• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Konferenzschrift
  4. Show Me What You Got: Vulnerabilities of Industrial Components Revealed by Automated Blackbox Testing
 
  • Details
  • Full
Options
2026
Conference Paper
Title

Show Me What You Got: Vulnerabilities of Industrial Components Revealed by Automated Blackbox Testing

Abstract
Operational Technology Components (OTCs) that control and monitor industrial processes are a valuable target for attackers. Reducing the likelihood of successful attacks requires identifying, assessing, and mitigating vulnerabilities in those components. To achieve this, blackbox penetration testing can be applied. However, traditional approaches to penetration testing do not take the specificities of OTCs, such as their focus on availability and their resource constraints, into account. Thus, we describe a test strategy specifically targeting OTCs, and consequently apply this strategy to ten OTCs. Our experiments reveal findings for all considered OTCs, including crashes, hangs, and information on outdated software. Most crashes or hangs are concerned with SNMP and TCP (6,418 and 2,864 findings in total, respectively). We analyzed some of the more severe crashes and found that they were caused either by overload or unexpected TCP options. Moreover, we identified limitations of the u sed tools with respect to fingerprinting, severity assessment, and crash detection.
Author(s)
Borcherding, Anne  
Fraunhofer-Institut für Optronik, Systemtechnik und Bildauswertung IOSB  
Giraud, Mark Leon
Fraunhofer-Institut für Optronik, Systemtechnik und Bildauswertung IOSB  
Tzigiannis, Laura
Fraunhofer-Institut für Optronik, Systemtechnik und Bildauswertung IOSB  
Mainwork
ICISSP 2026, 12th International Conference on Information Systems Security and Privacy. Proceedings. Vol.2  
Conference
International Conference on Information Systems Security and Privacy 2026  
Open Access
File(s)
Download (249.1 KB)
Rights
CC BY-NC-ND 4.0: Creative Commons Attribution-NonCommercial-NoDerivatives
DOI
10.5220/0014355200004061
10.24406/publica-8046
Language
English
Fraunhofer-Institut für Optronik, Systemtechnik und Bildauswertung IOSB  
Keyword(s)
  • Operational Technology

  • Vulnerability Scanning

  • Fuzzing

  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024