{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,27]],"date-time":"2025-03-27T06:40:49Z","timestamp":1743057649817,"version":"3.40.3"},"publisher-location":"Cham","reference-count":46,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030346461"},{"type":"electronic","value":"9783030346478"}],"license":[{"start":{"date-parts":[[2019,1,1]],"date-time":"2019-01-01T00:00:00Z","timestamp":1546300800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2019,1,1]],"date-time":"2019-01-01T00:00:00Z","timestamp":1546300800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2019]]},"DOI":"10.1007\/978-3-030-34647-8_14","type":"book-chapter","created":{"date-parts":[[2019,11,18]],"date-time":"2019-11-18T16:02:52Z","timestamp":1574092972000},"page":"271-288","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Modeling and Machine-Checking Bump-in-the-Wire Security for Industrial Control Systems"],"prefix":"10.1007","author":[{"given":"Mehdi","family":"Sabraoui","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jeffrey","family":"Hieb","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Adrian","family":"Lauf","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"James","family":"Graham","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2019,11,19]]},"reference":[{"key":"14_CR1","unstructured":"M. Abrams and J. Weiss, Malicious control system cyber security attack case study \u2013 Maroochy Water Services, presented at the Twenty-Fourth Annual Computer Security Applications Conference, 2008"},{"key":"14_CR2","doi-asserted-by":"publisher","first-page":"345","DOI":"10.1016\/j.jnca.2015.05.015","volume":"59","author":"Raphael Amoah","year":"2016","unstructured":"R. Amoah, S. Camtepe and E. Foo, Formal modeling and analysis of DNP3 Secure Authentication, Journal of Network and Computer Applications, vol. 59, pp. 345\u2013360, 2016","journal-title":"Journal of Network and Computer Applications"},{"key":"14_CR3","unstructured":"N. Anderson, Confirmed: US and Israel created Stuxnet, lost control of it, Ars Technica, June 1, 2012"},{"key":"14_CR4","doi-asserted-by":"crossref","unstructured":"A. Appel, Verification of a cryptographic primitive: SHA-256, ACM Transactions on Programming Languages and Systems, vol. 37(2), article no. 7, 2015","DOI":"10.1145\/2701415"},{"key":"14_CR5","unstructured":"Azure, Azure Cosmos TLA+ specifications, GitHub (github.com\/Azure\/azure-cosmos-tla), 2018"},{"key":"14_CR6","doi-asserted-by":"crossref","unstructured":"M. Bartock, J. Cichonski, M. Souppaya, M. Smith, G. Witte and K. Scarfone, Guide for Cybersecurity Event Recovery, NIST Special Publication 800-184, National Institute of Standards and Technology, Gaithersburg, Maryland, 2016","DOI":"10.6028\/NIST.SP.800-184"},{"key":"14_CR7","unstructured":"L. Beringer, A. Petcher, K. Ye and A. Appel, Verified correctness and security of OpenSSL HMAC, Proceedings of the Twenty-Fourth USENIX Security Symposium, pp. 207\u2013221, 2015"},{"key":"14_CR8","unstructured":"Blue Coat Systems, Blue Coat ICS Protection, Scanner Station Version, USB Malware Defense for Industrial Computers, User Guide, Version 5.3.1, Sunnyvale, California (docplayer.net\/18790337-Blue-coat-ics-protection-scanner-station-version.html), 2014"},{"key":"14_CR9","unstructured":"P. Cichonski, T. Millar, T. Grance and K. Scarfone, Computer Security Incident Handling Guide, NIST Special Publication 800-61, Revision 2, National Institute of Standards and Technology, Gaithersburg, Maryland, 2012"},{"key":"14_CR10","unstructured":"Control Microsystems, DNP3 User and Reference Manual, Kanata, Canada, 2007"},{"key":"14_CR11","unstructured":"K. Curtis, A DNP3 Protocol Primer (Revision A), DNP3 Users Group, Calgary, Canada (www.dnp.org\/Portals\/0\/AboutUs\/DNP3%20Primer%20Rev%20A.pdf), 