advances in Intrusion Detection","author":"K Wang","year":"2004","unstructured":"Wang, K., Stolfo, S.J.: Anomalous payload-based network intrusion detection. In: Jonsson, E., Valdes, A., Almgren, M. (eds.) RAID 2004. LNCS, vol. 3224, pp. 203\u2013222. Springer, Heidelberg (2004). https:\/\/doi.org\/10.1007\/978-3-540-30143-1_11"},{"key":"6_CR3","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"284","DOI":"10.1007\/11663812_15","volume-title":"Recent Advances in Intrusion Detection","author":"R Chinchani","year":"2006","unstructured":"Chinchani, R., van den Berg, E.: A fast static analysis approach to detect exploit code inside network flows. In: Valdes, A., Zamboni, D. (eds.) RAID 2005. LNCS, vol. 3858, pp. 284\u2013308. Springer, Heidelberg (2006). https:\/\/doi.org\/10.1007\/11663812_15"},{"key":"6_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"226","DOI":"10.1007\/11856214_12","volume-title":"Recent Advances in Intrusion Detection","author":"K Wang","year":"2006","unstructured":"Wang, K., Parekh, J.J., Stolfo, S.J.: Anagram: a content anomaly detector resistant to mimicry attack. In: Zamboni, D., Kruegel, C. (eds.) RAID 2006. LNCS, vol. 4219, pp. 226\u2013248. Springer, Heidelberg (2006). https:\/\/doi.org\/10.1007\/11856214_12"},{"key":"6_CR5","unstructured":"Fogla, P., Sharif, M., Perdisci, R., Kolesnikov, O., Lee, W.: Polymorphic blending attacks. In: Proceedings of the 15th Conference on USENIX Security Symposium (2006)"},{"issue":"6","key":"6_CR6","doi-asserted-by":"publisher","first-page":"89","DOI":"10.1145\/1273442.1250746","volume":"42","author":"Nicholas Nethercote","year":"2007","unstructured":"Nethercote, N., Seward, J.: Valgrind: a framework for heavyweight dynamic binary instrumentation, pp. 89\u2013100 (2007)","journal-title":"ACM SIGPLAN Notices"},{"key":"6_CR7","doi-asserted-by":"crossref","unstructured":"Fovino, I.N., Carcano, A., Murel, T.D.L., Trombetta, A., Masera, M.: Modbus\/DNP3 state-based intrusion detection system, pp. 729\u2013736 (2010)","DOI":"10.1109\/ISIE.2010.5637577"},{"key":"6_CR8","unstructured":"Falliere, N., Murchu, L.O., Chien, E.: W32. stuxnet dossier. White paper, Symantec Corporation, Security Response. 5(6), 29 (2011)"},{"key":"6_CR9","unstructured":"Serebryany, K., Bruening, D., Potapenko, A., Vyukov, D.: AddressSanitizer: A fast address sanity checker, pp. 28\u201328 (2012)"},{"issue":"12","key":"6_CR10","doi-asserted-by":"publisher","first-page":"44","DOI":"10.1109\/MC.2012.325","volume":"45","author":"I Ahmed","year":"2012","unstructured":"Ahmed, I., Obermeier, S., Naedele, M., Richard III, G.G.: SCADA systems: challenges for forensic investigators. Computer 45(12), 44\u201351 (2012)","journal-title":"Computer"},{"key":"6_CR11","unstructured":"IEC 61131\u20133 Ed. 3.0 b:2013, Programmable controllers - Part 3: Programming languages. Standard, International Electrotechnical Commission (2013)"},{"key":"6_CR12","unstructured":"IEC 61850\u20135 Ed. 2.0:2013, Communication Networks and Systems for Power Utility Automation - Part 5: Communication requirements for functions and device models. Standard, International Electrotechnical Commission (2013)"},{"key":"6_CR13","unstructured":"Lee, R.M., Assante, M.J., Conway, T.: German Steel Mill Cyber Attack. Technical report, SANS, USA (2014)"},{"key":"6_CR14","unstructured":"ICS Focused Malware. https:\/\/ics-cert.us-cert.gov\/advisories\/ICSA-14-178-01 (2014). Accessed 03 June 2018"},{"key":"6_CR15","doi-asserted-by":"crossref","unstructured":"Had\u017eiosmanovi\u0107, D., Sommer, R., Zambon, E., Hartel, P.H.: Through the eye of the PLC: Semantic security monitoring for industrial processes. In: Proceedings of the 30th Annual Computer Security Applications Conference (ACSAC) (2014)","DOI":"10.1145\/2664243.2664277"},{"key":"6_CR16","doi-asserted-by":"crossref","unstructured":"McLaughlin, S.E., Zonouz, S.A., Pohly, D.J., McDaniel, P.D.: A trusted safety verifier for process controller code. In: Proceeding of the 21st Network and Distributed System Security Symposium (NDSS) (2014)","DOI":"10.14722\/ndss.2014.23043"},{"key":"6_CR17","unstructured":"Cyber-Attack Against Ukrainian Critical Infrastructure. https:\/\/ics-cert.us-cert.gov\/alerts\/IR-ALERT-H-16-056-01 (2016). Accessed 03 June 2018"},{"key":"6_CR18","unstructured":"ICS-CERT Annual Vulnerability Coordination