{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,28]],"date-time":"2026-07-28T19:12:02Z","timestamp":1785265922036,"version":"3.55.0"},"reference-count":28,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2023,10,20]],"date-time":"2023-10-20T00:00:00Z","timestamp":1697760000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Digital Threats"],"published-print":{"date-parts":[[2023,12,31]]},"abstract":"<jats:p>Critical infrastructures are making increasing use of digital technology for process control. While there are benefits, such as increased efficiency and new functionality, digitalization also introduces the risk of cyber-attacks to systems that support critical functions. A valuable target in these Industrial Control Systems (ICSs) are the Programmable Logic Controllers (PLCs) controlling the machinery that manages a physical process. PLCs have proven to be vulnerable to a range of cyber-attacks in the past; however, newer technologies such as embedded servers and virtualization have the potential to improve this situation and be used to monitor a PLC\u2019s function. In this article, the implementation of a Host-based Intrusion Detection System (HIDS) for a modern PLC is described. This method uniquely makes use of native technologies on the PLC to monitor a dynamic simulated process in real time. Both the PLC\u2019s integrity (checksum, file size, etc.) and the process control are monitored to determine whether the PLC has been compromised in a cyber-attack. The proposed solution detects a range of attacks, even when the PLC\u2019s control logic is compromised and\u2014unlike previous PLC HIDS methods\u2014requires no modification of the underlying PLC technology.<\/jats:p>","DOI":"10.1145\/3617692","type":"journal-article","created":{"date-parts":[[2023,9,13]],"date-time":"2023-09-13T12:16:37Z","timestamp":1694607397000},"page":"1-19","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":6,"title":["Goosewolf: An Embedded Intrusion Detection System for Advanced Programmable Logic Controllers"],"prefix":"10.1145","volume":"4","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5832-1988","authenticated-orcid":false,"given":"David","family":"Allison","sequence":"first","affiliation":[{"name":"AIT Austrian Institute of Technology GmbH, Austria"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1299-2364","authenticated-orcid":false,"given":"Kieran","family":"McLaughlin","sequence":"additional","affiliation":[{"name":"Queen\u2019s University Belfast, United Kingdom"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8990-6751","authenticated-orcid":false,"given":"Paul","family":"Smith","sequence":"additional","affiliation":[{"name":"AIT Austrian Institute of Technology GmbH, Austria"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,10,20]]},"reference":[{"key":"e_1_3_1_2_2","volume-title":"Did Stuxnet Take Out 1,000 Centrifuges at the Natanz Enrichment Plant?","author":"Albright D.","year":"2010","unstructured":"D. Albright, P. Brannan, and C. Walrond. 2010. Did Stuxnet Take Out 1,000 Centrifuges at the Natanz Enrichment Plant?Technical Report. Institute for Science and International Security."},{"key":"e_1_3_1_3_2","volume-title":"Utilising the Multi-Functional Platform of the Siemens S7-1518 Programmable Logic Controller for Security Applications","author":"Allison David","year":"2019","unstructured":"David Allison. 2019. Utilising the Multi-Functional Platform of the Siemens S7-1518 Programmable Logic Controller for Security Applications. Master\u2019s Thesis. Queen\u2019s University Belfast, Belfast."},{"key":"e_1_3_1_4_2","doi-asserted-by":"crossref","first-page":"585","DOI":"10.1109\/GHTC.2014.6970342","volume-title":"IEEE Global Humanitarian Technology Conference (GHTC\u201914)","author":"Alves T.","year":"2014","unstructured":"T. Alves, M. Buratto, F. de Souza, and T. Rodrigues. 2014. OpenPLC: An open source alternative to automation. In IEEE Global Humanitarian Technology Conference (GHTC\u201914). 585\u2013589. DOI:https:\/\/doi.org\/10.1109\/GHTC.2014.6970342"},{"key":"e_1_3_1_5_2","volume-title":"Black Hat USA","author":"Beresford D.","year":"2011","unstructured":"D. Beresford. 2011. Exploiting Siemens Simatic S7 PLCs. In Black Hat USA."