2005"},{"key":"14_CR12","first-page":"67","volume-title":"IFIP Advances in Information and Communication Technology","author":"Samuel East","year":"2009","unstructured":"S. East, J. Butts, M. Papa and S. Shenoi, A taxonomy of attacks on the DNP3 protocol, in Critical Infrastructure Protection III, C. Palmer and S. Shenoi (Eds.), Springer, Berlin Heidelberg, Germany, pp. 67\u201381, 2009"},{"key":"14_CR13","doi-asserted-by":"crossref","unstructured":"J. Edmonds, M. Papa and S. Shenoi, Security analysis of multilayer SCADA protocols, in Critical Infrastructure Protection, E. Goetz and S. Shenoi (Eds.), Springer, Boston, Massachusetts, pp. 205\u2013221. 2007","DOI":"10.1007\/978-0-387-75462-8_15"},{"key":"14_CR14","unstructured":"N. Falliere, Stuxnet introduces the first known rootkit for industrial control systems, Symantec Security Response Blog (www.symantec.com\/connect\/blogs\/stuxnet-introduces-first-known-rootkit-scada-devices), August 6, 2010"},{"key":"14_CR15","unstructured":"N. Falliere, L. O\u2019Murchu and E. Chien, W32.Stuxnet Dossier, Version 1.4, Symantec, Mountain View, California, 2011"},{"key":"14_CR16","unstructured":"M. Fernandez, G. Klein, I. Kuz and T. Murray, CAmkES Formalization of a Component Platform, National Information and Communications Technology Research Centre of Excellence (NICTA), Sydney, Australia, 2012"},{"key":"14_CR17","doi-asserted-by":"crossref","unstructured":"K. Fisher, J. Launchbury and R. Richards, The HACMS Program: Using formal methods to eliminate exploitable bugs, Philosophical Transactions, Series A, Mathematical Physical and Engineering Sciences, vol. 375(2104), article no. 20150401, 2017","DOI":"10.1098\/rsta.2015.0401"},{"key":"14_CR18","unstructured":"T. Gary, ICS\/SCADA smart scanning: Discover and assess IT-based systems in converged IT\/OT environments, Tenable Blog, June 12, 2018"},{"key":"14_CR19","doi-asserted-by":"crossref","unstructured":"G. Gilchrist, Secure authentication for DNP3, Proceedings of the IEEE Power and Energy Society General Meeting \u2013 Conversion and Delivery of Electrical Energy in the 21st Century, 2008","DOI":"10.1109\/PES.2008.4596147"},{"key":"14_CR20","unstructured":"J. Hieb, J. Graham, J. Schreiver and K. Moss, Security preprocessor for industrial control networks, Proceedings of the Seventh International Conference on Information Warfare and Security, pp. 130\u2013137, 2012"},{"issue":"7","key":"14_CR21","doi-asserted-by":"publisher","first-page":"498","DOI":"10.1016\/j.cose.2006.03.001","volume":"25","author":"Vinay M. Igure","year":"2006","unstructured":"V. Igure, S. Laughter and R. Williams, Security issues in SCADA networks, Computers and Security, vol. 25(7), pp. 498\u2013506, 2006","journal-title":"Computers & Security"},{"key":"14_CR22","unstructured":"Industrial Control Systems Cyber Emergency Response Team (ICS-CERT), Advisory (ICSA-12-231-01B), Sixnet Universal Protocol Undocumented Function Codes (Update B), Idaho Falls, Idaho (www.us-cert.gov\/ics\/advisories\/ICSA-13-231-01B), September 17, 2013"},{"key":"14_CR23","unstructured":"Industrial Control Systems Cyber Emergency Response Team (ICS-CERT), ICS-CERT Advisories, Idaho Falls, Idaho (ics-cert.us-cert.gov\/advisories), 2019"},{"key":"14_CR24","unstructured":"Kaspersky Lab ICS CERT, Threat Landscape for Industrial Automation Systems in the Second Half of 2016, Kaspersky Lab, Moscow, Russia, 2017"},{"key":"14_CR25","unstructured":"Kaspersky Lab ICS CERT, Threat Landscape for Industrial Automation Systems in H2 2017, Kaspersky Lab, Moscow, Russia, 2018"},{"issue":"9","key":"14_CR26","doi-asserted-by":"publisher","first-page":"91","DOI":"10.1145\/1631687.1596566","volume":"44","author":"Gerwin