Notes: SoK: Security of Programmable Logic Controllers

Last updated Papers

I wasn’t sufficiently aware of how PLC’s evolution from isolated microprocessor controllers, to networked devices, and now soft PLCs progressively imports conventional computing attack surfaces into systems that still have hard real-time and physical-process constraints.

In PLC world, control logic executes in millisecond-scale scan cycles over sensor inputs and actuator outputs, mediated by firmware, RTOS/runtime, I/O and network modules. Fieldbus protocols such as Modbus and PROFIBUS coexist with Ethernet, MQTT and OPC UA. Attacks consequently span control-logic injection, CPU mode manipulation, firmware modification, runtime/OS compromise, network manipulation, and even I/O-based covert channels.

The SoK systematizes 17 years of PLC security research and finds that 82% of studied attacks require no knowledge of the physical environment. More interestingly, recovery remains comparatively underdeveloped, while research is fragmented across vendors and increasingly between hard and soft PLCs.

SoK: Security of Programmable Logic Controllers