Richard Derbyshire

dblp:222/9541 · DBLP profile ↗
← Back
3ranked-venue papers
1as first author
3since 2021 · last 2023
0000-0003-3902-5056ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 1 first-author · 3 since 2021
YearPublicationVenuePosition
2023 Walking under the ladder logic: PLC-VBS: a PLC control logic vulnerability scanning tool
abstract
Cyber security risk assessments provide a crucial starting point towards the understanding of existing risk exposure, via which suitable mitigation strategies can be formed. Risk is viewed as a product of threat, vulnerability and impact, and equal understanding of each of these elements is vitally important. This can be a challenge in Industrial Control System (ICS) environments, where adopted technologies are typically not only bespoke, but interact directly with the physical world. To date, existing vulnerability identification has focused on traditional vulnerability categories. While this approach provides risk assessors with a baseline understanding and the ability to hypothesize about potential resulting impacts, it is rather high level, operating at a level of abstraction that would be viewed as incomplete within a traditional information system context. The work presented in this paper takes the understanding of ICS device vulnerabilities a step deeper. It offers a tool, PLC-VBS, that helps identify Programmable Logic Controller (PLC) vulnerabilities, specifically within logic used to monitor, control, and automate operational processes. PLC-VBS gives risk assessors a more coherent picture about the potential impact should the identified vulnerabilities be exploited; this applies specifically to operational process elements.
Sam Maesschalck, Alexander Staves, Richard Derbyshire, Benjamin Green 0001, David Hutchison 0001
Comput. Secur.3
2021 "Talking a different Language": Anticipating adversary attack cost for cyber risk assessment
abstract
Typical cyber security risk assessment methods focus on the system under consideration, its vulnerabilities, and the resulting impact in the event of a system compromise. Cyber security, however, increasingly requires anticipating the moves of intelligent adversaries, who make decisions based on a range of factors including the cost of their attacks. A study of current risk assessment literature and industry practice shows that consideration of this cost is a notable gap in the understanding of adversaries. The factors of cost experienced by an adversary are established in this paper as Time, Finance, and Risk, supported by a practical study undertaken with relevant security practitioners. Using these factors as a base, a framework is proposed and developed to support the probabilistic determination of cost incurred by an adversary. This framework is an important extension to existing cyber security risk assessments, and is demonstrated in the paper through the use of a case study.
Richard Derbyshire, Benjamin Green 0001, David Hutchison 0001
Comput. Secur.1
2021 PCaaD: Towards automated determination and exploitation of industrial systems
abstract
Over the last decade, Programmable Logic Controllers (PLCs) have been increasingly targeted by attackers to obtain control over industrial processes that support critical services.Such targeted attacks typically require detailed knowledge of system-specific attributes, including hardware configurations, adopted protocols, and PLC control-logic, i.e., process comprehension.The consensus from both academics and practitioners suggests stealthy process comprehension obtained from a PLC alone, to execute targeted attacks, is impractical.In contrast, we assert that current PLC programming practices open the door to a new vulnerability class, affording attackers an increased level of process comprehension.To support this, we propose the concept of Process Comprehension at a Distance (PCaaD), as a novel methodological and automatable approach towards the system-agnostic identification of PLC library functions.This leads to the targeted exfiltration of operational data, manipulation of control-logic behavior, and establishment of covert command and control channels through unused memory.We validate PCaaD on widely used PLCs through its practical application.
Benjamin Green 0001, Richard Derbyshire, Marina Krotofil, William Knowles, Daniel Prince, Neeraj Suri
Comput. Secur.2