EDBT 2026 Demo / reviewers in the wild / expert
Wael Alsabbagh
dblp:295/4690
· DBLP profile ↗
7ranked-venue papers
7as first author
7since 2021 · last 2025
0000-0001-5235-0262ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 4 · 4 first-author · 4 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Smart Traps for Smart Systems: Scalable Honeynets for IIoT CybersecurityabstractHoneypots serve as decoy systems that attract and monitor intruders, offering insights into their behavior. When interconnected, these honeypots form honeynets, simulating high-value environments to engage attackers and facilitate deeper analysis. However, in Industrial Internet of Things (IIoT) networks, deploying honeypots presents challenges such as static configurations, lack of network context, and difficulties in scaling.In this paper, we introduce TrapNet, a scalable, lightweight honeynet framework specifically designed for IIoT environments. TrapNet combines compact, on-site honeypots with large-scale, adaptive honeynets deployed on fog and cloud infrastructures using microservices. This approach enables fast deployment, scalability, and flexibility, providing an effective solution for IIoT cybersecurity. Our experimental results show that TrapNet efficiently detects intrusions while maintaining low resource overhead. Additionally, all code and configurations used in this study are publicly available, fostering further research and innovation in honeynet design and IIoT security. Wael Alsabbagh, Diego Urrego, Peter Langendörfer |
ICCCN | 1 |
| 2024 | Workshop: Hacking the Backbone: Shell Reverse Attacks on IIoT Systems
Wael Alsabbagh, Chaerin Kim, Nitin Sanjay Patil, Peter Langendörfer |
EWSN | 1 |
| 2024 | A Payload of Lies: False Data Injection Attacks on MQTT-based IIoT SystemsabstractIn the ever-evolving landscape of Industrial Internet of Things (IIoT), security emerges as a critical concern. This paper delves into the realm of False Data Injection Attacks (FDIAs) within MQTT-based IIoT systems, specifically targeting the publisher-subscriber model. Our exploration unveils two distinct attack scenarios that exploit the vulnerabilities inherent in the communication fabric. In the first scenario, we demonstrate the potential chaos wrought by sending false data to subscribers, manipulating their perception and inducing actions that align with the attacker’s whims. The second scenario ventures into the heart of the publisher, where the attacker injects false data – deceptive status updates from other publishers e.g., Programmable Logic Controllers (PLCs). The repercussions ripple through the entire industrial process, impacting operations based on fraudulent information. This showcases the cascading effects of FDIAs, illustrating the profound threat they pose to the reliability and integrity of IIoT systems. For real-world attack scenarios, Our attacks were conducted on a small MQTT-based IIoT system, using the Fischertechnik Lernfabrik 4.0 9V factory. Finally, we proposes mitigation solutions to safeguard IIoT systems from the far-reaching consequences of false data manipulation. Our attack codes as well as a proof-of-concept are publicly available for further research. Wael Alsabbagh, Chaerin Kim, Peter Langendörfer |
IECON | 1 |
| 2023 | A Stealthy False Command Injection Attack on Modbus based SCADA SystemsabstractModbus is a widely-used industrial protocol in Supervisory Control and Data Acquisition (SCADA) systems for different purposes such as controlling remote devices, monitoring physical processes, data acquisition, etc. Unfortunately, such a protocol lacks security means i.e., authentication, integrity, and confidentiality. This has exposed industrial plants using the Modbus protocol and made them attractive to malicious adversaries who could perform various kinds of cyber-attacks causing significant consequences as Stuxnet showed. In this paper, we exploit the insecurity of the Modbus protocol and perform a stealthy false command injection scenario concealing our injection from the SCADA operator. Our attack approach is comprised of two main phases: 1) Pre-attack phase (offline) where an attacker sniffs, collects and stores sufficient valid request-response pairs in a database, 2) Attack phase (online) where the attacker performs false command injection and conceals his injection by replaying a valid response from his database upon each request sent from the HMI user. Such a scenario is quite severe and might cause disastrous damages in SCADA systems and critical infrastructures if it is successfully implemented by malicious adversaries. Finally, we suggest some appropriate mitigation solutions to prevent such a serious threat. Wael Alsabbagh, Samuel Amogbonjaye, Diego Urrego, Peter Langendörfer |
