1/67
im a bot(tom)net
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Internet of Things (IoT)
also known as the Internet of Everything (IoE), refers to computing devices that are web-enabled and have the capability of sensing, collecting, and sending data using sensors, and the communication hardware and processors that are embedded within the device.
Thing
refers to a device that is implanted in a natural, human-made, or machine-made object and has the functionality of communicating over a network.
Sensing Technology
Sensors embedded in the devices sense a wide variety of information from their surroundings, including temperature, gases, location, workings of some industrial machinery, or health data of a patient.
IoT Gateways
Gateways are used to bridge the gap between an IoT device (internal network) and the end-user (external network), thus allowing them to connect and communicate with each other. The data collected by the sensors in the IoT device is sent to the connected user or cloud through the gateway.
Cloud Server/Data Storage
After traveling through the gateway, the collected data arrives at the cloud, where it is stored and undergoes data analysis. The processed data is then transmitted to the user, who can take certain actions based on the information received.
Remote Control using Mobile App
The end-user uses remote controls such as mobile phones, tablets, laptops, etc., installed with a mobile app to monitor, control, retrieve data, and take a specific action on IoT devices from a remote location.
Edge Technology Layer
This layer consists of all the hardware components, including sensors, radio-frequency identification (RFID) tags, readers, or other soft sensors, and the device itself. These entities are the primary part of the data sensors that are deployed in the field for monitoring or sensing various phenomena.
Access Gateway Layer
This layer helps to bridge the gap between two endpoints, such as a device and a client. The initial data handling also takes place in this layer. This layer carries out message routing, message identification, and subscribing.
Internet Layer
This is a crucial layer as it serves as the main component in carrying out communication between two endpoints, such as device-to-device, device-to-cloud, device-to-gateway, or back-end data sharing.
Middleware Layer
This is one of the most critical layers that operates in two-way mode. As the name suggests, this layer sits in the middle of the application layer and the hardware layer, thus behaving as an interface between these two layers. It is responsible for important functions such as data management, device management, and various issues like data analysis, data aggregation, data filtering, device information discovery, and access control.
Application Layer
This layer, placed at the top of the stack, is responsible for the delivery of services to the relevant users from different sectors, including building, industrial, manufacturing, automobile, security, and healthcare.
DDoS Attack
An attacker converts the devices into an army of botnets to target a specific system or server, making it unavailable to provide services.
Attack on HVAC Systems
As HVAC (Heating, Ventilation, and Air Conditioning) systems are generally connected to the networks of various industries, government sectors, and hospitals, their vulnerabilities are exploited by attackers to steal confidential information such as user credentials and to perform further attacks on the target network.
Rolling Code Attack
The code that locks or unlocks a car or garage is called a rolling code or hopping code. It is used in a keyless entry system to prevent replay attacks. An eavesdropper can capture the code transmitted and later use it to unlock the garage or vehicle.
BlueBorne Attack
Attackers connect to nearby devices and exploit the vulnerabilities of the Bluetooth protocol to compromise the devices. It is a collection of various techniques based on the known vulnerabilities of the Bluetooth protocol.
Jamming Attack
is a type of attack in which the communications between wireless IoT devices are jammed to compromise them. During this attack, an overwhelming volume of malicious traffic is sent, which results in a DoS attack to authorized users, thus obstructing legitimate traffic and making the endpoints unable to communicate with each other.
Remote Access using Backdoor
Attackers exploit vulnerabilities in the IoT device to turn it into a backdoor and gain access to an organization’s network.
Remote Access using Telnet
Attackers exploit an open Telnet port to obtain information that is shared between the connected devices, including their software and hardware models.
Sybil Attack
An attacker uses multiple forged identities to create a strong illusion of traffic congestion, affecting communication between neighboring nodes and networks.
Exploit Kits
A malicious script is used by the attackers to exploit poorly patched vulnerabilities in an IoT device.
Man-in-the-Middle Attack
An attacker pretends to be a legitimate sender who intercepts all the communication between the sender and receiver and hijacks the communication.
Replay Attack
Attackers intercept legitimate messages from valid communication and continuously send the intercepted message to the target device to perform a denial-of-service attack or crash the target device.
Forged Malicious Device
Attackers replace authentic IoT devices with malicious devices if they have physical access to the network.
Side-Channel Attack
Attackers perform side-channel attacks by extracting information about encryption keys by observing the emission of signals, i.e., “side channels”, from IoT devices.
Ransomware Attack
A type of malware that uses encryption to block a user’s access to his/her device, either by locking the screen or by locking the user’s files.