},{"key":"e_1_3_1_6_2","volume-title":"Black Hat USA","author":"Biham E.","year":"2019","unstructured":"E. Biham, S. Bitan, A. Carmel, A. Dankner, U. Malin, and A. Wool. 2019. Rogue 7: Rogue engineering-station attacks on S 7 Simatic PLCs. In Black Hat USA."},{"key":"e_1_3_1_7_2","volume-title":"International Conference on Nuclear Security: Sustaining and Strengthening Efforts","author":"Silva R. Busquim e","year":"2020","unstructured":"R. Busquim e Silva, K. Shirvan, J. Piqueira, and R. Marques. 2020. Development of the Asherah nuclear power plant simulator for cyber security assessment. In International Conference on Nuclear Security: Sustaining and Strengthening Efforts. International Atomic Energy Agency, Vienna."},{"key":"e_1_3_1_8_2","volume-title":"Significant Cyber Incidents Since 2006","author":"Studies Center for Strategic and International","year":"2019","unstructured":"Center for Strategic and International Studies. 2019. Significant Cyber Incidents Since 2006. Technical Report. Center for Strategic and International Studies. Retrieved from https:\/\/www.csis.org\/programs\/strategic-technologies-program\/significant-cyber-incidents"},{"key":"e_1_3_1_9_2","unstructured":"L. Cerulus. 2019. How Ukraine became a test bed for cyberweaponry. Retrieved from https:\/\/www.politico.eu\/article\/ukraine-cyber-war-frontline-russia-malware-attacks\/"},{"key":"e_1_3_1_10_2","first-page":"67","volume-title":"Resilience Week (RWS\u201916)","author":"Garcia L.","year":"2016","unstructured":"L. Garcia, S. Zonouz, D. Wei, and L. de Aguiar. 2016. Detecting PLC control corruption via on-device runtime verification. In Resilience Week (RWS\u201916). 67\u201372. DOI:https:\/\/doi.org\/10.1109\/RWEEK.2016.7573309"},{"key":"e_1_3_1_11_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijcip.2013.05.001"},{"key":"e_1_3_1_12_2","first-page":"37","article-title":"Accurate modeling of the Siemens S7 SCADA protocol for intrusion detection and digital forensics","volume":"9","author":"Goldenberg N.","year":"2014","unstructured":"N. Goldenberg and A. Wool. 2014. Accurate modeling of the Siemens S7 SCADA protocol for intrusion detection and digital forensics. J. Digit. Forens., Secur. Law 9 (012014), 37\u201350. DOI:https:\/\/doi.org\/10.13140\/2.1.1723.8727","journal-title":"J. Digit. Forens., Secur. Law"},{"key":"e_1_3_1_13_2","first-page":"824","volume-title":"IEEE Industrial Cyber-Physical Systems (ICPS\u201918)","author":"Jin C.","year":"2018","unstructured":"C. Jin, S. Valizadeh, and M. van Dijk. 2018. Snapshotter: Lightweight intrusion detection and prevention system for industrial control systems. In IEEE Industrial Cyber-Physical Systems (ICPS\u201918). 824\u2013829. DOI:https:\/\/doi.org\/10.1109\/ICPHYS.2018.8390813"},{"key":"e_1_3_1_14_2","unstructured":"Kaspersky Lab. 2013. Kaspersky Lab Identifies Operation \u201cRed October \u201d an Advanced Cyber-Espionage Campaign Targeting Diplomatic and Government Institutions Worldwide. Retrieved from https:\/\/www.kaspersky.com\/about\/press-releases\/2013_kaspersky-lab-identifies-operation--red-october--an-advanced-cyber-espionage-campaign-targeting-diplomatic-and-government-institutions-worldwide"},{"key":"e_1_3_1_15_2","first-page":"524","volume-title":"IEEE Conference on Communications and Network Security (CNS\u201915)","author":"Klick J.","year":"2015","unstructured":"J. Klick, S. Lau, D. Marzin, J. O. Malchow, and V. Roth. 2015. Internet-facing PLCs as a network backdoor. In IEEE Conference on Communications and Network Security (CNS\u201915). IEEE, 524\u2013532. DOI:https:\/\/doi.org\/10.1109\/CNS.2015.7346865"},{"key":"e_1_3_1_16_2","volume-title":"DEF CON","author":"Lei C.","year":"2017","unstructured":"C. Lei, L. Donguong, and M. Liang. 2017. The spear to break the security wall of S7CommPlus. In DEF CON."},{"key":"e_1_3_1_17_2","unstructured":"B. Marr. 2018. What Is Industry 4.0? Here\u2019s a Super Easy Explanation for Anyone. Retrieved from https:\/\/www.forbes.com\/sites\/bernardmarr\/2018\/09\/02\/what-is-industry-4-0-heres-a-super-easy-explanation-for-anyone\/"},{"key":"e_1_3_1_18_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2020.102535"},{"key":"e_1_3_1_19_2","unstructured":"National Institute for Standards and Technology (NIST). 