# Low-overhead and Non-invasive Electromagnetic Side-Channel Monitoring for Forensic-ready Industrial Control Systems

Canonical URL: https://markscanlon.co/publications/EM-SCAForensicReadinessICS

CSL-JSON: https://markscanlon.co/publications/EM-SCAForensicReadinessICS.csl.json
BibTeX: https://markscanlon.co/publications/EM-SCAForensicReadinessICS.bib
RIS: https://markscanlon.co/publications/EM-SCAForensicReadinessICS.ris

Authors: Buddhima Weerasinghe; Asanka Sayakkara; Kasun De Zoysa; Mark Scanlon
Venue: Digital Forensics Doctoral Symposium
Year: 2025
DOI: https://doi.org/10.1145/3712716.3712722
PDF: https://markscanlon.co/publications/EM-SCAForensicReadinessICS.pdf
Full text: https://markscanlon.co/publications/EM-SCAForensicReadinessICS.full.md

## Contribution Summary

This work explores the potential of using electromagnetic (EM) radiation emitted by industrial control systems (ICS) network infrastructure as a window to detect network-based threats and act as a trigger mechanism to activate the forensic readiness features of the ICS infrastructure. The authors propose an approach to monitor ICS network infrastructure using unintentional EM radiation emitted by Ethernet network cables during their regular operation. An empirical evaluation highlights that it is possible to detect various types of denial of service (DoS) attacks through EM emission patterns of Ethernet cables with considerable accuracy. The work introduces an architecture for the ICS infrastructure to be forensic-ready with minimal computational resources while being independent and non-invasive to the infrastructure itself.

## Abstract

Industrial control systems (ICS) are the backbone of modern manufacturing facilities. Due to the distributed nature of ICS hardware in their deployment environment, they are often networked through Ethernet, opening up a window for network-based attacks. Preventive security measures, such as constant packet capture and inspection, are impractical due to the computational overhead required. Therefore, computationally feasible trigger mechanisms are needed that can activate security, as well as on-demand forensic readiness features, in the infrastructure. This work proposes an approach to monitor ICS network infrastructure using unintentional electromagnetic (EM) radiation emitted by Ethernet network cables during their regular operation. An empirical evaluation highlights that it is possible to detect various types of denial of service (DoS) attacks through EM emission patterns of Ethernet cables with considerable accuracy (HTTP Flood = 99.70%, TCP Flood = 73.22%, UDP Flood = 69.95%). Based on the experimental findings, this work introduces an architecture for the ICS infrastructure to be forensic-ready with minimal computational resources while being independent and non-invasive to the infrastructure itself.

