feat(ics): dynamic Modbus/TCP probe for PLC/SPS devices (#148)
CI / Check (pull_request) Failing after 4m3s
CI / Detect Changes (pull_request) Has been skipped
CI / Deploy Agent (pull_request) Has been skipped
CI / Deploy Dashboard (pull_request) Has been skipped
CI / Deploy Docs (pull_request) Has been skipped
CI / Deploy MCP (pull_request) Has been skipped
CI / Check (pull_request) Failing after 4m3s
CI / Detect Changes (pull_request) Has been skipped
CI / Deploy Agent (pull_request) Has been skipped
CI / Deploy Dashboard (pull_request) Has been skipped
CI / Deploy Docs (pull_request) Has been skipped
CI / Deploy MCP (pull_request) Has been skipped
Adds the first dynamic dimension to PLC/SPS targets: probe the running device over industrial protocols, complementing the static control-logic rules. - New ScanType::IcsProbe (+ phase), offered for PlcSps with a reachable endpoint (opt-in / default-off). - pipeline::ics::modbus — a minimal, read-only Modbus/TCP client: issues Read Holding Registers + Read Device Identification, never writes to the live process. Detects an endpoint that answers unauthenticated Modbus and reads its device identity (vendor/product/revision). - pipeline::ics::probe_target — emits findings: `ics-modbus-exposed` (Critical, CWE-306 — Modbus/TCP has no auth/encryption by protocol design) and `ics-device-disclosure` (Low, CWE-200). Targets the Modbus port (502) of the target's Live URL, independent of any WebVisu HTTP port. - orchestrator: a PLC/SPS target runs the ICS probe when planned (alongside the control-logic scan and DAST). Unit-tested against an in-process mock Modbus server + endpoint-parsing and device-id parsing tests. Docs: new "Dynamic testing — ICS protocol probe" section. First increment of #148 (soft-PLC + industrial-protocol probing); OPC UA / EtherNet-IP and the OpenPLC soft-PLC harness (orca-infra) follow. Tracker #167. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
a3f3f1d4f5
commit
5e8250f7e9
@@ -76,3 +76,22 @@ guard-aware), cleartext/insecure communication (CWE-319), insecure protocol port
|
||||
The **SBOM** view lists the CODESYS libraries (`pkg:codesys/<name>@<version>`) and
|
||||
the runtime; matching runtime components (e.g. the `Cmp*` / `3SLicense` libraries)
|
||||
surface real CODESYS advisories as CVE alerts.
|
||||
|
||||
## Dynamic testing — ICS protocol probe
|
||||
|
||||
Beyond the static analysis, Certifai can **probe the running device** over
|
||||
industrial protocols. Attach a **Live URL** artifact (the device host / WebVisu
|
||||
URL) to the PLC/SPS target and enable the **ICS Probe** scan.
|
||||
|
||||
The probe is **read-only** — it never writes to the live process. It currently
|
||||
speaks **Modbus/TCP** (port 502): it confirms whether the device answers
|
||||
unauthenticated Modbus requests and reads its device identity (vendor / product /
|
||||
revision). Because Modbus/TCP has no authentication or encryption in the protocol,
|
||||
a reachable endpoint that answers is reported as an exposed control interface
|
||||
(CWE-306). OPC UA and EtherNet/IP probes are planned.
|
||||
|
||||
::: warning
|
||||
The ICS probe connects to the live device. It is **opt-in** (off by default) and
|
||||
should only be run against targets you are authorized to test. It performs reads
|
||||
only, never writes.
|
||||
:::
|
||||
|
||||
Reference in New Issue
Block a user