{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T16:22:52Z","timestamp":1783614172243,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":62,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,12,4]],"date-time":"2023-12-04T00:00:00Z","timestamp":1701648000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100006374","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61833015, 62293511, 62293503, 62293500, 62073285, 62303126 and 62362008"],"award-info":[{"award-number":["61833015, 62293511, 62293503, 62293500, 62073285, 62303126 and 62362008"]}],"id":[{"id":"10.13039\/501100006374","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Key Lab of CS&AUS of Zhejiang Province"},{"DOI":"10.13039\/501100006374","name":"Natural Science Foundation of Zhejiang Province","doi-asserted-by":"publisher","award":["LR23F030001, LZ21F020006"],"award-info":[{"award-number":["LR23F030001, LZ21F020006"]}],"id":[{"id":"10.13039\/501100006374","id-type":"DOI","asserted-by":"publisher"}]},{"name":"National Research Foundation, Singapore","award":["SMI-2022-MTP-05"],"award-info":[{"award-number":["SMI-2022-MTP-05"]}]},{"name":"Xiaomi Foundation"},{"DOI":"10.13039\/501100006374","name":"Fundamental Research Funds for the Central Universities","doi-asserted-by":"publisher","award":["226-2022-00120, Zhejiang University NGICS Platform"],"award-info":[{"award-number":["226-2022-00120, Zhejiang University NGICS Platform"]}],"id":[{"id":"10.13039\/501100006374","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,12,4]]},"DOI":"10.1145\/3627106.3627179","type":"proceedings-article","created":{"date-parts":[[2023,12,2]],"date-time":"2023-12-02T18:13:22Z","timestamp":1701540802000},"page":"310-323","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":13,"title":["SePanner: Analyzing Semantics of Controller Variables in Industrial Control Systems based on Network Traffic"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0002-1111-8074","authenticated-orcid":false,"given":"Jie","family":"Meng","sequence":"first","affiliation":[{"name":"State Key Laboratory of Industrial Control Technology and College of Control Science and Engineering, Zhejiang University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1596-6890","authenticated-orcid":false,"given":"Zeyu","family":"Yang","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Industrial Control Technology and College of Control Science and Engineering, Zhejiang University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0950-1525","authenticated-orcid":false,"given":"Zhenyong","family":"Zhang","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Public Big Data and College of Computer Science and Technology, Guizhou University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7639-3686","authenticated-orcid":false,"given":"Yangyang","family":"Geng","sequence":"additional","affiliation":[{"name":"Information Engineering University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8158-150X","authenticated-orcid":false,"given":"Ruilong","family":"Deng","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Industrial Control Technology and College of Control Science and Engineering, Zhejiang University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4221-2162","authenticated-orcid":false,"given":"Peng","family":"Cheng","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Industrial Control Technology and College of Control Science and Engineering, Zhejiang University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3155-3145","authenticated-orcid":false,"given":"Jiming","family":"Chen","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Industrial Control Technology and College of Control Science and Engineering, Zhejiang University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0594-0432","authenticated-orcid":false,"given":"Jianying","family":"Zhou","sequence":"additional","affiliation":[{"name":"Singapore University of Technology and Design, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,12,4]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"2022. INCONTROLLER: New State-Sponsored Cyber Attack Tools Target Multiple Industrial Control Systems. (2022). https:\/\/www.mandiant.com\/resources\/blog\/incontroller-state-sponsored-ics-tool."