- By:
- Asmar Awad, Rima L; Sprayberry, Michael; Ahmad, Irfan; Rogers, Michael; Lopez Jr, Juan
- Page Number:
- 131-152
- Volume:
- 725
- Book Title:
- Critical Infrastructure Protection XVIII
- Publication Date:
- March 12, 2026
- Publisher Location:
- Springer, Cham, Switzerland
- Conference Name:
- 18th IFIP WG 11.10 International Conference (ICCIP 2024)
- Conference Location:
- Arlington, Virginia, United States of America
- Conference Sponsor:
- Various
- View DOI Listing:
- https://doi.org/10.1007/978-3-031-81888-2_7
Abstract
The introduction of Industry 4.0 and Internet-based technologies has enhanced industrial control system operations but have inadvertently increased their vulnerabilities to cyber attacks. When an industrial control system is compromised, security analysts need to identify the root cause quickly to start the recovery process and develop mitigation strategies. Memory forensics is critical in the incident analysis process to ascertain what occurred. Approaches for analyzing the persistent memory in industrial control devices are limited and almost nonexistent for volatile memory. This chapter proposes an automated methodology for programmable logic controller memory dump analysis using computer vision and deep learning techniques. The methodology converts the sequences of bytes in a programmable logic controller memory dump to red-green-blue pixels and employs a deep learning model that learns the underlying patterns and features of pre-labeled forensic artifacts in images and segments them into distinct regions. The trained model is employed to automatically segment new memory images and identify forensic artifacts. Evaluation of the methodology on a Schneider Electric Modicon M221 programmable logic controller under code injection and code modification attacks demonstrates its ability to detect attack artifacts in memory dumps.