{"id":"https://openalex.org/W4327939490","doi":"https://doi.org/10.1016/j.fsidi.2023.301513","title":"Towards generic memory forensic framework for programmable logic controllers","display_name":"Towards generic memory forensic framework for programmable logic controllers","publication_year":2023,"publication_date":"2023-03-01","ids":{"openalex":"https://openalex.org/W4327939490","doi":"https://doi.org/10.1016/j.fsidi.2023.301513"},"language":"en","primary_location":{"is_oa":true,"landing_page_url":"https://doi.org/10.1016/j.fsidi.2023.301513","pdf_url":null,"source":{"id":"https://openalex.org/S4210178067","display_name":"Forensic Science International Digital Investigation","issn_l":"2666-2817","issn":["2666-2817","2666-2825"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320990","host_organization_name":"Elsevier BV","host_organization_lineage":["https://openalex.org/P4310320990"],"host_organization_lineage_names":["Elsevier BV"],"type":"journal"},"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"publishedVersion","is_accepted":true,"is_published":true},"type":"article","type_crossref":"journal-article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"hybrid","oa_url":"https://doi.org/10.1016/j.fsidi.2023.301513","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5054475455","display_name":"Rima Asmar Awad","orcid":"https://orcid.org/0000-0002-3340-7742"},"institutions":[{"id":"https://openalex.org/I1289243028","display_name":"Oak Ridge National Laboratory","ror":"https://ror.org/01qz5mb56","country_code":"US","type":"facility","lineage":["https://openalex.org/I1289243028","https://openalex.org/I1330989302","https://openalex.org/I39565521","https://openalex.org/I4210159294"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Rima Asmar Awad","raw_affiliation_strings":["Oak Ridge National Laboratory, Oak Ridge, TN, 37830, USA"],"affiliations":[{"raw_affiliation_string":"Oak Ridge National Laboratory, Oak Ridge, TN, 37830, USA","institution_ids":["https://openalex.org/I1289243028"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5007440779","display_name":"Muhammad H. Rais","orcid":"https://orcid.org/0000-0002-9944-1142"},"institutions":[{"id":"https://openalex.org/I184840846","display_name":"Virginia Commonwealth University","ror":"https://ror.org/02nkdxk79","country_code":"US","type":"education","lineage":["https://openalex.org/I184840846"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Muhammad Haris Rais","raw_affiliation_strings":["Virginia Commonwealth University, Richmond, VA, 23284, USA"],"affiliations":[{"raw_affiliation_string":"Virginia Commonwealth University, Richmond, VA, 23284, USA","institution_ids":["https://openalex.org/I184840846"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5058477060","display_name":"Michael E. Rogers","orcid":"https://orcid.org/0000-0002-6790-4050"},"institutions":[{"id":"https://openalex.org/I63920570","display_name":"Tennessee Technological University","ror":"https://ror.org/05drmrq39","country_code":"US","type":"education","lineage":["https://openalex.org/I63920570"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Michael Rogers","raw_affiliation_strings":["Tennessee Technological University, Cookeville, TN, 38505, USA"],"affiliations":[{"raw_affiliation_string":"Tennessee Technological University, Cookeville, TN, 38505, USA","institution_ids":["https://openalex.org/I63920570"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5063509441","display_name":"Irfan Ahmed","orcid":"https://orcid.org/0000-0001-5648-388X"},"institutions":[{"id":"https://openalex.org/I184840846","display_name":"Virginia Commonwealth University","ror":"https://ror.org/02nkdxk79","country_code":"US","type":"education","lineage":["https://openalex.org/I184840846"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Irfan Ahmed","raw_affiliation_strings":["Virginia Commonwealth University, Richmond, VA, 23284, USA"],"affiliations":[{"raw_affiliation_string":"Virginia Commonwealth University, Richmond, VA, 23284, USA","institution_ids":["https://openalex.org/I184840846"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5014047735","display_name":"Vincent Paquit","orcid":"https://orcid.org/0000-0003-0331-2598"},"institutions":[{"id":"https://openalex.org/I1289243028","display_name":"Oak Ridge National