Skip to content
Preprint

RISK: Auditing Industrial Control Systems for Too-Late-to-Recover Vulnerabilities

Sep 2026 · 0 citations · 42 references
Computer Science

Abstract

The security of industrial control systems (ICS) is important. Yet most ICS security efforts focus on the detection of ICS attacks, with much less attention to the recovery after detection. In this paper, we address this underexplored area by jointly auditing the detection and recovery of ICS. Specifically, we define the too-late-to-recover (TLTR) vulnerability, which allows an attack to drain the available recovery margin before being detected, such that the subsequent recovery procedure will fail to bring the ICS back to a safe state due to the insufficient margin. To audit an ICS for TLTR vulnerabilities, we develop RISK, an automated framework that discovers and validates possible TLTR attack scenarios. RISK holistically models and analyzes, statically and dynamically, the PLC control logic, attack detection policies, recovery procedures, and operational behaviors of an ICS to generate TLTR attack scenarios with concrete attack parameters. We evaluate RISK on three ICS testbeds as well as a real-world fertilizer production plant. Across the three testbeds, a total of 392 TLTR attacks are generated and confirmed, whereas only a small fraction of them can be discovered by existing ICS vetting tools. In the real-world plant, RISK identified a critical TLTR vulnerability which was validated by plant engineers.

View source

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.