Geri Dön

Zafiyet veritabanlarına göre trafo merkezlerindeki akıllı elektronik cihazların firmware analizörü

Firmware analyzer of intelligent electronic devices in substations based on vulnerability databases

  1. Tez No: 1000116
  2. Yazar: KHOULOUD GARGOURI
  3. Danışmanlar: DOÇ. DR. MURAT İSKEFİYELİ
  4. Tez Türü: Yüksek Lisans
  5. Konular: Bilgisayar Mühendisliği Bilimleri-Bilgisayar ve Kontrol, Computer Engineering and Computer Science and Control
  6. Anahtar Kelimeler: Belirtilmemiş.
  7. Yıl: 2024
  8. Dil: Türkçe
  9. Üniversite: Sakarya Üniversitesi
  10. Enstitü: Fen Bilimleri Enstitüsü
  11. Ana Bilim Dalı: Bilgisayar Mühendisliği Ana Bilim Dalı
  12. Bilim Dalı: Siber Güvenlik Bilim Dalı
  13. Sayfa Sayısı: Belirtilmemiş.

Özet

Modern toplum, kritik altyapılarının düzgün işleyişine büyük ölçüde bağımlıdır. Gelişmekte olan teknolojiler, yüksek yaşam standartlarına katkı sağlarken; sanayileşmiş ülkeler ulaşım, iletişim, finansal işlemler, gıda temini ve sağlık hizmetleri gibi alanlarda bilgi ve iletişim sistemlerine güvenmektedir. Endüstriyel Kontrol Sistemleri (EKS), bu kritik altyapıların izlenmesi, sürdürülmesi ve yönetilmesi açısından hayati öneme sahiptir. Enerji sektöründe ise EKS, elektrik üretimi, iletimi ve dağıtımı süreçlerinde vazgeçilmezdir. Akıllı Şebeke'nin artan bağlantılı yapısıyla birlikte, koruma, kontrol ve izleme gibi işlevler hızla gelişen iletişim altyapılarına bağımlı hale gelmiştir. Bu dijital entegrasyon, Kritik Altyapıların performansını önemli ölçüde artırmış; hizmet kalitesini yükseltmiş, operasyonel verimlilik sağlamış, otomasyonu desteklemiş ve maliyetleri düşürmüştür. Ancak aynı zamanda, endüstriyel cihazların internete maruz kalmasıyla birlikte siber saldırıların sayısında ciddi bir artışa yol açmıştır. Bu bağlantılı yapı, saldırı yüzeyini genişleterek tehdit aktörlerinin kritik sistemleri tehlikeye atmasını kolaylaştırmıştır. Elektrik şebekesine yönelik iyi planlanmış bir siber saldırı, ciddi ekipman hasarlarına ve yaygın elektrik kesintilerine neden olabilir. Akıllı şebekeler içerisinde, Akıllı Elektronik Cihazlar (IED'ler), SCADA haberleşmesi, gerçek zamanlı izleme ve istasyonlardaki olaylara özgü veri kaydı gibi işlevleri mümkün kılan temel bileşenlerdir. Ancak bu IED'lerde yerleşik olarak bulunan üretici yazılımları (firmware), çoğunlukla istismar edilebilir zafiyetler içermekte olup, onları siber saldırılar için cazip hedefler haline getirmektedir. Bu zafiyetlerin tespit edilmesi ve giderilmesi, siber güvenlik uzmanları için kritik bir görevdir. Teknik olarak zafiyet tespitleri pasif ya da aktif tarama yöntemleriyle gerçekleştirilmektedir. Yapılan araştırmalar, pasif yöntemlerin genellikle daha verimli olduğunu, daha kısa sürede, doğru sonuçlar verdiğini ve ağda rahatsız edici trafik oluşturmadan çalıştığını ortaya koymaktadır. Bu durum, özellikle aktif tarayıcıların oluşturduğu yoğun trafik nedeniyle dengesizleşebilen ya da durma riski taşıyan EKS ortamlarında büyük önem taşır. Bu nedenle, Pasif Zafiyet Tespiti (PZT), Operasyonel Teknoloji (OT) ortamları için daha uygun kabul edilmektedir. Her zafiyet tarama sürecinin temelinde, özellikle pasif tarama cihazların doğru şekilde tanımlanması yatmaktadır. Eğer bir cihazın statik özelliklerinden herhangi biri hatalı belirlenirse, zafiyet tarama sonuçları da hatalı olabilir. Bu tür cihaz bilgileri genellikle OT varlık envanterinde tutulur ve her endüstriyel kuruluşun bu envantere sahip olması gerekir. Ancak, özellikle Programlanabilir Lojik Kontrolörler (PLC'ler) ve IED'ler gibi gömülü endüstriyel cihazlar söz konusu olduğunda, eksiksiz ve doğru bir varlık envanterinin sürdürülmesi büyük bir zorluk oluşturmaktadır. Bu zorlukları göz önünde bulunduran bu çalışma, mevcut envanterlerde eksiklikler bulunduğu varsayımıyla, zafiyet taramasına başlamadan önce cihazlara ait üretici, model, seri numarası ve donanım/yazılım sürümleri gibi detaylı bilgilerin yapılandırma