2018. NVD - CVE-2018-13805 Details. Retrieved from https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2018-13805"},{"key":"e_1_3_1_20_2","unstructured":"National Institute for Standards and Technology (NIST). 2021. NVD - CVE-2020-15782 Details. Retrieved from https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2020-15782"},{"key":"e_1_3_1_21_2","unstructured":"Prosys OPC UA Ltd.2019. Prosys OPC UA Simulation Server. Retrieved from https:\/\/www.prosysopc.com\/opc-ua"},{"key":"e_1_3_1_22_2","doi-asserted-by":"crossref","first-page":"125","DOI":"10.1016\/j.nucengdes.2018.02.030","article-title":"Use of STPA as a diverse analysis method for optimization and design verification of digital instrumentation and control systems in nuclear power plants","volume":"331","author":"Rejzek M.","year":"2018","unstructured":"M. Rejzek and C. Hilbes. 2018. Use of STPA as a diverse analysis method for optimization and design verification of digital instrumentation and control systems in nuclear power plants. Nucl. Eng. Des. 331 (May2018), 125\u2013135. DOI:https:\/\/doi.org\/10.1016\/j.nucengdes.2018.02.030","journal-title":"Nucl. Eng. Des."},{"key":"e_1_3_1_23_2","unstructured":"Secure PLC Programming Project. 2021. Secure PLC Coding Practices: Top 20 List. Retrieved from https:\/\/plc-security.com\/content\/Top_20_Secure_PLC_Coding_Practices_V1.0.pdf"},{"key":"e_1_3_1_24_2","unstructured":"Siemens AG. 2018. Setting up communication between CPU and C\/C++ runtime for a multifunctional platform using OPC UA. Retrieved from https:\/\/cache.industry.siemens.com\/dl\/files\/176\/109749176\/att_956095\/v1\/109749176_CPU1518Mfp_OpcUa_DOC_V1_en.pdf"},{"key":"e_1_3_1_25_2","unstructured":"Softing Industrial Automation GmbH. 2019. dataFEED OPC Suite. Retrieved from https:\/\/industrial.softing.com\/products\/opc-opc-ua-software-platform\/opc-server-middleware\/datafeed-opc-suite-base.html"},{"key":"e_1_3_1_26_2","volume-title":"Black Hat Asia","author":"Spenneberg R.","year":"2016","unstructured":"R. Spenneberg, M. Br\u00fcggemann, and H. Schwartke. 2016. PLC-blaster: A worm living solely in the PLC. In Black Hat Asia. Retrieved from https:\/\/www.blackhat.com\/docs\/asia-16\/materials\/asia-16-Spenneberg-PLC-Blaster-A-Worm-Living-Solely-In-The-PLC-wp.pdf"},{"key":"e_1_3_1_27_2","first-page":"1","volume-title":"World Congress on Industrial Control Systems Security (WCICSS\u201916)","author":"Wardak H.","year":"2016","unstructured":"H. Wardak, S. Zhioua, and A. Almulhem. 2016. PLC access control: A security analysis. In World Congress on Industrial Control Systems Security (WCICSS\u201916). IEEE, 1\u20136. DOI:https:\/\/doi.org\/10.1109\/WCICSS.2016.7882935"},{"key":"e_1_3_1_28_2","unstructured":"K. Zetter. 2011. How Digital Detectives Deciphered Stuxnet the Most Menacing Malware in History. Retrieved from https:\/\/www.wired.com\/2011\/07\/how-digital-detectives-deciphered-stuxnet\/"},{"key":"e_1_3_1_29_2","volume-title":"Countdown to Zero Day: Stuxnet and the Launch of the World\u2019s First Digital Weapon","author":"Zetter K.","year":"2014","unstructured":"K. Zetter. 2014. Countdown to Zero Day: Stuxnet and the Launch of the World\u2019s First Digital Weapon. Crown Publishing Group."}],"container-title":["Digital Threats: Research and Practice"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3617692","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3617692","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:36:32Z","timestamp":1750178192000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3617692"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,10,20]]},"references-count":28,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2023,12,31]]}},"alternative-id":["10.1145\/3617692"],"URL":"https:\/\/doi.org\/10.1145\/3617692","relation":{},"ISSN":["2692-1626","2576-5337"],"issn-type":[{"value":"2692-1626","type":"print"},{"value":"2576-5337","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,10,20]]},"assertion":[{"value":"2022-11-04","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-08-10","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-10-20","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}