Files
Barbason_22142000_2026.pdf
Open access - Adobe PDF
- 2.3 MB
Details
- Supervisors
- Faculty
- Degree label
- Abstract
- ICS systems are becoming increasingly connected, but this increases the risk of cyber attacks, requiring more vulnerability analysis and penetration testing on systems such as PLCs, which were not designed with security measures in mind. This paper demonstrates our physical testbed made of a Revolution Pi Connect+ running NodeRED and controlling a Fischertechnik mini-factory, and our remote setup, which is used to simulate a cloud server, to demonstrate cyber attacks at various ICS levels. A significant number of these attacks, across ICS levels 0 to 4, had a measurable and impactful effect on the network-level, ranging from ARP poisoning, Denial of Service, RST attacks, to application-level, such as replay attacks and NodeRED Flow Injection. Most of these attacks are possible due to a lack of security measures. These results demonstrate that the primary danger is not sophisticated exploitation, but rather the absence of basic security measures on the network architecture and application configuration, whose presence would have prevented the majority of these attacks.