Laboratory","ror":"https://ror.org/01qz5mb56","country_code":"US","type":"facility","lineage":["https://openalex.org/I1289243028","https://openalex.org/I1330989302","https://openalex.org/I39565521","https://openalex.org/I4210159294"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Vincent Paquit","raw_affiliation_strings":["Oak Ridge National Laboratory, Oak Ridge, TN, 37830, USA"],"affiliations":[{"raw_affiliation_string":"Oak Ridge National Laboratory, Oak Ridge, TN, 37830, USA","institution_ids":["https://openalex.org/I1289243028"]}]}],"institution_assertions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5054475455"],"corresponding_institution_ids":["https://openalex.org/I1289243028"],"apc_list":{"value":2950,"currency":"USD","value_usd":2950,"provenance":"doaj"},"apc_paid":{"value":2950,"currency":"USD","value_usd":2950,"provenance":"doaj"},"fwci":7.324,"has_fulltext":false,"cited_by_count":10,"citation_normalized_percentile":{"value":0.999475,"is_in_top_1_percent":true,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":95,"max":96},"biblio":{"volume":"44","issue":null,"first_page":"301513","last_page":"301513"},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T12122","display_name":"Physical Unclonable Functions (PUFs) and Hardware Security","score":0.9984,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T12122","display_name":"Physical Unclonable Functions (PUFs) and Hardware Security","score":0.9984,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12495","display_name":"Electrostatic Discharge in Electronics","score":0.9983,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.997,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/microprocessor","display_name":"Microprocessor","score":0.41366172}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7558869},{"id":"https://openalex.org/C149635348","wikidata":"https://www.wikidata.org/wiki/Q193040","display_name":"Embedded system","level":1,"score":0.5705164},{"id":"https://openalex.org/C37374048","wikidata":"https://www.wikidata.org/wiki/Q188674","display_name":"Programmable logic controller","level":2,"score":0.5067645},{"id":"https://openalex.org/C203479927","wikidata":"https://www.wikidata.org/wiki/Q5165939","display_name":"Controller (irrigation)","level":2,"score":0.42893338},{"id":"https://openalex.org/C2780728072","wikidata":"https://www.wikidata.org/wiki/Q5297","display_name":"Microprocessor","level":2,"score":0.41366172},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.27609318},{"id":"https://openalex.org/C6557445","wikidata":"https://www.wikidata.org/wiki/Q173113","display_name":"Agronomy","level":1,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"is_oa":true,"landing_page_url":"https://doi.org/10.1016/j.fsidi.2023.301513","pdf_url":null,"source":{"id":"https://openalex.org/S4210178067","display_name":"Forensic Science International Digital Investigation","issn_l":"2666-2817","issn":["2666-2817","2666-2825"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320990","host_organization_name":"Elsevier BV","host_organization_lineage":["https://openalex.org/P4310320990"],"host_organization_lineage_names":["Elsevier BV"],"type":"journal"},"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"publishedVersion","is_accepted":true,"is_published":true},{"is_oa":true,"landing_page_url":"https://www.osti.gov/biblio/1965252","pdf_url":null,"source":{"id":"https://openalex.org/S4306402487","display_name":"OSTI OAI (U.S. Department of Energy Office of Scientific and Technical Information)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I139351228","host_organization_name":"Office of Scientific and Technical Information","host_organization_lineage":["https://openalex.org/I139351228"],"host_organization_lineage_names":["Office of Scientific and Technical Information"],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false}],"best_oa_location":{"is_oa":true,"landing_page_url":"https://doi.org/10.1016/j.fsidi.2023.301513","pdf_url":null,"source":{"id":"https://openalex.org/S4210178067","display_name":"Forensic Science International Digital Investigation","issn_l":"2666-2817","issn":["2666-2817","2666-2825"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320990","host_organization_name":"Elsevier BV","host_organization_lineage":["https://openalex.org/P4310320990"],"host_organization_lineage_names":["Elsevier