dosyalarından çıkarılmasını amaçlamaktadır. Bu çalışma, Akıllı Şebeke uygulamaları için özel olarak tasarlanmış, Endüstriyel Kontrol Sistemlerindeki (EKS) IED'lerde zafiyet tespiti amacıyla yarı otomatik ve müdahalesiz bir yaklaşım sunmaktadır. Önerilen yöntem, IEC 61850 standardı ile uyumlu Trafo Merkezi Yapılandırma Dili (SCL) dosyalarını kullanarak IED'lerin üretici, model, donanım ve yazılım/firmware sürümleri gibi statik özelliklerini operasyonel ağlara doğrudan müdahale etmeden çıkarmaktadır. Bu çıkarılan özellikler, cihaz üreticilerinin (örneğin ABB, Siemens) yayınladığı güvenlik duyuruları, Ulusal Zafiyet Veritabanı (NVD) ve Ortak Zayıflık Sınıflandırması (CWE) ile eşleştirilerek her bir IED için kapsamlı bir zafiyet raporu üretilmektedir. Raporlar, EKS şirketlerinin %60'ından fazlasının ekipmanlarındaki açıkları tespit etmek için üretici güvenlik duyurularına güvendiğini ortaya koymaktadır. Bu çalışma özellikle bu süreci sadeleştirmeye odaklanmakta ve bir veya daha fazla IED için zafiyet raporlamasını otomatikleştiren bir araç sunmaktadır. Bu sayede operatörler zaman ve çabadan tasarruf etmektedir. Geleneksel Aktif Zafiyet Taraması (AVS) araçlarının yüksek ağ trafiği ya da müdahaleci sorgularla OT sistemlerini bozma riski bulunurken, önerilen Pasif Zafiyet Tespiti (PVD) yaklaşımı, herhangi bir paket enjeksiyonu ya da müdahaleci işlem gerçekleştirmediği için güvenli bir şekilde çalışmaktadır. Üretilen zafiyet raporları yalnızca her bir IED'yi etkileyen bilinen CVE'leri listelemekle kalmaz; aynı zamanda risk puanları, saldırı vektörleri, zayıflık sınıflandırmaları, etkilenen sürümler, üretici tarafından yayınlanan yamalar ve önerilen önlemler gibi kritik meta verileri de içerir. Bu kapsamlı veri seti, operasyon mühendisleri ve siber güvenlik analistlerinin EKS altyapılarının açıklık ve dayanıklılık düzeyini değerlendirmelerine yardımcı olmak amacıyla yapılandırılmış ve aranabilir bir veritabanında toplanmaktadır. Sistemin deneysel doğrulaması, Sakarya Üniversitesi Ulusal Kritik Altyapılar Test Merkezi (CENTER Energy) bünyesindeki üretim, iletim, dağıtım ve tüketimi kapsayan gerçekçi bir enerji sistemleri test ortamında gerçekleştirilmiştir. ABB'nin REF615, REL650 ve RET670 IED cihazları üzerinde başarıyla test edilmiş ve önerilen çözüm, her cihazı etkileyen bilinen tüm zafiyetleri doğru bir şekilde tespit etmiştir. Sonuçlar, IEC 61850 yapılandırma dosyası analizinin pasif zafiyet tespitiyle bütünleştirilmesinin, trafo merkezleri ve diğer EKS bileşenlerinin siber güvenlik duruşunu güçlendirmede etkili ve uygulanabilir bir yöntem olduğunu göstermektedir. Bilindiği kadarıyla, bu çalışma, SCL dosyalarından IED bilgilerini çıkarma ve bu bilgileri NVD, CWE ve üretici duyuruları ile zenginleştirerek eyleme geçirilebilir zafiyet değerlendirmeleri oluşturma sürecini uçtan uca otomatikleştiren ilk çalışmadır. Ayrıca bu araştırma, yeniden kullanılabilir ve genişletilebilir bir veritabanı modeli sunarak çoklu cihaz üreticilerini destekleyebilecek şekilde ölçeklenebilir bir yapı ortaya koymakta ve gerçek dünyadaki OT/EKS ortamlarında yaygın olarak uygulanabilirliği mümkün kılmaktadır. Önerilen metodoloji, varlık görünürlüğü ve zafiyet istihbaratının sıklıkla parçalı ve güncel olmayan yapısını bütünleyerek EKS siber güvenliğinde önemli bir boşluğu doldurmaktadır. Sonuç olarak, bu tez, kritik altyapı ortamlarında zafiyet değerlendirmesi için pratik, ölçeklenebilir ve doğru bir yaklaşım sunmaktadır. Standartlaştırılmış yapılandırma analizini tehdit istihbarat kaynaklarıyla entegre ederek, EKS için otomatik, gerçek zamanlı ve üretici bağımsız siber güvenlik çözümlerinin gelecekteki gelişimine zemin hazırlamaktadır. Gelecekteki iyileştirmeler arasında, aracın veritabanının farklı üreticilere ait IED'leri kapsayacak şekilde genişletilmesi ve hem veritabanı oluşturma hem de yapılandırma dosyalarının elde edilmesi süreçlerinin tamamen otomatik hale getirilmesi yer almaktadır.