},{"key":"e_1_3_2_1_2_1","volume-title":"[Online]","author":"UDS ISO","year":"2023","unstructured":"2023. UDS ISO 14229:Standardized CAN-based protocol for diagnostics. (2023). [Online]."},{"key":"e_1_3_2_1_3_1","volume-title":"https:\/\/www.darkreading.com\/vulnerabilities-threats\/triton-trisis-attacks-another-victim","author":"Higgins Kelly Jackson","year":"2019","unstructured":"Kelly Jackson Higgins. 2019. Triton\/Trisis Attacks Another Victim. (2019). https:\/\/www.darkreading.com\/vulnerabilities-threats\/triton-trisis-attacks-another-victim."},{"key":"e_1_3_2_1_4_1","volume-title":"Than Previously Thought.","author":"Kelley Michael B","year":"2013","unstructured":"Michael B Kelley. 2013. The Stuxnet Attack On Iran\u2019s Nuclear Plant Was \u2019Far More Dangerous\u2019 Than Previously Thought. (2013). https:\/\/www.businessinsider.com\/stuxnet-was-far-more-dangerous-than-previous-thought-2013-11."},{"key":"e_1_3_2_1_5_1","unstructured":"ISO 14230-3. 1999. Keyword Protocol 2000 Part 3. (1999). https:\/\/www.sis.se\/api\/document\/preview\/895162\/."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.comcom.2020.03.007"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.rser.2016.01.025"},{"key":"e_1_3_2_1_8_1","volume-title":"https:\/\/github.com\/Paucpauc\/lexus_canbus_id","author":"Lexus","year":"2021","unstructured":"Andrey. 2021. Lexus RX350 (III, 2011, AL10) CAN bus IDs. (2021). https:\/\/github.com\/Paucpauc\/lexus_canbus_id."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1080\/23742917.2016.1252211"},{"key":"e_1_3_2_1_10_1","volume-title":"https:\/\/control.com\/textbook\/programmable-logic-controllers\/ladder-diagram-ld-programming\/","author":"Automation Control","year":"2023","unstructured":"Control Automation. 2023. Ladder Diagram (LD) Programming Contacts and Coils. (2023). https:\/\/control.com\/textbook\/programmable-logic-controllers\/ladder-diagram-ld-programming\/."},{"key":"e_1_3_2_1_11_1","first-page":"723","article-title":"Exploiting siemens simatic s7 plcs","volume":"16","author":"Beresford Dillon","year":"2011","unstructured":"Dillon Beresford. 2011. Exploiting siemens simatic s7 plcs. Black Hat USA 16, 2 (2011), 723\u2013733.","journal-title":"Black Hat USA"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/IFIPNetworking.2015.7145307"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.comcom.2016.02.015"},{"key":"e_1_3_2_1_14_1","volume-title":"Cybersecurity for industrial control systems: A survey. computers & security 89","author":"Bhamare Deval","year":"2020","unstructured":"Deval Bhamare, Maede Zolanvari, Aiman Erbad, Raj Jain, Khaled Khan, and Nader Meskin. 2020. Cybersecurity for industrial control systems: A survey. computers & security 89 (2020), 101677."},{"key":"e_1_3_2_1_15_1","volume-title":"Black Hat USA 2019","author":"Biham Eli","year":"2019","unstructured":"Eli Biham, Sara Bitan, Aviad Carmel, Alon Dankner, Uriel Malin, and Avishai Wool. 2019. Rogue7: Rogue engineering-station attacks on s7 simatic plcs. Black Hat USA 2019 (2019)."},{"key":"e_1_3_2_1_16_1","volume-title":"Be Safe, Be Secure.","year":"2023","unstructured":"Binaryedge. 2023. Binaryedge.io: Be Ready, Be Safe, Be Secure. (2023). https:\/\/www.binaryedge.io\/."},{"key":"e_1_3_2_1_17_1","volume-title":"https:\/\/github.com\/digitalbond\/Redpoint","author":"Bond Digital","year":"2016","unstructured":"Digital Bond. 2016. Redpoint.Digital Bond\u2019s ICS Enumeration Tools. (2016). https:\/\/github.com\/digitalbond\/Redpoint."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/2590296.2590346"},{"key":"e_1_3_2_1_19_1","volume-title":"Rosetta: Extracting protocol semantics using binary analysis with applications to protocol replay and natrewriting. CyLab","author":"Caballero Juan","year":"2007","unstructured":"Juan Caballero and Dawn Song. 2007. Rosetta: Extracting protocol semantics using binary analysis with applications to protocol replay and natrewriting. CyLab (2007), 32."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2012.08.003"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/1315245.1315286"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2022.3185649"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/2939918.2939921"},{"key":"e_1_3_2_1_24_1","volume-title":"https:\/\/www.zoomeye.org\/","author":"Chuangyu Zhidao","year":"2023","unstructured":"Zhidao Chuangyu. 