Klein","year":"2009","unstructured":"G. Klein, P. Derrin and K. Elphinstone, Experience report: seL4: Formally verifying a high-performance microkernel, Proceedings of the Fourteenth ACM SIGPLAN International Conference on Functional Programming, pp. 91\u201396, 2009","journal-title":"ACM SIGPLAN Notices"},{"key":"14_CR27","doi-asserted-by":"crossref","unstructured":"G. Klein, K. Elphinstone, G. Heiser, J. Andronick, D. Cock, P. Derrin, D. Elkaduwe, K. Engelhardt, R. Kolanski, M. Norrish, T. Sewell, H. Tuch and S. Winwood, seL4: Formal verification of an OS kernel, Proceedings of the Twenty-Second ACM Symposium on Operating Systems Principles, pp. 207\u2013220, 2009","DOI":"10.1145\/1629575.1629596"},{"key":"14_CR28","unstructured":"D. Kuhn and J. Dray, Formal specification and verification of control software for cryptographic equipment, Proceedings of the Sixth Annual Computer Security Applications Conference, pp. 32\u201343, 1990"},{"issue":"5","key":"14_CR29","doi-asserted-by":"publisher","first-page":"687","DOI":"10.1016\/j.jss.2006.08.039","volume":"80","author":"Ihor Kuz","year":"2007","unstructured":"I. Kuz, Y. Liu, I. Gorton and G. Heiser, CAmkES: A component model for secure microkernel-based embedded systems, Journal of Systems and Software, vol. 80(5), pp. 687\u2013699, 2007","journal-title":"Journal of Systems and Software"},{"issue":"3","key":"14_CR30","doi-asserted-by":"publisher","first-page":"872","DOI":"10.1145\/177492.177726","volume":"16","author":"Leslie Lamport","year":"1994","unstructured":"L. Lamport, The temporal logic of actions, ACM Transactions on Programming Languages and Systems, vol. 16(3), pp. 872\u2013923, 1994","journal-title":"ACM Transactions on Programming Languages and Systems"},{"key":"14_CR31","unstructured":"L. Lamport, Specifying Systems: The TLA+ Language and Tools for Hardware and Software Engineers, Addison-Wesley, Boston, Massachusetts, 2002"},{"key":"14_CR32","unstructured":"L. Lamport, The TLA Home Page (lamport.azurewebsites.net\/tla\/tla.html), December 6, 2018"},{"key":"14_CR33","unstructured":"H. Mackenzie, SCADA security basics: Why industrial networks are different than IT networks, Tofino Security Blog, October 31, 2012"},{"key":"14_CR34","doi-asserted-by":"publisher","first-page":"4","DOI":"10.1016\/j.ijcip.2017.10.001","volume":"19","author":"Luis Mart\u00edn-Liras","year":"2017","unstructured":"L. Martin-Liras, M. Prada, J. Fuertes, A. Moran, S. Alonso and M. Dominguez, Comparative analysis of the security of configuration protocols for industrial control devices, International Journal of Critical Infrastructure Protection, vol. 19, pp. 4\u201315, 2017","journal-title":"International Journal of Critical Infrastructure Protection"},{"key":"14_CR35","unstructured":"Modbus Organization, Modbus over Serial Line: Specification and Implementation Guide, V1.02, Hopkinton, Massachusetts (www.modbus.org\/docs\/Modbus_over_serial_line_V1_02.pdf), 2006"},{"key":"14_CR36","unstructured":"National Institute of Standards and Technology, Framework for Improving Critical Infrastructure Cybersecurity, Version 1.1, Gaithersburg, Maryland, 2018"},{"key":"14_CR37","unstructured":"C. Newcombe, T. Rath, F. Zhang, B. Munteanu, M. Brooker and M. Deardeuff, Use of Formal Methods at Amazon Web Services, Amazon, Seattle, Washington (lamport.azurewebsites.net\/tla\/formal-methods-amazon.pdf), 2014"},{"key":"14_CR38","unstructured":"B. Obama, Presidential Policy Directive 21: Critical Infrastructure Security and Resilience (PPD-21), The White House, Washington, DC, February 12, 2013"},{"key":"14_CR39","unstructured":"M. Permann, K. Lee, J. Hammer and K. Rohde, Mitigations for security vulnerabilities found in control system networks, presented at the Sixteenth Annual Joint ISA POWID\/EPRI Controls