{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T04:24:08Z","timestamp":1750220648370,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":24,"publisher":"ACM","license":[{"start":{"date-parts":[[2019,12,10]],"date-time":"2019-12-10T00:00:00Z","timestamp":1575936000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2019,12,10]]},"DOI":"10.1145\/3372318.3372323","type":"proceedings-article","created":{"date-parts":[[2019,12,23]],"date-time":"2019-12-23T20:55:31Z","timestamp":1577134531000},"page":"38-47","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["A Strategy for Security Testing Industrial Firewalls"],"prefix":"10.1145","author":[{"given":"Thuy D.","family":"Nguyen","sequence":"first","affiliation":[{"name":"Naval Postgraduate School"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Steve C.","family":"Austin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Cynthia E.","family":"Irvine","sequence":"additional","affiliation":[{"name":"Naval Postgraduate School"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2019,12,10]]},"reference":[{"volume-title":"ControlLogix System User Manual","key":"e_1_3_2_1_1_1","unstructured":"Allen-Bradley. 2017. ControlLogix System User Manual . Rockwell Automation Inc., Milwaukee, WI. Allen-Bradley. 2017. ControlLogix System User Manual. Rockwell Automation Inc., Milwaukee, WI."},{"volume-title":"Stratix 5950 Security Appliance User Manual","key":"e_1_3_2_1_2_1","unstructured":"Allen-Bradley. 2019. Stratix 5950 Security Appliance User Manual . Rockwell Automation Inc., Milwaukee, WI. Allen-Bradley. 2019. Stratix 5950 Security Appliance User Manual. Rockwell Automation Inc., Milwaukee, WI."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1002\/stvr.1544"},{"issue":"7","key":"e_1_3_2_1_4_1","first-page":"0","article-title":"User's Guide Tofino Central Management Platform","volume":"1","author":"Byres Security Inc.","year":"2012","unstructured":"Byres Security Inc. 2012 . User's Guide Tofino Central Management Platform , Version 1 . 7 . 0 . Byres Security Inc. Byres Security Inc. 2012. User's Guide Tofino Central Management Platform, Version 1.7.0. Byres Security Inc.","journal-title":"Version"},{"key":"e_1_3_2_1_5_1","volume-title":"Lesson Learned: Risks Posed by Firewall Firmware Vulnerabilities. https:\/\/www.eenews.net\/assets\/2019\/09\/06\/document_ew_02.pdf","author":"Western Electric Coordinating Council","year":"2019","unstructured":"Western Electric Coordinating Council . 2019 . Lesson Learned: Risks Posed by Firewall Firmware Vulnerabilities. https:\/\/www.eenews.net\/assets\/2019\/09\/06\/document_ew_02.pdf Western Electric Coordinating Council. 2019. Lesson Learned: Risks Posed by Firewall Firmware Vulnerabilities. https:\/\/www.eenews.net\/assets\/2019\/09\/06\/document_ew_02.pdf"},{"key":"e_1_3_2_1_6_1","unstructured":"Eaton. [n. d.]. Tofino 9211-ET Ethernet based Industrial Security Appliance EPS9211-ET Rev4 120310 Datasheet. https:\/\/www.mtl-inst.com\/images\/uploads\/datasheets\/tofino\/EPS9211-ET.pdf  Eaton. [n. d.]. Tofino 9211-ET Ethernet based Industrial Security Appliance EPS9211-ET Rev4 120310 Datasheet. https:\/\/www.mtl-inst.com\/images\/uploads\/datasheets\/tofino\/EPS9211-ET.pdf"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2012.012012.100092"},{"volume-title":"Perspectives of System Informatics, Dines Bj\u00f8rner, Manfred Broy, and Alexandre V","author":"J\u00fcrjens Jan","key":"e_1_3_2_1_8_1","unstructured":"Jan J\u00fcrjens and Guido Wimmel . 2001. Specification-Based Testing of Firewalls . In Perspectives of System Informatics, Dines Bj\u00f8rner, Manfred Broy, and Alexandre V . Zamulin (Eds.). Springer Berlin Heidelberg , Berlin, Heidelberg , 308--316. Jan J\u00fcrjens and Guido Wimmel. 2001. Specification-Based Testing of Firewalls. In Perspectives of System Informatics, Dines Bj\u00f8rner, Manfred Broy, and Alexandre V. Zamulin (Eds.). Springer Berlin Heidelberg, Berlin, Heidelberg, 308--316."