2023. Zoomeye. (2023). https:\/\/www.zoomeye.org\/."},{"key":"e_1_3_2_1_25_1","unstructured":"WinTECH\u00a0Software Design. 2017. A SCADA MODBUS network scanner. (2017). https:\/\/www.win-tech.com\/html\/demos.htm."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijcip.2015.05.001"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICNP.2016.7784407"},{"key":"e_1_3_2_1_28_1","volume-title":"Journal of Physics: Conference Series, Vol.\u00a02414","author":"Geng Yangyang","year":"2015","unstructured":"Yangyang Geng, Rongkuan Ma, Qiang Wei, and Wenhai Wang. 2022. Programmable logic controller memory management vulnerability analysis. In Journal of Physics: Conference Series, Vol.\u00a02414. IOP Publishing, 012015."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-72817-9_8"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/2664243.2664277"},{"key":"e_1_3_2_1_31_1","volume-title":"https:\/\/www.dragos.com\/wp-content\/uploads\/TRISIS-01.pdf","author":"Dragos Inc. 2017. TRISIS Malware:Analysis of Safety System Targeted Malware.","year":"2017","unstructured":"Dragos Inc. 2017. TRISIS Malware:Analysis of Safety System Targeted Malware. (2017). https:\/\/www.dragos.com\/wp-content\/uploads\/TRISIS-01.pdf."},{"key":"e_1_3_2_1_32_1","volume-title":"ICSREF: A framework for automated reverse engineering of industrial control systems binaries. arXiv preprint arXiv:1812.03478","author":"Keliris Anastasis","year":"2018","unstructured":"Anastasis Keliris and Michail Maniatakos. 2018. ICSREF: A framework for automated reverse engineering of industrial control systems binaries. arXiv preprint arXiv:1812.03478 (2018)."},{"key":"e_1_3_2_1_33_1","unstructured":"kmalinich. 2018. node-bmw-ref. (2018). https:\/\/github.com\/kmalinich\/node-bmw-ref."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSMC.1987.4309069"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-99843-5_5"},{"key":"e_1_3_2_1_36_1","unstructured":"Liras. 2017. The Unity (UMAS) protocol. (2017). http:\/\/lirasenlared.blogspot.com\/2017\/08\/the-unity-umas-protocol-part-i.html."},{"key":"e_1_3_2_1_37_1","unstructured":"Gordon\u00a0Fyodor Lyon. 2008. Nmap network scanning: The official Nmap project guide to network discovery and security scanning. Insecure. Com LLC (US)."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.icte.2018.02.001"},{"key":"e_1_3_2_1_39_1","volume-title":"https:\/\/github.com\/damienmaguire\/BMW-E65-CANBUS","author":"Maguire Damien","year":"2023","unstructured":"Damien Maguire. 2023. BMW-E65-CANBUS. (2023). https:\/\/github.com\/damienmaguire\/BMW-E65-CANBUS."},{"key":"e_1_3_2_1_40_1","volume-title":"DIgital Bond","year":"2016","unstructured":"Meeas. 2012. PLCScan. DIgital Bond (2016). (2012). https:\/\/github.com\/meeas\/plcscan\/blob\/master\/plcscan.py."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/PST.2016.7906943"},{"key":"e_1_3_2_1_42_1","unstructured":"Davide Nardella. 2016. Step7 Open Source Ethernet Communication Suite. (2016). https:\/\/snap7.sourceforge.net\/."},{"key":"e_1_3_2_1_43_1","volume-title":"What We\u2019ve Learned from the Dec 1st Attack on an Israeli Water Reservoir?. (2020). https:\/\/www.otorio.com\/blog\/what-we-ve-learned-from-the-december-1st-attack-on-an-israeli-water-reservoir\/","author":"Even Noam","unstructured":"Noam Even.2020. What We\u2019ve Learned from the Dec 1st Attack on an Israeli Water Reservoir?. (2020). https:\/\/www.otorio.com\/blog\/what-we-ve-learned-from-the-december-1st-attack-on-an-israeli-water-reservoir\/."},{"key":"e_1_3_2_1_44_1","unstructured":"The one place to understand everything on\u00a0the internet. 2023. The one place to understand everything on the internet. (2023). https:\/\/censys.io\/."},{"key":"e_1_3_2_1_45_1","volume-title":"ICCIP 2021","author":"Qasim Syed\u00a0Ali","year":"2022","unstructured":"Syed\u00a0Ali Qasim, Adeen Ayub, Jordan Johnson, and Irfan Ahmed. 2022. Attacking the IEC 61131 Logic Engine in Programmable Logic Controllers. In Critical Infrastructure Protection XV: 15th IFIP WG 11.10 International Conference, ICCIP 2021, Virtual Event, March 15\u201316, 2021, Revised Selected Papers 15. Springer, 73\u201395."},{"key":"e_1_3_2_1_46_1","volume-title":"Critical Infrastructure Protection II 2","author":"Rrushi Julian","unstructured":"Julian Rrushi and Roy Campbell. 