A Decade After Stuxnet: How Siemens S7 is Still an Attacker's Heaven

No ratings

Presented at BlackHat Europe 2023 by

Industrial Control Systems have long evolved from specialized electronics communicating over proprietary bus systems to fully-fledged embedded computers based on commodity Ethernet connections. The Stuxnet computer worm of 2010 demonstrated to the general public that this development makes Industrial Control Systems susceptible to cyberattacks with physical consequences. Siemens as the vendor of the affected Programmable Logic Controllers (PLCs) has released multiple new products since then, which double down on Ethernet connectivity in company networks and are expected to conform to higher security standards.In our presentation, we reverse-engineer the Siemens S7-1500 Software Controller PLC up to the communication protocol and show the violation of fundamental security principles. We show that substantial efforts have been put into obfuscating communication and modifying established cryptography primitives without increasing the effective security level. Along the way, we will release a few tools to help with reverse-engineering that particular PLC firmware. Unlike previous publications on this topic, we put an emphasis on providing sufficient details to enable other people to reproduce our research and build upon it. To that end, the S7-1500 Software Controller has been chosen, because it resembles the widespread S7-1500 hardware PLC series while being a software-only PLC, making it very accessible to the broader research community.