Information Assurance and Security (Data Privacy)

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/67

flashcard set

Earn XP

Description and Tags

im a bot(tom)net

Last updated 6:36 PM on 10/5/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

68 Terms

1
New cards

Internet of Things (IoT)

also known as the Internet of Everything (IoE), refers to computing devices that are web-enabled and have the capability of sensing, collecting, and sending data using sensors, and the communication hardware and processors that are embedded within the device.

2
New cards

Thing

refers to a device that is implanted in a natural, human-made, or machine-made object and has the functionality of communicating over a network.

3
New cards

Sensing Technology

Sensors embedded in the devices sense a wide variety of information from their surroundings, including temperature, gases, location, workings of some industrial machinery, or health data of a patient. 

4
New cards

IoT Gateways

Gateways are used to bridge the gap between an IoT device (internal network) and the end-user (external network), thus allowing them to connect and communicate with each other. The data collected by the sensors in the IoT device is sent to the connected user or cloud through the gateway. 

5
New cards

Cloud Server/Data Storage

After traveling through the gateway, the collected data arrives at the cloud, where it is stored and undergoes data analysis. The processed data is then transmitted to the user, who can take certain actions based on the information received. 

6
New cards

Remote Control using Mobile App

The end-user uses remote controls such as mobile phones, tablets, laptops, etc., installed with a mobile app to monitor, control, retrieve data, and take a specific action on IoT devices from a remote location. 

7
New cards

Edge Technology Layer 

This layer consists of all the hardware components, including sensors, radio-frequency identification (RFID) tags, readers, or other soft sensors, and the device itself. These entities are the primary part of the data sensors that are deployed in the field for monitoring or sensing various phenomena.

8
New cards

Access Gateway Layer 

This layer helps to bridge the gap between two endpoints, such as a device and a client. The initial data handling also takes place in this layer. This layer carries out message routing, message identification, and subscribing.

9
New cards

Internet Layer 

This is a crucial layer as it serves as the main component in carrying out communication between two endpoints, such as device-to-device, device-to-cloud, device-to-gateway, or back-end data sharing. 

10
New cards

Middleware Layer 

This is one of the most critical layers that operates in two-way mode. As the name suggests, this layer sits in the middle of the application layer and the hardware layer, thus behaving as an interface between these two layers. It is responsible for important functions such as data management, device management, and various issues like data analysis, data aggregation, data filtering, device information discovery, and access control. 

11
New cards

Application Layer 

This layer, placed at the top of the stack, is responsible for the delivery of services to the relevant users from different sectors, including building, industrial, manufacturing, automobile, security, and healthcare.

12
New cards

DDoS Attack

An attacker converts the devices into an army of botnets to target a specific system or server, making it unavailable to provide services. 

13
New cards

Attack on HVAC Systems

As HVAC (Heating, Ventilation, and Air Conditioning) systems are generally connected to the networks of various industries, government sectors, and hospitals, their vulnerabilities are exploited by attackers to steal confidential information such as user credentials and to perform further attacks on the target network. 

14
New cards

Rolling Code Attack

The code that locks or unlocks a car or garage is called a rolling code or hopping code. It is used in a keyless entry system to prevent replay attacks. An eavesdropper can capture the code transmitted and later use it to unlock the garage or vehicle. 

15
New cards

BlueBorne Attack

Attackers connect to nearby devices and exploit the vulnerabilities of the Bluetooth protocol to compromise the devices. It is a collection of various techniques based on the known vulnerabilities of the Bluetooth protocol. 

16
New cards

Jamming Attack

is a type of attack in which the communications between wireless IoT devices are jammed to compromise them. During this attack, an overwhelming volume of malicious traffic is sent, which results in a DoS attack to authorized users, thus obstructing legitimate traffic and making the endpoints unable to communicate with each other. 

17
New cards

Remote Access using Backdoor

Attackers exploit vulnerabilities in the IoT device to turn it into a backdoor and gain access to an organization’s network. 

18
New cards

Remote Access using Telnet

Attackers exploit an open Telnet port to obtain information that is shared between the connected devices, including their software and hardware models. 

19
New cards

Sybil Attack

An attacker uses multiple forged identities to create a strong illusion of traffic congestion, affecting communication between neighboring nodes and networks. 

20
New cards

Exploit Kits

A malicious script is used by the attackers to exploit poorly patched vulnerabilities in an IoT device. 

21
New cards

Man-in-the-Middle Attack

An attacker pretends to be a legitimate sender who intercepts all the communication between the sender and receiver and hijacks the communication. 

22
New cards

Replay Attack

Attackers intercept legitimate messages from valid communication and continuously send the intercepted message to the target device to perform a denial-of-service attack or crash the target device. 

23
New cards

Forged Malicious Device

Attackers replace authentic IoT devices with malicious devices if they have physical access to the network. 

24
New cards

Side-Channel Attack

Attackers perform side-channel attacks by extracting information about encryption keys by observing the emission of signals, i.e., “side channels”, from IoT devices.