},{"key":"e_1_3_2_1_9_1","volume-title":"Operating System Penetration. In National Computer Conference (AFIPS '75)","author":"Linde Richard R.","year":"1975","unstructured":"Richard R. Linde . 1975 . Operating System Penetration. In National Computer Conference (AFIPS '75) . ACM, 361--368. https:\/\/doi.org\/10.1145\/1499949.1500018 10.1145\/1499949.1500018 Richard R. Linde. 1975. Operating System Penetration. In National Computer Conference (AFIPS '75). ACM, 361--368. https:\/\/doi.org\/10.1145\/1499949.1500018"},{"key":"e_1_3_2_1_10_1","first-page":"02","article-title":"MODBUS over Serial Line Specification and Implementation Guide","volume":"1","author":"Modbus Organization","year":"2006","unstructured":"Modbus Organization 2006 . MODBUS over Serial Line Specification and Implementation Guide , Version 1 . 02 . Modbus Organization. http:\/\/www.modbus.org\/docs\/Modbus_over_serial_line_V1_02.pdf Modbus Organization 2006. MODBUS over Serial Line Specification and Implementation Guide, Version 1.02. Modbus Organization. http:\/\/www.modbus.org\/docs\/Modbus_over_serial_line_V1_02.pdf","journal-title":"Version"},{"key":"e_1_3_2_1_11_1","unstructured":"National Institute of Standards and Technology. 2010. CVE-2010-5107 Detail. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2010-5107  National Institute of Standards and Technology. 2010. CVE-2010-5107 Detail. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2010-5107"},{"key":"e_1_3_2_1_12_1","unstructured":"National Institute of Standards and Technology. 2017. CVE-2017-11400 Detail. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-11400  National Institute of Standards and Technology. 2017. CVE-2017-11400 Detail. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-11400"},{"key":"e_1_3_2_1_13_1","unstructured":"National Institute of Standards and Technology. 2017. CVE-2017-11401 Detail. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-11401  National Institute of Standards and Technology. 2017. CVE-2017-11401 Detail. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-11401"},{"key":"e_1_3_2_1_14_1","unstructured":"National Institute of Standards and Technology. 2017. CVE-2017-11402 Detail. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-11402  National Institute of Standards and Technology. 2017. CVE-2017-11402 Detail. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-11402"},{"key":"e_1_3_2_1_15_1","unstructured":"National Institute of Standards and Technology. 2017. CVE-2017-15906 Detail. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-15906  National Institute of Standards and Technology. 2017. CVE-2017-15906 Detail. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-15906"},{"key":"e_1_3_2_1_16_1","first-page":"22","article-title":"The CIP Networks Library Volume 1: Common Industrial Protocol","volume":"3","author":"Open DeviceNet Vendor Association","year":"2017","unstructured":"Open DeviceNet Vendor Association , Inc. 2017 . The CIP Networks Library Volume 1: Common Industrial Protocol , Version 3 . 22 . Open DeviceNet Vendor Association, Inc., Ann Arbor, MI. Open DeviceNet Vendor Association, Inc. 2017. The CIP Networks Library Volume 1: Common Industrial Protocol, Version 3.22. Open DeviceNet Vendor Association, Inc., Ann Arbor, MI.","journal-title":"Version"},{"key":"e_1_3_2_1_17_1","first-page":"23","article-title":"The CIP Networks Library Volume 2:EtherNet\/IP Adaptation of CIP","volume":"1","author":"Open DeviceNet Vendor Association","year":"2017","unstructured":"Open DeviceNet Vendor Association , Inc. 2017 . The CIP Networks Library Volume 2:EtherNet\/IP Adaptation of CIP , Version 1 . 23 . Open DeviceNet Vendor Association, Inc., Ann Arbor, MI. Open DeviceNet Vendor Association, Inc. 2017. The CIP Networks Library Volume 2:EtherNet\/IP Adaptation of CIP, Version 1.23. Open DeviceNet Vendor Association, Inc., Ann Arbor, MI.","journal-title":"Version"},{"key":"e_1_3_2_1_18_1","unstructured":"M. J. Ranum. 1995. On the topic of Firewall Testing. https:\/\/www.ranum.com\/security\/computer_security\/archives\/fw-testing.htm  M. J. Ranum. 