2008. Detecting cyber attacks on nuclear power plants. In Critical Infrastructure Protection II 2. Springer, 41\u201354."},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2017.06.012"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1007\/s42452-019-0860-2"},{"key":"e_1_3_2_1_49_1","unstructured":"Shodan. 2023. Search Engine for the Internet of Everything. (2023). https:\/\/www.shodan.io\/."},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.5555\/2206293"},{"key":"e_1_3_2_1_51_1","volume-title":"https:\/\/github.com\/taojy123\/KeymouseGo\/","year":"2023","unstructured":"taojy123. 2023. KeymouseGo. (2023). https:\/\/github.com\/taojy123\/KeymouseGo\/."},{"key":"e_1_3_2_1_52_1","volume-title":"A Practical Format and Semantic Reverse Analysis Approach for Industrial Control Protocols. Security and Communication Networks 2021","author":"Wang Qun","year":"2021","unstructured":"Qun Wang, Zhonghao Sun, Zhangquan Wang, Shiping Ye, Ziyi Su, Hao Chen, and Chao Hu. 2021. A Practical Format and Semantic Reverse Analysis Approach for Industrial Control Protocols. Security and Communication Networks 2021 (2021)."},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1080\/17445760.2019.1655740"},{"key":"e_1_3_2_1_54_1","unstructured":"Wireshark. 2023. The widely-used network protocol analyzer. (2023). https:\/\/www.wireshark.org\/."},{"key":"e_1_3_2_1_55_1","volume-title":"https:\/\/fofa.info\/","author":"XinAn HuaShun","year":"2023","unstructured":"HuaShun XinAn. 2023. Fofa. (2023). https:\/\/fofa.info\/."},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660352"},{"key":"e_1_3_2_1_57_1","first-page":"2039","article-title":"Intrusion detection techniques for industrial control systems","volume":"53","author":"Yang An","year":"2016","unstructured":"An Yang, Limin Sun, Xiaoshan Wang, and Z Shi. 2016. Intrusion detection techniques for industrial control systems. Journal of Computer Research and Development 53, 9 (2016), 2039\u20132054.","journal-title":"Journal of Computer Research and Development"},{"key":"e_1_3_2_1_58_1","volume-title":"PLC-Sleuth: Detecting and Localizing PLC Intrusions Using Control Invariants. In 23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID","author":"Yang Zeyu","year":"2020","unstructured":"Zeyu Yang, Liang He, Peng Cheng, Jiming Chen, David\u00a0KY Yau, and Linkang Du. 2020. PLC-Sleuth: Detecting and Localizing PLC Intrusions Using Control Invariants. In 23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2020). 333\u2013348."},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1145\/3560905.3568521"},{"key":"e_1_3_2_1_60_1","unstructured":"Yapeng Ye Zhuo Zhang Fei Wang Xiangyu Zhang and Dongyan Xu. 2021. NetPlier: Probabilistic Network Protocol Reverse Engineering from Message Traces.. In NDSS."},{"key":"e_1_3_2_1_61_1","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Yu Le","year":"2022","unstructured":"Le Yu, Yangyang Liu, Pengfei Jing, Xiapu Luo, Lei Xue, Kaifa Zhao, Yajin Zhou, Ting Wang, Guofei Gu, Sen Nie, 2022. Towards automatically reverse engineering vehicle diagnostic protocols. In 31st USENIX Security Symposium (USENIX Security 22). 1939\u20131956."},{"key":"e_1_3_2_1_62_1","article-title":". An Automated Methodof Unknown Protocol Fuzzing Test","volume":"43","author":"Zhang WY ZHANG, L","year":"2020","unstructured":"WY ZHANG, L Zhang, JL MAO, 2020. An Automated Methodof Unknown Protocol Fuzzing Test. ChineseJournal ofComputers 43, 4 (2020), 653G667.","journal-title":"ChineseJournal ofComputers"}],"event":{"name":"ACSAC '23: Annual Computer Security Applications Conference","location":"Austin TX USA","acronym":"ACSAC '23"},"container-title":["Annual Computer Security Applications Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3627106.3627179","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3627106.3627179","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T17:39:35Z","timestamp":1755884375000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3627106.3627179"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,12,4]]},"references-count":62,"alternative-id":["10.1145\/3627106.3627179","10.1145\/3627106"],"URL":"https:\/\/doi.org\/10.1145\/3627106.3627179","relation":{},"subject":[],"published":{"date-parts":[[2023,12,4]]},"assertion":[{"value":"2023-12-04","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}