Client Impersonation
An attacker masquerades as a legitimate smart device/server using a malicious device and compromises an IoT client device by impersonating it to perform unauthorized activities or access sensitive information on behalf of the legitimate client.
SQL Injection Attack
Attackers perform SQL injection attacks by exploiting vulnerabilities in the mobile or web applications used to control the IoT devices, to gain access to the devices and perform further attacks on them.
SDR-Based Attack
Using a software-based radio communication system, an attacker can examine the communication signals passing through the IoT network and can send spam messages to the interconnected devices.
Fault Injection Attack
Also known as perturbation attacks, occurs when an attacker tries to introduce fault behavior in an IoT device, to exploit these faults to compromise the security of that device.
Optical, Electromagnetic Fault Injection (EMFI), Body Bias Injection (BBI)
The main objective of these attacks is to inject faults into devices by projecting lasers and electromagnetic pulses that are used in analog blocks such as random number generators (RNGs) and for applying high-voltage pulses.
Power/Clock/Reset Glitching
These types of attacks occur when faults or glitches are injected into the power supply that can be used for remote execution, also causing the skipping of key instructions. Faults can also be injected into the clock network used for delivering a synchronized signal across the chip.
Frequency/Voltage Tampering
In these attacks, the attackers try to tamper with the operating conditions of a chip, and they can also modify the level of the power supply and alter the clock frequency of the chip. The intention of the attackers is to introduce fault behavior into the chip to compromise the device security.
Temperature Attacks
Attackers alter the temperature for operating the chip, thereby changing the whole operating environment. This attack can be operated in non-nominal conditions.
Network Pivoting
An attacker uses a malicious smart device to connect and gain access to a closed server, and then uses that connection to pivot other devices and network connections to the server to steal sensitive information.
DNS Rebinding Attack
DNS rebinding is a process of obtaining access to a victim’s router using a malicious JavaScript code injected on a web page.
Firmalyzer
Enables device vendors and security professionals to perform an automated security assessment of the software that powers IoT devices (firmware) to identify configuration and application vulnerabilities. This tool notifies users about the vulnerabilities discovered and assists in mitigating those in a timely manner.
OT or Operational Technology
is a combination of software and hardware designed to detect or cause changes in industrial operations through direct monitoring and/or controlling of industrial physical devices.
Assets
Different components of OT are generally referred to as assets. Most OT systems, such as ICSs, comprise physical assets such as sensors and actuators, servers, workstations, network devices, and logical assets that represent the workings and containment of physical assets, such as graphics representing process flow, program logic, firmware, or firewall rules.
Zones and Conduits
A network segregation technique used to isolate networks and assets to impose and maintain strong access control mechanisms.
Industrial Network and Business Network
OT generally comprises a collection of automated control systems. These systems are networked to achieve a business objective. A network comprising these systems is known as an industrial network. An enterprise or business network comprises a network of systems that offer an information infrastructure to the business. Businesses often need to establish communications between business networks and industrial networks.
Industrial Protocols
Most OT systems employ proprietary protocols or non-proprietary protocols. These protocols are generally used for serial communication and can also be used for communication over standard Ethernet using Internet Protocol (IP), along with transport layer protocols TCP or UDP.
Network Perimeter/Electronic Security Perimeter
The network perimeter is the outermost boundary of a network zone, i.e., a closed group of assets. It acts as a point of separation between the interior and exterior of a zone. Generally, cybersecurity controls are implemented at the network perimeter.
An Electronic Security Perimeter refers to a boundary between secure and insecure zones.
Critical Infrastructure
A collection of physical or logical systems and assets, the failure or destruction of which will severely impact security, safety, the economy, or public health.
The Purdue Model
Derived from the Purdue Enterprise Reference Architecture (PERA) model, which is a widely used conceptual model that describes the internal connections and dependencies of important components in ICS networks. It is also known as the Industrial Automation and Control System reference model.
Enterprise Zone (IT Systems)
is a part of IT, in which supply-chain management and scheduling are performed using business systems such as SAP and ERP.
Level 5 (Enterprise Network)
This is a corporate-level network where business operations such as B2B (business-to-business) and B2C (business-to-customer) services are performed. Internet connectivity and management can be handled at this level.
Level 4 (Business Logistics Systems)
All the IT systems supporting the production process in the plant lie at this level. Managing schedules, planning, and other logistics of the manufacturing operations is performed here.
Manufacturing Zone (OT Systems)
All the devices, networks, control, and monitoring systems reside in this zone.