Özet (Çeviri)

Modern society relies heavily on the smooth operation of its critical infrastructure. Emerging technologies contribute to high living standards, while industrialized countries depend on information and communication systems for transportation, communication, financial transactions, food supply, and healthcare services. Industrial Control Systems (ICS) are essential for overseeing, maintaining, and managing these critical infrastructures. In the energy sector, ICS is vital for power generation, transmission, and distribution. With the increasing interconnectivity of the Smart Grid, functions such as protection, control, and monitoring have become heavily dependent on rapidly evolving communication infrastructures. Substations play a central role in the distribution process by transforming high-voltage electricity into low voltage, and digital substations offer additional advantages such as improved measurement accuracy, ease of configuration, and real-time performance. These substations also incorporate additional digital components, including electronic relays, merging units, SCADA gateways, HMIs, time synchronization devices, and networking equipment. While this digital integration has significantly enhanced the performance of the energy systems—offering benefits like improved service quality, operational efficiency, automation, and cost savings—it has also led to a surge in cyber-attacks due to the exposure of industrial devices to the internet. This connectivity has broadened the attack surface, giving threat actors more opportunities to compromise critical systems. A well-orchestrated cyber-attack on the power grid could result in severe equipment damage and widespread blackouts. Within smart grids, Intelligent Electronic Devices (IEDs) serve as essential elements, providing functions such as protection, control, real-time monitoring, measurement, and communication. Categorized into control, monitoring, and protection types, IEDs work together to enhance the reliability, maintainability, and quality of the power system and are generally compatible with protocols such as IEC 61850, Modbus, and DNP3. A single multifunctional IED can simultaneously incorporate protection functions, communication protocols, and monitoring capabilities. However, the widespread adoption of Ethernet and TCP/IP-based communication has exposed these devices to the internet and wide-area networks, leaving them vulnerable to cyberattacks. Compromising an IED can lead to the takeover of substation equipment control, manipulation of measurements, and cascading failures that put the entire grid at risk. Therefore, identifying software vulnerabilities in IEDs and implementing protective measures against them is a vital task for cybersecurity experts. Technically, vulnerability detections are carried out using either passive or active scanning techniques. Research indicates that passive methods are generally more efficient, providing accurate results with minimal scanning time and without introducing disruptive traffic into the network. This is particularly important for ICS systems, which are highly sensitive and can be destabilized or shut down by the intrusive traffic generated by active scanners. Therefore, Passive Vulnerability Detection (PVD) is typically more suitable for Operational Technology (OT) environments. The cornerstone of any vulnerability scanning process—especially passive scanning—is the precise identification of devices. If any static attribute of a device is incorrectly defined, the vulnerability scanning results may be inaccurate. This device information is typically maintained in the OT asset inventory, which every industrial organization should possess. Despite its importance for cybersecurity and vulnerability management, maintaining a complete and accurate asset inventory remains a major challenge—especially for embedded industrial devices like Programmable Logic Controllers (PLCs) and IEDs. Acknowledging these challenges, this study assumes the presence of gaps in current asset inventories and proposes a method to extract detailed device information (such as manufacturer, model, serial number, and hardware/software versions) from configuration files before initiating vulnerability scans. In the Passive Vulnerability Detection (PVD) method, system components are generally matched with CVE–CPE records. However, this approach has limitations: some CVE entries lack CPE identifiers, there may be gaps or outdated data in CPE–CVE mappings, and inconsistent CPE assignments for the same product can be observed across different sources. Moreover, in security advisories and notices issued by vendors, instead of the devices' CPEs, static information such as models, software and hardware versions, and design standards is provided. For these reasons, in this work, vulnerabilities are identified by matching based on this device information rather than relying on CPE. IEC 61850 is an international standard designed to standardize communication between Intelligent Electronic Devices (IEDs) in substations. It organizes device data using a hierarchical, object-oriented model, allowing each data object to be uniquely identified and accessed across the network through the MMS protocol. In addition, the standard introduces the Substation Configuration Language (SCL), an XML-based format that describes the configuration of IEC 61850 systems. SCL files serve as comprehensive documentation, detailing device characteristics and the overall system topology. This work presents a semi-automated and non-intrusive approach to vulnerability detection in IEDs within Industrial Control Systems (ICS), specifically designed for smart grid applications. The proposed method utilizes Substation Configuration Language (SCL) files compliant with the IEC 61850 standard to extract static attributes of IEDs — including vendor, model, hardware, and firmware versions — without requiring direct interaction with operational networks. These extracted attributes are then correlated with publicly available security advisories from device manufacturers (e.g., ABB), the National Vulnerability Database (NVD), and the Common Weakness Enumeration (CWE) database to generate a comprehensive vulnerability report for each identified IED. Reports reveal that over 60% of ICS companies rely on vendor-issued security advisories to detect flaws in their equipment. This study focuses particularly on streamlining this process, introducing a tool that automates vulnerability reporting for one or more IEDs, helping operators save time and effort. A three-stage method is proposed for identifying vulnerabilities in IEDs:  Preparation stage: A comprehensive vulnerability database was created using data obtained from sources such as ABB security bulletins, the NVD, and the CWE. The vulnerability data were stored in a MySQL database.  Manual operations stage: The IP addresses of the IEDs in the target system were identified through Nmap's ARP scan, after which the SCL files were extracted using IEDExplorer and stored for analysis.  Automated processing stage: A Python-based program parsed these files to determine the static information of the device, which was then matched with the database to generate device-specific reports containing the relevant vulnerabilities and mitigation recommendations. Additionally, the user may manually enter the information of a device. In this case, the vulnerability detection process is carried out in the same way without parsing SCL files. Unlike injectionsal Active Vulnerability Scanning (AVS) tools, which may disrupt OT systems due to high network traffic or intrusive queries, the proposed Passive Vulnerability Detection (PVD) approach ensures safe operation by avoiding any packet injection or intrusive actions. The generated vulnerability reports not only list known CVEs affecting each IED but also include critical metadata such as risk scores, attack vectors, weakness classifications, affected versions, vendor-issued patches, and suggested mitigations. This extensive dataset is assembled into a structured and searchable database that can serve both operational engineers and cybersecurity analysts in evaluating the exposure and resilience of their ICS infrastructure. Experimental validation of the system was conducted using a realistic test environment, the energy systems—covering production, transmission, distribution, and consumption—at the National Critical Infrastructures Testbed Center at Sakarya University (CENTER Energy). It was successfully evaluated on ABB's REF615, REL650, and RET670 IED devices and the proposed solution produced accurate results including all the known vulnerabilities affecting each device. The results highlight the feasibility and effectiveness of combining IEC 61850 configuration parsing with passive vulnerability detection correlation for enhancing the cybersecurity posture of substations and other ICS components. To the best of our knowledge, this is the first study to automate the end-to-end process of extracting IED information from SCL files and enriching it with data from NVD, CWE, and vendor disclosures to produce actionable vulnerability assessments. Furthermore, this research contributes a reusable and extensible database model that can be scaled to support multiple device vendors, enabling wider applicability in real-world OT/ICS environments. The proposed methodology bridges a crucial gap in ICS cybersecurity, where asset visibility and vulnerability intelligence often remain fragmented and outdated. In conclusion, this thesis provides a practical, scalable, and accurate approach to vulnerability assessment in critical infrastructure environments. By integrating standardized configuration analysis with threat intelligence sources, it lays the groundwork for future developments in automated, real-time, and vendor-agnostic cybersecurity solutions for ICS. Future improvements may include expanding the tool's database to include IEDs from various vendors and automating both the database generation and configuration files retrieval processes.

