Version 2 of the Graphical Realism Framework for Industrial Control Simulation (GRFICS)
Version 2 of the Graphical Realism Framework for Industrial Control Simulation (GRFICS)
This version of GRFICS is organized as 5 VirtualBox VMs (a 3D simulation, a soft PLC, an HMI, a pfsense firewall, and a workstation) communicating with each other on host-only virtual networks. For a more detailed explanation of the entire framework and some background information on ICS networks, please refer to the workshop paper located at https://www.usenix.org/conference/ase18/presentation/formby
A video series walking through VM setup and example attacks is available on the Fortiphyd YouTube channel at https://www.youtube.com/playlist?list=PL2RSrzaDx0R670yPlYPqM51guk3bQjFG5
A commercial version of GRFICS with more scenarios, advanced features, and streamlined usability is being offered by Fortiphyd Logic. Find out more at https://www.fortiphyd.com/training
The simulation VM (named ChemicalPlant) runs a realistic simulation of a chemical process reaction that is controlled and monitored by simulated remote IO devices through a simple JSON API. These remote IO devices are then monitored and controlled by the PLC VM using the Modbus protocol. This VM is located in the ICS network subnet (192.168.95.0/24) with the IP addresses 192.168.95.10-192.168.95.15
The PLC VM (named plc_2) is a modified version of OpenPLC (https://github.com/thiagoralves/OpenPLC_v2) that uses an older version of the libmodbus library with known buffer overflow vulnerabilities. This VM is located in the ICS network subnet (192.168.95.0/24) at 192.168.95.2
The HMI VM (named ScadaBR) primarily contains an operator HMI created using the free ScadaBR software. This HMI is used to monitor the process measurements being collected by the PLC and send commands to the PLC. This VM is located in the DMZ network subnet (192.168.90.0/24) at 192.168.90.5
The firewall VM (named pfSense) provides routing and firewall features between the DMZ and ICS network. The WAN interface is on the DMZ subnet (192.168.90.0/24) at 192.168.90.100 and the LAN interface is on the ICS subnet (192.168.95.0/24) at 192.168.95.1
The workstation VM is an Ubuntu 16.04 machine with software used for programming the OpenPLC. The workstation is located in the ICS network (192.168.95.0/24) at 192.168.95.5.
Download and install the latest version of VirtualBox.
Create a host-only interface in VirtualBox.
Download an image for both the desktop and server versions of 64-bit Ubuntu 16.04.
See instructions for each VM in corresponding directories.
Download VMs:
Add 2 host-only adapters in VirtualBox:
Your VirtualBox settings should look something like the below screenshot, although the names will likely differ.
Import each VM into VirtualBox using File->Import Appliance
Go into each VM's network settings, and attach each adapter to the correct network:
Start all the VMs. Attention, it is important to follow a boot order for the vm:
If for some reason you start first ScadaBR and then the other VMs, the HMI could not be able to retrive data from the Chemical Plant. In this case you can log in the Chemical Plant VM and run run_all.sh in ~/GRIFICSv2/simulation_vm/simulation/remote_io/modbus.
VM credentials
If you downloaded a VM, the simulation scripts should start on boot. If not, log into the simulation VM and open 2 terminals. In one, cd into the ~/GRFICSv2/simulation_vm/simulation
directory and run ./simulation
. In the second terminal, cd into the ~/GRFICSv2/simulation_vm/simulation/remote_io/modbus
directory and run sudo bash run_all.sh
.
If you downloaded a VM, the PLC should start on boot. If not, log into plc VM, cd into the OpenPLC_v2 directory, and run sudo nodejs server.js
Point your internet browser to the IP address of the simulation VM (default 192.168.95.10) to view the visualization.