Level 3 (Operational Systems/Site Operations)
In this level, production management, individual plant monitoring, and control functions are defined. Production workflows and output of the desired product are ensured at this level.
Level 2 (Control Systems/Area Supervisory Controls)
Supervising, monitoring, and controlling the physical process is carried out at this level.
Level 1 (Basic Controls/Intelligent Devices)
Analysis and alteration of the physical process can be done at this level. The operations in basic control include “start motors,” “open valves,” “move actuators,” etc.
Level 0 (Physical Process)
In this level, the actual physical process is defined, and the product is manufactured. Higher levels control and monitor operations at this level; therefore, this layer is also referred to as Equipment Under Control (EUC). A minor error in any of the devices at this level can affect overall operations.
Industrial Demilitarized Zone (IDMZ)
is a barrier between the manufacturing zone (OT systems) and the enterprise zone (IT systems) that enables a secure network connection between the two systems.
Maintenance and Administrative Threat
Attackers exploit zero-day vulnerabilities to target the maintenance and administration of the OT network. By exploiting these vulnerabilities, attackers inject and spread malware to IT systems and target connected industrial control systems such as SCADA and PLC.
Data Leakage
Attackers may exploit IT systems connected to the OT network to gain access to the IT/OT gateway and steal operationally significant data such as configuration files.
Protocol Abuse
Owing to compatibility issues, many OT systems use outdated legacy protocols and interfaces such as Modbus and CAN bus. Attackers exploit these protocols and interfaces to perform various attacks on OT systems. For example, attackers may abuse the emergency stop (e-stop), which is a safety mechanism used to shut down the machinery in emergencies to execute single-packet attacks.
Potential Destruction of ICS Resources
Attackers exploit vulnerabilities in OT systems to disrupt or degrade the functionality of the OT infrastructure, leading to life- and safety-critical issues.
Reconnaissance Attacks
OT systems allow remote communication with minimal or no encryption or authentication mechanisms. Attackers can perform initial reconnaissance and scanning on the target OT infrastructure to gather information necessary for later stages of the attack.
Denial-of-Service Attacks
Attackers exploit communication protocols such as Common Industrial Protocol (CIP) to perform DoS attacks on the target OT systems. For example, an attacker may send a malicious CIP connection request to a target device; once a connection is established, he/she may send a fake IP configuration to the device. If the device accepts the configuration, loss of communication may occur between the device and other connected systems.
HMI-Based Attacks
Human–Machine Interfaces (HMIs) are often called Hacker–Machine Interfaces. Even with the advancement and automation of OT, human interaction and control over the operational process remain challenges due to underlying vulnerabilities.
Exploiting Enterprise-Specific Systems and Tools
Attackers may target ICS devices such as Safety Instrumented Systems (SIS) to inject malware by exploiting underlying protocols to detect hardware and systems used in communications, and further disrupt or damage their services.
Spear Phishing
Attackers send fake emails containing malicious links or attachments, seemingly originating from legitimate or well-known sources, to the victim. When the victim clicks on the link or downloads the attachment, it injects malware, starts damaging resources, and spreads itself to other systems.
Malware Attacks
Attackers are reusing legacy malware packages that were previously used to exploit IT systems to exploit OT systems. They perform reconnaissance attacks to identify vulnerabilities in newly connected OT systems. Once they detect vulnerabilities, they reuse the older malware versions to perform various attacks on the OT systems. In some scenarios, attackers also develop malware targeting OT systems, such as ICS/SCADA.
Exploiting Unpatched Vulnerabilities
Attackers exploit unpatched vulnerabilities in ICS products, firmware, and other software used in OT networks. ICS vendors develop products that are reliable and provide high-speed, real-time performance with no built-in security features.
Side-Channel Attacks
Attackers perform side-channel attacks to retrieve critical information from an OT system by observing its physical implementation. Attackers use various techniques, such as timing analysis and power analysis, to perform side-channel attacks.
Buffer Overflow Attack
The attacker exploits various buffer overflow vulnerabilities that exist in ICS software, such as HMI web interface, ICS web client, communications interfaces, etc., to inject malicious data and commands to modify the normal behavior and operation of the systems.
Exploiting RF Remote Controllers
OT networks use RF technology to control various industrial operations remotely. RF communication protocols lack built-in security for remote communication. Vulnerabilities in these protocols can be exploited by attackers to perform various attacks on industrial machines that lead to production sabotage, system control, and unauthorized access.
ICS Exploitation Framework (ISF)
is an exploitation framework based on Python that is similar to the Metasploit framework. This tool provides various exploit modules that allow attackers to hack target ICS systems and networks.