and Instrumentation Conference, 2006"},{"issue":"5","key":"14_CR40","doi-asserted-by":"publisher","first-page":"12","DOI":"10.1145\/1067627.806586","volume":"15","author":"J. M. Rushby","year":"1981","unstructured":"J. Rushby, Design and verification of secure systems, Proceedings of the Eighth ACM Symposium on Operating Systems Principles, pp. 12\u201321, 1981","journal-title":"ACM SIGOPS Operating Systems Review"},{"key":"14_CR41","doi-asserted-by":"crossref","unstructured":"K. Scarfone and P. Mell, Guide to Intrusion Detection and Prevention Systems (IDPS), NIST Special Publication 800-94, National Institute of Standards and Technology, Gaithersburg, Maryland, 2007","DOI":"10.6028\/NIST.SP.800-94"},{"key":"14_CR42","unstructured":"U. Shamir, Analyzing a New Variant of BlackEnergy 3: Likely Insider-Based Execution, SentinelOne, Mountain View, California, 2016"},{"key":"14_CR43","unstructured":"K. Stouffer, J. Falco and K. Scarfone, Guide to Industrial Control Systems (ICS) Security, NIST Special Publication 800-82, National Institute of Standards and Technology, Gaithersburg, Maryland, 2011"},{"issue":"3","key":"14_CR44","doi-asserted-by":"publisher","first-page":"30","DOI":"10.1016\/j.tej.2017.02.006","volume":"30","author":"Julia E. Sullivan","year":"2017","unstructured":"J. Sullivan and D. Kamensky, How cyber-attacks in Ukraine show the vulnerability of the U.S. power grid, The Electricity Journal, vol. 30(3), pp. 30\u201335, 2017","journal-title":"The Electricity Journal"},{"key":"14_CR45","unstructured":"United Nations Security Council Counter-Terrorism Committee Executive Directorate (CTED) and United Nations Office of Counter-Terrorism, The Protection of Critical Infrastructure against Terrorist Attacks: Compendium of Good Practices, Geneva, Switzerland, 2018"},{"key":"14_CR46","unstructured":"D. Wagner, Infrastructure under attack, Risk Management, vol. 63(8), pp. 28\u201333, 2016"}],"container-title":["IFIP Advances in Information and Communication Technology","Critical Infrastructure Protection XIII"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-34647-8_14","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,11,18]],"date-time":"2023-11-18T01:06:01Z","timestamp":1700269561000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-34647-8_14"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019]]},"ISBN":["9783030346461","9783030346478"],"references-count":46,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-34647-8_14","relation":{},"ISSN":["1868-4238","1868-422X"],"issn-type":[{"type":"print","value":"1868-4238"},{"type":"electronic","value":"1868-422X"}],"subject":[],"published":{"date-parts":[[2019]]},"assertion":[{"value":"19 November 2019","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ICCIP","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Critical Infrastructure Protection","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Arlington, VA","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"USA","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2019","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"11 March 2019","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"12 March 2019","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"13","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"iccip2019","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/www.ifip1110.org\/Conferences\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"n\/a","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"34","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"16","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"47% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"n\/a","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}