Report. Report, National Cybersecurity and Communications Integration Center (2016)"},{"key":"6_CR19","doi-asserted-by":"crossref","unstructured":"Ahmed, I., Roussev, V., Johnson, W., Senthivel, S., Sudhakaran, S.: A SCADA system testbed for cybersecurity and forensic research and pedagogy. In: Proceedings of the 2nd Annual Industrial Control System Security Workshop (ICSS) (2016)","DOI":"10.1145\/3018981.3018984"},{"key":"6_CR20","unstructured":"CRASHOVERRIDE Malware (2017). https:\/\/ics-cert.us-cert.gov\/alerts\/ICS-ALERT-17-206-01 . Accessed 03 June 2018"},{"issue":"7","key":"6_CR21","doi-asserted-by":"crossref","first-page":"951","DOI":"10.1093\/bioinformatics\/btw771","volume":"33","author":"M Cinelli","year":"2017","unstructured":"Cinelli, M., et al.: Feature selection using a one dimensional na\u00efve Bayes\u2019 classifier increases the accuracy of support vector machine classification of CDR3 repertoires. Bioinformatics 33(7), 951\u2013955 (2017)","journal-title":"Bioinformatics"},{"issue":"6","key":"6_CR22","doi-asserted-by":"publisher","first-page":"18","DOI":"10.1109\/MSP.2017.4251102","volume":"15","author":"I Ahmed","year":"2017","unstructured":"Ahmed, I., Obermeier, S., Sudhakaran, S., Roussev, V.: Programmable logic controller forensics. IEEE Secur. Priv. 15(6), 18\u201324 (2017a)","journal-title":"IEEE Secur. Priv."},{"key":"6_CR23","doi-asserted-by":"publisher","first-page":"S57","DOI":"10.1016\/j.diin.2017.06.012","volume":"22","author":"S Senthivel","year":"2017","unstructured":"Senthivel, S., Ahmed, I., Roussev, V.: SCADA network forensics of the PCCC protocol. Digit. Invest. 22, S57\u2013S65 (2017b)","journal-title":"Digit. Invest."},{"key":"6_CR24","doi-asserted-by":"crossref","unstructured":"Senthivel, S., Dhungana, S., Yoo, H., Ahmed, I., Roussev, V.: Denial of engineering operations attacks in industrial control systems. In: Proceeding of the 8th ACM Conference on Data and Application Security and Privacy (CODASPY) (2018)","DOI":"10.1145\/3176258.3176319"},{"key":"6_CR25","unstructured":"Digital Bond\u2019s IDS\/IPS rules for ICS (2018). https:\/\/github.com\/digitalbond\/Quickdraw-Snort . Accessed 19 July 2018"},{"key":"6_CR26","unstructured":"Sushma K., Nehal A., Hyunguk Y., Irfan A.: CLIK on PLCs! attacking control logic with decompilation and virtual PLC. In: Proceeding of the 2019 NDSS Workshop on Binary Analysis Research (BAR) (2019)"},{"key":"6_CR27","unstructured":"Hyunguk Y., Irfan A.: Control logic injection attacks on industrial control systems. In: 34th IFIP International Conference on Information Security and Privacy Protection (2019)"},{"key":"6_CR28","unstructured":"Tofino Xenon Security Appliance (2019). https:\/\/www.tofinosecurity.com\/products\/tofino-xenon-security-appliance . Accessed 17 April 2019"}],"container-title":["Lecture Notes in Computer Science","Detection of Intrusions and Malware, and Vulnerability Assessment"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-22038-9_6","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,9,17]],"date-time":"2023-09-17T09:24:30Z","timestamp":1694942670000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-030-22038-9_6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019]]},"ISBN":["9783030220372","9783030220389"],"references-count":28,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-22038-9_6","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019]]},"assertion":[{"value":"6 June 2019","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"DIMVA","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Gothenburg","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Sweden","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2019","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"19 June 2019","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20 June 2019","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"dimva2019","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.dimva2019.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"dimca2019.hotcrp.com","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"80","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"23","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"29% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"6","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information"}}]}}