Notes: SoK: Security of Programmable Logic Controllers
I wasn’t sufficiently aware of how PLC’s evolution from isolated microprocessor controllers, to networked devices, and now soft PLCs progressively imports conventional computing attack surfaces into systems that still have hard real-time and physical-process constraints.
In PLC world, control logic executes in millisecond-scale scan cycles over sensor inputs and actuator outputs, mediated by firmware, RTOS/runtime, I/O and network modules. Fieldbus protocols such as Modbus and PROFIBUS coexist with Ethernet, MQTT and OPC UA. Attacks consequently span control-logic injection, CPU mode manipulation, firmware modification, runtime/OS compromise, network manipulation, and even I/O-based covert channels.
The SoK systematizes 17 years of PLC security research and finds that 82% of studied attacks require no knowledge of the physical environment. More interestingly, recovery remains comparatively underdeveloped, while research is fragmented across vendors and increasingly between hard and soft PLCs.