PLC Source Code Protection Failures and Solutions

No ratings

Presented at S4 2014 by

This session evaluates mechanisms used by major PLC vendors that provide source code protection for their products. Their research has found that vendors such as Rockwell Automation, Siemens and Omron use similar protection schemes that can be readily bypassed and shows how exploitation of vulnerabilities can lead not only to system malfunction, but also to loss of intellectual property-affecting vendors, asset owners and system integrators. The ability to remove source code protection has serious financial implications. Not only can the asset owners begin maintaining their own code (cutting out support contracts), but competitors who gain access to protected source files can steal the intellectual property. There are also security concerns for the asset owners. Being able to remove source code protection could allow an attacker to maliciously modify the ladder logic before it is loaded on the PLC to achieve more significant physical effects. The researchers will also present a scheme that enables vendors to maintain their current feature set, while providing secure implementation of source code protection.