Skip to main content

Digital Forensics in Industrial Control Systems

  • Conference paper
  • First Online:

Part of the book series: Lecture Notes in Computer Science ((LNPSE,volume 11698))

Abstract

The increasing complexity of industrial control systems (ICS) and interconnection with other systems poses more safety- and/or security-related challenges due to a rising number of attacks and errors. The event reconstruction is the goal of the new field of ICS forensics differing from well-established Desktop-IT forensics. We identify ICS properties, implications and the impact on the forensic process.

Our primary contribution is the identifcation of ICS specific properties and their impact on the forensic process in order to foster forensic capabilities and forensic readiness in ICS. An existing model for Desktop-IT forensics is successfully adapted for use in ICS.

This is a preview of subscription content, log in via an institution.

Buying options

Chapter
USD   29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD   49.99
Price excludes VAT (USA)
  • Available as EPUB and PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD   64.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Learn about institutional subscriptions

References

  1. Inman, K., Rudin, N.: Principles and Practises of Criminalistics: The Profession of Forensic Science. CRC Press LLC, Boca Raton (2001)

    Google Scholar 

  2. Pollitt, M.: Applying traditional forensic taxonomy to digital forensics. In: Ray, I., Shenoi, S. (eds.) DigitalForensics 2008. ITIFIP, vol. 285, pp. 17–26. Springer, Boston, MA (2008). https://doi.org/10.1007/978-0-387-84927-0_2

    Chapter  Google Scholar 

  3. Kiltz, S., Dittmann, J., Vielhauer, C.: Supporting forensic design - a course profile to teach forensics. In: IMF 2015. IEEE, Magdeburg (2015)

    Google Scholar 

  4. Peisert, S., Bishop, M., Marzullo, K.: Computer forensics in forensis. In: SADFE 2008, pp. 102–112. IEEA, Seattle (2008)

    Article  Google Scholar 

  5. PROFIBUS and PROFINET International, PROFIBUS. https://www.profibus.com/technology/profibus/. Accessed 3 Feb 2019

  6. PROFIBUS and PROFINET International: PROFINET. https://www.profibus.com/technology/profinet/. Accessed 3 Feb 2019

  7. Modbus Organisation: Modbus. http://www.modbus.org/. Accessed 3 Feb 2019

  8. ENISA: Introduction to Network Forensics. https://www.enisa.europa.eu/topics/trainings-for-cybersecurity-specialists/online-training-material/documents/introduction-to-network-forensics-ex1-toolset.pdf. Accessed 20 Feb 2019

  9. Rockwell Automation: Converged Plantwide Ethernet (CPwE) Design and Implementation Guide. https://literature.rockwellautomation.com/idc/groups/literature/documents/td/enet-td001_-en-p.pdf. Accessed 3 Feb 2019

  10. International Electrotechnical Commission: IEC 62443-2-1:2010 Industrial communication networks - Network and system security - Part 2–1: Establishing an industrial automation and control system security program (2010)

    Google Scholar 

  11. Van Vliet, P., Kechadi, M.-T., Le-Khac, N.-A.: Forensics in industrial control system: a case study. https://arxiv.org/ftp/arxiv/papers/1611/1611.01754.pdf. Accessed 3 Feb 19

  12. Williams, T.J.: The Purdue enterprise reference architecture: a technical guide for CIM planning and implementation. Instrument Society of America, Research Triangle Park, NC (1992)

    Google Scholar 

Download references

Acknowledgements

This document was produced with the financial assistance of the European Union. The views expressed herein can in no way be taken to reflect the official opinion of the European Union.

Author information

Authors and Affiliations

Authors

Corresponding author

Correspondence to Robert Altschaffel .

Editor information

Editors and Affiliations

Rights and permissions

Reprints and permissions

Copyright information

© 2019 Springer Nature Switzerland AG

About this paper

Check for updates. Verify currency and authenticity via CrossMark

Cite this paper

Altschaffel, R., Hildebrandt, M., Kiltz, S., Dittmann, J. (2019). Digital Forensics in Industrial Control Systems. In: Romanovsky, A., Troubitsyna, E., Bitsch, F. (eds) Computer Safety, Reliability, and Security. SAFECOMP 2019. Lecture Notes in Computer Science(), vol 11698. Springer, Cham. https://doi.org/10.1007/978-3-030-26601-1_9

Download citation

  • DOI: https://doi.org/10.1007/978-3-030-26601-1_9

  • Published:

  • Publisher Name: Springer, Cham

  • Print ISBN: 978-3-030-26600-4

  • Online ISBN: 978-3-030-26601-1

  • eBook Packages: Computer ScienceComputer Science (R0)

Publish with us

Policies and ethics