CCNC | 1 |
| 2023 | Good Night, and Good Luck: A Control Logic Injection Attack on OpenPLCabstractReal hardware PLCs are quite pricey, and some-times are unaffordable for scientists/engineers to build up small testbeds, and conduct their experiments or academic researches. For all that, the OpenPLC project introduces a reasonable alternative option and offers flexibility in programming codes, simulating physical processes and also the possibility of being utilized with low-cost devices e.g., Raspberry Pi and Arduino Uno. Unfortunately, the OpenPLC project was designed without any security in mind i.e., it lacks protection mechanisms such as encryption, authorization, anti-replay algorithms, etc. This allows attackers to fully access the OpenPLC and makes unauthorized changes e.g., start/stop the PLC, setting/updating passwords, removing/altering the user-program, and others. In this paper we conduct intensive investigations and disclose some vulnerabilities existing in the OpenPLC project, showing that an attacker without any prior knowledge neither to the user credentials, nor to the physical process; can access critical information and maliciously alter the user-program the OpenPLC executes. All our experiments were conducted on the latest version of the OpenPLC i.e., V3. Our experimental results proved that attackers can confuse the physical process controlled by the infected OpenPLC. Finally we suggest security recommendations for the OpenPLC founder and engineers to close the disclosed vulnerabilities and have more secure OpenPLC based environments. Wael Alsabbagh, Chaerin Kim, Peter Langendörfer |
IECON | 1 |
| 2023 | You Are What You Attack: Breaking the Cryptographically Protected S7 ProtocolabstractS7 protocol defines an appropriate format for exchanging messages between SIMATIC S7 PLCs and their corresponding engineering software i.e., TIA Portal. Recently, Siemens has provided its newer PLC models and their proprietary S7 protocols with a very developed and sophisticated integrity check mechanism to protect them from various exploits e.g., replay attacks. This paper addresses exactly this point, and investigates the security of the most developed integrity check mechanism that the newest S7CommPlus protocol version implements. Our results showed that the latest S7 PLC models as well as their related protocols are still vulnerable. We found that adversaries can manipulate two hashes that play a significant role in generating keys and bytes for the encryption processes implemented in the S7CommPlus protocol. This allows to reproduce S7 packets and conduct several attacks that eventually impact the operation of the target PLC and the entire physical process it controls. To validate our findings, we test all the attack scenarios presented in this work on a cryptographically protected S7 PLC from the 1500 family which uses the S7CommPlusV3 protocol. Wael Alsabbagh, Peter Langendörfer |
WFCS | 1 |
| 2021 | A Control Injection Attack against S7 PLCs -Manipulating the Decompiled CodeabstractIn this paper, we discuss an approach which allows an attacker to modify the control logic program that runs in S7 PLCs in its high-level decompiled format. Our full attack-chain compromises the security measures of PLCs, retrieves the machine bytecode of the target device, and employs a decompiler to convert the stolen compiled bytecode (low-level) to its decompiled version (high-level) e.g. Ladder Diagram LAD. As the LAD code exposes the structure and semantics of the control logic, our attack also manipulates the LAD code based on the attacker’s understanding to the physical process causing abnormal behaviors of the system that we target. Finally, it converts the infected LAD code to its executable version i.e. machine bytecode that can run on the PLC using a compiler before pushing the malicious code back to the PLC. For a real scenario, we implemented our full attack-chain on a small industrial setting using real S7-300 PLCs, and built the database (for our decompiler and compiler) using 108 different control logic programs of varying complexity, ranging from simple programs consisting of a few instructions to more complex ones including multi functions, sub-functions and data blocks. We tested and evaluated the accuracy of our decompiler and compiler on 5 random programs written for real industrial applications. Our experimental results showed that an external adversary is able to infect S7 PLCs successfully. We eventually suggest some potential mitigation approaches to secure systems against such a threat. Wael Alsabbagh, Peter Langendörfer |
IECON | 1 |