25
New cards

Ransomware Attack

A type of malware that uses encryption to block a user’s access to his/her device, either by locking the screen or by locking the user’s files. 

26
New cards

Client Impersonation

An attacker masquerades as a legitimate smart device/server using a malicious device and compromises an IoT client device by impersonating it to perform unauthorized activities or access sensitive information on behalf of the legitimate client. 

27
New cards

SQL Injection Attack

Attackers perform SQL injection attacks by exploiting vulnerabilities in the mobile or web applications used to control the IoT devices, to gain access to the devices and perform further attacks on them. 

28
New cards

SDR-Based Attack

Using a software-based radio communication system, an attacker can examine the communication signals passing through the IoT network and can send spam messages to the interconnected devices. 

29
New cards

Fault Injection Attack

Also known as perturbation attacks, occurs when an attacker tries to introduce fault behavior in an IoT device, to exploit these faults to compromise the security of that device. 

30
New cards

Optical, Electromagnetic Fault Injection (EMFI), Body Bias Injection (BBI)

The main objective of these attacks is to inject faults into devices by projecting lasers and electromagnetic pulses that are used in analog blocks such as random number generators (RNGs) and for applying high-voltage pulses. 

31
New cards

Power/Clock/Reset Glitching

These types of attacks occur when faults or glitches are injected into the power supply that can be used for remote execution, also causing the skipping of key instructions. Faults can also be injected into the clock network used for delivering a synchronized signal across the chip. 

32
New cards

Frequency/Voltage Tampering

In these attacks, the attackers try to tamper with the operating conditions of a chip, and they can also modify the level of the power supply and alter the clock frequency of the chip. The intention of the attackers is to introduce fault behavior into the chip to compromise the device security. 

33
New cards

Temperature Attacks

Attackers alter the temperature for operating the chip, thereby changing the whole operating environment. This attack can be operated in non-nominal conditions. 

34
New cards

Network Pivoting

An attacker uses a malicious smart device to connect and gain access to a closed server, and then uses that connection to pivot other devices and network connections to the server to steal sensitive information. 

35
New cards

DNS Rebinding Attack

DNS rebinding is a process of obtaining access to a victim’s router using a malicious JavaScript code injected on a web page. 

36
New cards

Firmalyzer 

Enables device vendors and security professionals to perform an automated security assessment of the software that powers IoT devices (firmware) to identify configuration and application vulnerabilities. This tool notifies users about the vulnerabilities discovered and assists in mitigating those in a timely manner.

37
New cards

OT or Operational Technology

is a combination of software and hardware designed to detect or cause changes in industrial operations through direct monitoring and/or controlling of industrial physical devices. 

38
New cards

Assets

Different components of OT are generally referred to as assets. Most OT systems, such as ICSs, comprise physical assets such as sensors and actuators, servers, workstations, network devices, and logical assets that represent the workings and containment of physical assets, such as graphics representing process flow, program logic, firmware, or firewall rules. 

39
New cards

Zones and Conduits

A network segregation technique used to isolate networks and assets to impose and maintain strong access control mechanisms. 

40
New cards

Industrial Network and Business Network

OT generally comprises a collection of automated control systems. These systems are networked to achieve a business objective. A network comprising these systems is known as an industrial network. An enterprise or business network comprises a network of systems that offer an information infrastructure to the business. Businesses often need to establish communications between business networks and industrial networks. 

41
New cards

Industrial Protocols

Most OT systems employ proprietary protocols or non-proprietary protocols. These protocols are generally used for serial communication and can also be used for communication over standard Ethernet using Internet Protocol (IP), along with transport layer protocols TCP or UDP. 

42
New cards

Network Perimeter/Electronic Security Perimeter

The network perimeter is the outermost boundary of a network zone, i.e., a closed group of assets. It acts as a point of separation between the interior and exterior of a zone. Generally, cybersecurity controls are implemented at the network perimeter. 


An Electronic Security Perimeter refers to a boundary between secure and insecure zones. 

43
New cards

Critical Infrastructure

A collection of physical or logical systems and assets, the failure or destruction of which will severely impact security, safety, the economy, or public health. 

44
New cards

The Purdue Model 

Derived from the Purdue Enterprise Reference Architecture (PERA) model, which is a widely used conceptual model that describes the internal connections and dependencies of important components in ICS networks. It is also known as the Industrial Automation and Control System reference model.

45
New cards

Enterprise Zone (IT Systems)

is a part of IT, in which supply-chain management and scheduling are performed using business systems such as SAP and ERP.

46
New cards

Level 5 (Enterprise Network)

This is a corporate-level network where business operations such as B2B (business-to-business) and B2C (business-to-customer) services are performed. Internet connectivity and management can be handled at this level. 

47
New cards

Level 4 (Business Logistics Systems)

All the IT systems supporting the production process in the plant lie at this level. Managing schedules, planning, and other logistics of the manufacturing operations is performed here. 

48
New cards

Manufacturing Zone (OT Systems)

All the devices, networks, control, and monitoring systems reside in this zone.