1995. On the topic of Firewall Testing. https:\/\/www.ranum.com\/security\/computer_security\/archives\/fw-testing.htm"},{"volume-title":"Technical Guide to Information Security Testing and Assessment","author":"Scarfone Karen","key":"e_1_3_2_1_19_1","unstructured":"Karen Scarfone , Murugiah Souppaya , Amanda Cody , and Angel Orebaugh . 2008. Technical Guide to Information Security Testing and Assessment . National Institute of Standards and Technology . Karen Scarfone, Murugiah Souppaya, Amanda Cody, and Angel Orebaugh. 2008. Technical Guide to Information Security Testing and Assessment. National Institute of Standards and Technology."},{"key":"e_1_3_2_1_20_1","unstructured":"Tofino Security (Belden Inc.) 2017. Tofino Xenon Tofino Configurator 03.2.00 User Manual. Tofino Security (Belden Inc.).  Tofino Security (Belden Inc.) 2017. Tofino Xenon Tofino Configurator 03.2.00 User Manual. Tofino Security (Belden Inc.)."},{"key":"e_1_3_2_1_21_1","unstructured":"Tofino Security (Belden Inc.). 2019. Tofino Xenon Industrial Security Appliance Product Bulletin. https:\/\/www.belden.com\/hubfs\/resources\/technical\/product-brochures-bulletins\/tofino-xenon-industrial-security-appliance-product-bulletin.pdf?hsLang=en  Tofino Security (Belden Inc.). 2019. Tofino Xenon Industrial Security Appliance Product Bulletin. https:\/\/www.belden.com\/hubfs\/resources\/technical\/product-brochures-bulletins\/tofino-xenon-industrial-security-appliance-product-bulletin.pdf?hsLang=en"},{"key":"e_1_3_2_1_22_1","unstructured":"United State Cybersecurity and Infrastructure Security Agency. [n. d.]. US-CERT Alert (TA17-163A) CrashOverride Malware. https:\/\/www.us-cert.gov\/ncas\/alerts\/TA17-163A  United State Cybersecurity and Infrastructure Security Agency. [n. d.]. US-CERT Alert (TA17-163A) CrashOverride Malware. https:\/\/www.us-cert.gov\/ncas\/alerts\/TA17-163A"},{"key":"e_1_3_2_1_23_1","unstructured":"United State Cybersecurity and Infrastructure Security Agency. 2018. ICS Advisory (ICSA-18-184-01) Rockwell Automation Allen-Bradley Stratix 5950. https:\/\/www.us-cert.gov\/ics\/advisories\/ICSA-18-184-01  United State Cybersecurity and Infrastructure Security Agency. 2018. ICS Advisory (ICSA-18-184-01) Rockwell Automation Allen-Bradley Stratix 5950. https:\/\/www.us-cert.gov\/ics\/advisories\/ICSA-18-184-01"},{"key":"e_1_3_2_1_25_1","first-page":"082A","article-title":"Handbook for the Computer Security Certification of Trusted Systems","volume":"5540","author":"Weissman Clark","year":"1995","unstructured":"Clark Weissman . 1995 . Handbook for the Computer Security Certification of Trusted Systems . Number NRL Technical Memorandum 5540 : 082A . Naval Research Laboratory, Naval Research Laboratory, Code 5540, Washington, D.C. 20375--5337, Chapter 10: Penetration Testing. Clark Weissman. 1995. Handbook for the Computer Security Certification of Trusted Systems. Number NRL Technical Memorandum 5540:082A. Naval Research Laboratory, Naval Research Laboratory, Code 5540, Washington, D.C. 20375--5337, Chapter 10: Penetration Testing.","journal-title":"Number NRL Technical Memorandum"}],"event":{"name":"ICSS: Fifth Annual Industrial Control System Security Workshop","sponsor":["ACSA Applied Computing Security Assoc"],"location":"San Juan PR USA","acronym":"ICSS"},"container-title":["Proceedings of the Fifth Annual Industrial Control System Security (ICSS) Workshop"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3372318.3372323","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3372318.3372323","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T22:02:20Z","timestamp":1750197740000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3372318.3372323"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,12,10]]},"references-count":24,"alternative-id":["10.1145\/3372318.3372323","10.1145\/3372318"],"URL":"https:\/\/doi.org\/10.1145\/3372318.3372323","relation":{},"subject":[],"published":{"date-parts":[[2019,12,10]]},"assertion":[{"value":"2019-12-10","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}