March 2026

Conference Paper

Automated Programmable Logic Controller Memory Forensics Using RGB Image Analysis and Deep Learning

By:
Asmar Awad, Rima L; Sprayberry, Michael; Ahmad, Irfan; Rogers, Michael; Lopez Jr, Juan
Page Number:
131-152
Volume:
725
Book Title:
Critical Infrastructure Protection XVIII
Publication Date:
March 12, 2026
Publisher Location:
Springer, Cham, Switzerland
Conference Name:
18th IFIP WG 11.10 International Conference (ICCIP 2024)
Conference Location:
Arlington, Virginia, United States of America
Conference Sponsor:
Various
View DOI Listing:
https://doi.org/10.1007/978-3-031-81888-2_7

Abstract

The introduction of Industry 4.0 and Internet-based technologies has enhanced industrial control system operations but have inadvertently increased their vulnerabilities to cyber attacks. When an industrial control system is compromised, security analysts need to identify the root cause quickly to start the recovery process and develop mitigation strategies. Memory forensics is critical in the incident analysis process to ascertain what occurred. Approaches for analyzing the persistent memory in industrial control devices are limited and almost nonexistent for volatile memory. This chapter proposes an automated methodology for programmable logic controller memory dump analysis using computer vision and deep learning techniques. The methodology converts the sequences of bytes in a programmable logic controller memory dump to red-green-blue pixels and employs a deep learning model that learns the underlying patterns and features of pre-labeled forensic artifacts in images and segments them into distinct regions. The trained model is employed to automatically segment new memory images and identify forensic artifacts. Evaluation of the methodology on a Schneider Electric Modicon M221 programmable logic controller under code injection and code modification attacks demonstrates its ability to detect attack artifacts in memory dumps.