BV"],"type":"journal"},"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"publishedVersion","is_accepted":true,"is_published":true},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/9","display_name":"Industry, innovation and infrastructure","score":0.67}],"grants":[],"datasets":[],"versions":[],"referenced_works_count":22,"referenced_works":["https://openalex.org/W1975554273","https://openalex.org/W2041078517","https://openalex.org/W2077699686","https://openalex.org/W2285923621","https://openalex.org/W2569220913","https://openalex.org/W2742236820","https://openalex.org/W2744632709","https://openalex.org/W2768270002","https://openalex.org/W2884147936","https://openalex.org/W2980479439","https://openalex.org/W3013638858","https://openalex.org/W3036981874","https://openalex.org/W4205496345","https://openalex.org/W4221103416","https://openalex.org/W4221118516","https://openalex.org/W4233210494","https://openalex.org/W4241972926","https://openalex.org/W4254042909","https://openalex.org/W4256190543","https://openalex.org/W4284978141","https://openalex.org/W4287105923","https://openalex.org/W4298257387"],"related_works":["https://openalex.org/W39373273","https://openalex.org/W2748952813","https://openalex.org/W2735012529","https://openalex.org/W2732121450","https://openalex.org/W2390545901","https://openalex.org/W2390279801","https://openalex.org/W2387235933","https://openalex.org/W2351709090","https://openalex.org/W2123880708","https://openalex.org/W2098026815"],"abstract_inverted_index":{"A":[0],"Programmable":[1],"Logic":[2],"Controller":[3],"(PLC)":[4],"is":[5,10,89,117],"a":[6,87,121,131,153],"microprocessor-based":[7],"controller":[8],"that":[9,215],"used":[11],"to":[12,56,80,94,96,107,119,166,203],"automate":[13],"physical":[14],"processes":[15],"in":[16,83,219,240],"critical":[17,118,207],"infrastructure":[18],"and":[19,23,34,50,67,75,129,162,175,187,196,210,234],"various":[20],"other":[21],"industries":[22],"manufacturing":[24],"sectors.":[25],"Initially,":[26],"PLCs":[27],"were":[28],"completely":[29],"isolated":[30],"from":[31,62],"the":[32,41,51,63,73,97,101,109,125,141,145,159,170,173,176,220,226,232],"Internet,":[33],"cyber":[35,84,243],"security":[36,91],"was":[37],"not":[38],"incorporated":[39],"at":[40],"time":[42,233],"of":[43,47,53,100,134,144,172,179,206,225,242],"development.":[44],"The":[45,222],"introduction":[46],"industry":[48],"4.0":[49],"evolution":[52],"ICS":[54],"systems":[55,74],"communicate":[57],"over":[58],"public":[59],"IP":[60],"addresses":[61],"Internet":[64,70],"enhanced":[65],"productivity":[66],"efficiency,":[68],"but":[69],"connectivity":[71],"exposed":[72],"their":[76],"vulnerabilities,":[77],"which":[78,200],"led":[79],"an":[81],"increase":[82],"attacks.":[85],"When":[86],"system":[88,246],"sabotaged/compromised,":[90],"analysts":[92],"need":[93],"get":[95],"root":[98],"cause":[99],"attack":[102],"as":[103,105],"quickly":[104],"possible":[106],"recover":[108],"system.":[110],"To":[111,151],"do":[112],"so,":[113],"memory":[114,127,142,154,174,189,208,227],"forensic":[115,213],"analysis":[116,165,239],"provide":[120],"unique":[122],"insight":[123],"into":[124],"run-time":[126],"activities":[128],"extract":[130,211],"reliable":[132],"source":[133],"evidence.":[135],"In":[136],"this":[137],"paper,":[138],"we":[139,156],"analyze":[140],"structure":[143,171],"Schneider":[146],"Electric":[147],"Modicon":[148],"M221":[149],"PLC.":[150],"build":[152],"profile,":[155],"reverse":[157],"engineer":[158],"communication":[160],"protocol":[161],"conduct":[163],"differential":[164,198],"gain":[167],"knowledge":[168],"about":[169],"low-level":[177],"representation":[178],"control":[180],"logic":[181],"instructions.":[182],"We":[183],"then":[184],"identify":[185,204],"dynamic":[186],"static":[188],"regions":[190],"by":[191],"modifying":[192],"different":[193],"project":[194],"fields":[195],"conducting":[197],"analysis,":[199],"allows":[201],"us":[202],"boundaries":[205],"structures":[209],"important":[212],"artifacts":[214],"can":[216,229],"be":[217],"found":[218],"memory.":[221],"Python":[223],"implementation":[224],"profile":[228],"help":[230],"reduce":[231],"effort":[235],"required":[236],"for":[237],"manual":[238],"case":[241],"incident":[244],"or":[245],"failure.":[247]},"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W4327939490","counts_by_year":[{"year":2024,"cited_by_count":4},{"year":2023,"cited_by_count":5}],"updated_date":"2024-12-28T22:14:50.780311","created_date":"2023-03-21"}