PROFIsafe is a functional-safety communication profile (FSCP 3/1, IEC 61784-3) that carries safety-critical data over PROFIBUS and PROFINET. Its safety measures are designed to detect accidental faults, such as interference, bit flips and delays. This work highlights that such mechanisms, built to tolerate random faults, do not automatically protect against malicious actions. As operational-technology networks become more interconnected with IT infrastructure, the assumption of isolated facilities no longer holds, exposing the system to adversaries the original threat model never considered. We demonstrate that an attacker with access to the communication channel can fully bypass the authentication and integrity checks of the current PROFIsafe version (2021). Although the cyclic redundancy check (CRC) is designed to guarantee message integrity, PROFIsafe also relies on it for implicit authentication. A frame is accepted only if its CRC matches the value expected by the receiver, which depends on a virtual Monitoring Number (MNR). Since the MNR is generated by a weak Fibonacci generator, an attacker passively observing the channel can recover its state from 96 consecutive messages in polynomial time and predict all subsequent values. Knowledge of the current MNR value allows the attacker to forge a valid CRC for any chosen payload, defeating the checks. The impact depends on the underlying medium: full impersonation over PROFINET, and a Denial-of-Service (DoS) over PROFIBUS, where a Man-in-the-Middle position is difficult to obtain. On PROFINET, the attacker can issue arbitrary commands to field devices or transmit forged measurements, that are indistinguishable from legitimate trafic. The shared serial bus and tight RS-485 timing of PROFIBUS degrade the attack to a DoS that compromises system availability. To mitigate this vulnerability, we propose a lightweight, backward-compatible countermeasure based on a truncated HMAC-SHA-256 tag embedded in the existing PROFIsafe payload. This cryptographic authentication is applied at the safety layer and preserves the Black Channel principle.
PROFIsafe è un profilo di comunicazione per la sicurezza funzionale (FSCP 3/1, IEC 61784-3) utilizzato per il trasferimento di dati critici tramite PROFIBUS e PROFINET. I suoi meccanismi di protezione sono progettati per rilevare guasti accidentali, come interferenze, inversioni di bit e ritardi di trasmissione. Questo lavoro evidenzia come tali meccanismi, concepiti per tollerare guasti casuali, non proteggono automaticamente da azioni malevole. La crescente interconnessione tra reti di operational technology (OT) e infrastrutture IT rende obsoleta l'ipotesi di impianti isolati, esponendo i sistemi a minacce non considerate nel modello originale. In questo lavoro dimostriamo che un attaccante con accesso al canale di comunicazione può aggirare i meccanismi di autenticazione ed integrità dell'attuale versione di PROFIsafe (2021). Nonostante il controllo di ridondanza ciclica (CRC) sia progettato per garantire l'integrità dei messaggi, PROFIsafe lo utilizza anche come forma implicita di autenticazione. Un frame viene accettato solo se il suo CRC corrisponde al valore atteso dal ricevitore, dipendente da un numero di monitoraggio virtuale (MNR). Poichè l'MNR è generato da un debole generatore di Fibonacci, un attaccante che osserva passivamente il traffico può ricostruire lo stato a partire da 96 messaggi consecutivi in tempo polinomiale e prevederne tutti i valori futuri. La conoscenza dell'MNR consente all'attaccante di generare CRC validi per payload arbitrari, eludendo i controlli del protocollo. Le conseguenze dipendono dal protocollo sottostante: su PROFINET l'attaccante può impersonare dispositivi legittimi, inviare comandi arbitrari o falsificare misurazioni; su PROFIBUS, i vincoli del bus limitano l'attacco a un Denial-of-Service (DoS), compromettendo la disponibilità del sistema. Per mitigare questa vulnerabilità, proponiamo una contromisura leggera e retrocompatibile basata su un tag HMAC-SHA-256 troncato, incorporato nel payload PROFIsafe già esistente. Questa autenticazione crittografica viene applicata a livello del safety layer, preservando il principio del Black Channel.
When safety is not security: monitoring number recovery attacks in PROFIsafe
CHIAVACCI, ALLEGRA
2025/2026
Abstract
PROFIsafe is a functional-safety communication profile (FSCP 3/1, IEC 61784-3) that carries safety-critical data over PROFIBUS and PROFINET. Its safety measures are designed to detect accidental faults, such as interference, bit flips and delays. This work highlights that such mechanisms, built to tolerate random faults, do not automatically protect against malicious actions. As operational-technology networks become more interconnected with IT infrastructure, the assumption of isolated facilities no longer holds, exposing the system to adversaries the original threat model never considered. We demonstrate that an attacker with access to the communication channel can fully bypass the authentication and integrity checks of the current PROFIsafe version (2021). Although the cyclic redundancy check (CRC) is designed to guarantee message integrity, PROFIsafe also relies on it for implicit authentication. A frame is accepted only if its CRC matches the value expected by the receiver, which depends on a virtual Monitoring Number (MNR). Since the MNR is generated by a weak Fibonacci generator, an attacker passively observing the channel can recover its state from 96 consecutive messages in polynomial time and predict all subsequent values. Knowledge of the current MNR value allows the attacker to forge a valid CRC for any chosen payload, defeating the checks. The impact depends on the underlying medium: full impersonation over PROFINET, and a Denial-of-Service (DoS) over PROFIBUS, where a Man-in-the-Middle position is difficult to obtain. On PROFINET, the attacker can issue arbitrary commands to field devices or transmit forged measurements, that are indistinguishable from legitimate trafic. The shared serial bus and tight RS-485 timing of PROFIBUS degrade the attack to a DoS that compromises system availability. To mitigate this vulnerability, we propose a lightweight, backward-compatible countermeasure based on a truncated HMAC-SHA-256 tag embedded in the existing PROFIsafe payload. This cryptographic authentication is applied at the safety layer and preserves the Black Channel principle.| File | Dimensione | Formato | |
|---|---|---|---|
|
2026_07_Chiavacci_ExecutiveSummary.pdf
accessibile in internet per tutti a partire dal 25/06/2029
Descrizione: Executive Summary
Dimensione
575.79 kB
Formato
Adobe PDF
|
575.79 kB | Adobe PDF | Visualizza/Apri |
|
2026_07_Chiavacci_Tesi.pdf
accessibile in internet per tutti a partire dal 25/06/2029
Descrizione: Thesis
Dimensione
1.27 MB
Formato
Adobe PDF
|
1.27 MB | Adobe PDF | Visualizza/Apri |
I documenti in POLITesi sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.
https://hdl.handle.net/10589/261099