Enhancing ICS Security Diagnostics with Pseudo-Greybox Fuzzing During Maintenance Testing

Kazutaka Matsuzaki, Shinichi Honiden

2023

Abstract

This paper presents a novel Pseudo-Greybox Fuzzer (pseudo-GBF) methodology designed to improve the security diagnosis of Industrial Control Systems (ICS) during maintenance testing. The proposed method combines stateful protocol fuzzing, network fuzzing, and ICS monitoring to optimize the coverage of state transitions in the system under test (SUT) while operating within the constraints of on-site maintenance testing. Pseudo-GBF enhances security testing by utilizing replayable seeds to trigger specific state transitions, enabling efficient and practical testing. By incorporating Pseudo-Greybox Fuzzing during maintenance testing, the methodology addresses the challenges faced in ICS security diagnostics, leading to improved security and resilience of critical infrastructure systems. This paper provides a comprehensive overview of the system design, including integrating stateful protocol fuzzing, network fuzzing, and ICS monitoring, demonstrating its potential to advance ICS security testing.

Download


Paper Citation


in Harvard Style

Matsuzaki K. and Honiden S. (2023). Enhancing ICS Security Diagnostics with Pseudo-Greybox Fuzzing During Maintenance Testing. In Proceedings of the 18th International Conference on Software Technologies - Volume 1: ICSOFT; ISBN 978-989-758-665-1, SciTePress, pages 660-667. DOI: 10.5220/0012137100003538


in Bibtex Style

@conference{icsoft23,
author={Kazutaka Matsuzaki and Shinichi Honiden},
title={Enhancing ICS Security Diagnostics with Pseudo-Greybox Fuzzing During Maintenance Testing},
booktitle={Proceedings of the 18th International Conference on Software Technologies - Volume 1: ICSOFT},
year={2023},
pages={660-667},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0012137100003538},
isbn={978-989-758-665-1},
}


in EndNote Style

TY - CONF

JO - Proceedings of the 18th International Conference on Software Technologies - Volume 1: ICSOFT
TI - Enhancing ICS Security Diagnostics with Pseudo-Greybox Fuzzing During Maintenance Testing
SN - 978-989-758-665-1
AU - Matsuzaki K.
AU - Honiden S.
PY - 2023
SP - 660
EP - 667
DO - 10.5220/0012137100003538
PB - SciTePress