Benzer Tezler

  1. Veri tabanı güvenlik riskleri, şifreleme algoritmaları ve enjeksiyon modelleri

    Database security risks, encryption algorithm and injection models

    ERTÜRK ERDAĞI

    Yüksek Lisans

    Türkçe

    Türkçe

    2017

    Bilgisayar Mühendisliği Bilimleri-Bilgisayar ve Kontrolİstanbul Teknik Üniversitesi

    Bilişim Uygulamaları Ana Bilim Dalı

    DOÇ. DR. ENVER ÖZDEMİR

  2. Mikroservis tabanlı ağ uygulamalarında zararlı davranışların saptanması

    Detecting malicious behavior in microservices-based web applications

    MUSTAFA ÖZBEK

    Yüksek Lisans

    Türkçe

    Türkçe

    2019

    Bilgisayar Mühendisliği Bilimleri-Bilgisayar ve Kontrolİstanbul Teknik Üniversitesi

    Bilgisayar Mühendisliği Ana Bilim Dalı

    DR. ÖĞR. ÜYESİ MEHMET TAHİR SANDIKKAYA

  3. Expanding password dictionaries by generating new probable passwords using machine learning techniques

    Makine öğrenmesi teknikleri ile yeni olası şifreler üreterek şifre sözlüklerinin genişletilmesi

    MEHMET GÖRKEM KESTANE

    Yüksek Lisans

    İngilizce

    İngilizce

    2024

    Bilgisayar Mühendisliği Bilimleri-Bilgisayar ve KontrolAkdeniz Üniversitesi

    Bilgisayar Mühendisliği Ana Bilim Dalı

    DR. ÖĞR. ÜYESİ MURAT AK

  4. Kurumsal bilgi güvenliğinde zafiyet, saldırı ve savunma öğelerinin incelenmesi

    Examination of vulnerability, attack and defense elements in corporate information security

    GÖKHAN MUHARREMOĞLU

    Yüksek Lisans

    Türkçe

    Türkçe

    2013

    Bilim ve Teknolojiİstanbul Üniversitesi

    Enformatik Ana Bilim Dalı

    PROF. DR. SEVİNÇ GÜLSEÇEN

  5. Web uygulamalarında zafiyet oluşturabilecek Türkçe dosya ve dizin isimleri analizi

    Analysis directory and file names in Turkish that can cause vulnerability on web application

    ONUR AKTAŞ

    Yüksek Lisans

    Türkçe

    Türkçe

    2018

    Bilgisayar Mühendisliği Bilimleri-Bilgisayar ve KontrolGazi Üniversitesi

    Bilgi Güvenliği Mühendisliği Ana Bilim Dalı

    PROF. DR. ŞEREF SAĞIROĞLU