49
New cards

Level 3 (Operational Systems/Site Operations)

In this level, production management, individual plant monitoring, and control functions are defined. Production workflows and output of the desired product are ensured at this level. 

50
New cards

Level 2 (Control Systems/Area Supervisory Controls)

Supervising, monitoring, and controlling the physical process is carried out at this level. 

51
New cards

Level 1 (Basic Controls/Intelligent Devices)

Analysis and alteration of the physical process can be done at this level. The operations in basic control include “start motors,” “open valves,” “move actuators,” etc. 

52
New cards

Level 0 (Physical Process)

In this level, the actual physical process is defined, and the product is manufactured. Higher levels control and monitor operations at this level; therefore, this layer is also referred to as Equipment Under Control (EUC). A minor error in any of the devices at this level can affect overall operations. 

53
New cards

Industrial Demilitarized Zone (IDMZ) 

is a barrier between the manufacturing zone (OT systems) and the enterprise zone (IT systems) that enables a secure network connection between the two systems.

54
New cards

Maintenance and Administrative Threat 

Attackers exploit zero-day vulnerabilities to target the maintenance and administration of the OT network. By exploiting these vulnerabilities, attackers inject and spread malware to IT systems and target connected industrial control systems such as SCADA and PLC. 

55
New cards

Data Leakage 

Attackers may exploit IT systems connected to the OT network to gain access to the IT/OT gateway and steal operationally significant data such as configuration files. 

56
New cards

Protocol Abuse 

Owing to compatibility issues, many OT systems use outdated legacy protocols and interfaces such as Modbus and CAN bus. Attackers exploit these protocols and interfaces to perform various attacks on OT systems. For example, attackers may abuse the emergency stop (e-stop), which is a safety mechanism used to shut down the machinery in emergencies to execute single-packet attacks. 

57
New cards

Potential Destruction of ICS Resources

Attackers exploit vulnerabilities in OT systems to disrupt or degrade the functionality of the OT infrastructure, leading to life- and safety-critical issues. 

58
New cards

Reconnaissance Attacks 

OT systems allow remote communication with minimal or no encryption or authentication mechanisms. Attackers can perform initial reconnaissance and scanning on the target OT infrastructure to gather information necessary for later stages of the attack.

59
New cards

Denial-of-Service Attacks 

Attackers exploit communication protocols such as Common Industrial Protocol (CIP) to perform DoS attacks on the target OT systems. For example, an attacker may send a malicious CIP connection request to a target device; once a connection is established, he/she may send a fake IP configuration to the device. If the device accepts the configuration, loss of communication may occur between the device and other connected systems.

60
New cards

HMI-Based Attacks 

Human–Machine Interfaces (HMIs) are often called Hacker–Machine Interfaces. Even with the advancement and automation of OT, human interaction and control over the operational process remain challenges due to underlying vulnerabilities. 

61
New cards

Exploiting Enterprise-Specific Systems and Tools

Attackers may target ICS devices such as Safety Instrumented Systems (SIS) to inject malware by exploiting underlying protocols to detect hardware and systems used in communications, and further disrupt or damage their services. 

62
New cards

Spear Phishing 

Attackers send fake emails containing malicious links or attachments, seemingly originating from legitimate or well-known sources, to the victim. When the victim clicks on the link or downloads the attachment, it injects malware, starts damaging resources, and spreads itself to other systems.

63
New cards

Malware Attacks 

Attackers are reusing legacy malware packages that were previously used to exploit IT systems to exploit OT systems. They perform reconnaissance attacks to identify vulnerabilities in newly connected OT systems. Once they detect vulnerabilities, they reuse the older malware versions to perform various attacks on the OT systems. In some scenarios, attackers also develop malware targeting OT systems, such as ICS/SCADA. 

64
New cards

Exploiting Unpatched Vulnerabilities 

Attackers exploit unpatched vulnerabilities in ICS products, firmware, and other software used in OT networks. ICS vendors develop products that are reliable and provide high-speed, real-time performance with no built-in security features.

65
New cards

Side-Channel Attacks 

Attackers perform side-channel attacks to retrieve critical information from an OT system by observing its physical implementation. Attackers use various techniques, such as timing analysis and power analysis, to perform side-channel attacks. 

66
New cards

Buffer Overflow Attack 

The attacker exploits various buffer overflow vulnerabilities that exist in ICS software, such as HMI web interface, ICS web client, communications interfaces, etc., to inject malicious data and commands to modify the normal behavior and operation of the systems.

67
New cards

Exploiting RF Remote Controllers 

OT networks use RF technology to control various industrial operations remotely. RF communication protocols lack built-in security for remote communication. Vulnerabilities in these protocols can be exploited by attackers to perform various attacks on industrial machines that lead to production sabotage, system control, and unauthorized access.

68
New cards

ICS Exploitation Framework (ISF)

is an exploitation framework based on Python that is similar to the Metasploit framework. This tool provides various exploit modules that allow attackers to hack target ICS systems and networks.