1/84
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Internet of Things (IoT)
also known as the Internet of Everything (IoE)
Internet of Things (IoT)
refers to computing devices that are web-enabled and have the capability of sensing, collecting, and sending data using sensors, and the communication hardware and processors that are embedded within the device.
“thing”
refers to a device that is implanted in a natural, human-made, or machine-made object and has the functionality of communicating over a network.
connectivity, sensors, artificial intelligence, small devices, and active engagement.
key features of the IoT are
Sensing Technology
Sensors embedded in the devices sense a wide variety of information from their surrounding
IoT Gateways
are used to bridge the gap between an IoT device (internal network) and the end-user (external network)
IoT Gateways
allows them to connect and communicate with each other. The data collected by the sensors in the IoT device is sent to the connected user or cloud through the gateway.
Cloud Server/ Data Storage
collected data arrives at the cloud, where it is stored and undergoes data analysis. The processed data is then transmitted to the user, who can take certain actions based on the information received
Remote Control using Mobile App
takes a specific action on IoT devices from a remote location
IoT Architecture
includes several layers designed to meet the requirements of various sectors, including societies, industry, enterprises, goverments.
Edge Technology Layer
consists of all the hardware components, including sensors, radio-frequency identification tags (RFID), readers.
Edge Technology Layer
These entries are the primary part of the data sensors that are deployed in the field for monitoring or sensing various phenomena
Access Gateway Layer
helps to bridge the gap between two endpoints
Access Gateway Layer
data handling takes place in this layer. carries out message routing, message identification, and subscribing
Internet Layer
it serves as the main component in carrying out communication between two endpoints, such as device to device etc.
Middleware Layer
operates in two-way mode. it sits in the middle of the application layer and the hardware layer. which becomes the interface
Middleware Layer
responsible for functions such as data management, device management, and various issues like data analysis, data aggregation, data filtering, device information discovery, and access control
Application Layer
placed at the top of the stack
Application Layer
responsible for the delivery of services to the relevant users from different sectors, including building, industrial etc.
DDoS Attack
converts the devices into an army of botnets to target a specific system
Attack on HVAC Systems
are connected to the networks of various buildings, which means that data can be targeted
Rolling Code Attack or Hopping Code
locks or unlocks a car garage
Rolling Code Attack or Hopping Code
a keyless entry system to prevent replay attacks. can be captured by an eavesdropper
Blue Borne Attack
connects to nearby devices and exploit it using Bluetooth protocol
Jamming Attack
communications between wireless IoT devices are jammed to compromise them
Jamming Attack
overwhelming volume of malicous code traffic is sent
Remote Access using Backdoor
uses a backdoor to gain access to a network
Remote Access using Telnet
exploits an open Telnet port to obtain information that is shared between the connected devices, both hardware and software
Sybil Attack
uses multiple forged identities to create a strong illusion of traffic congestion
Exploit Kits
malicious script used by the attackers to exploit poorly patched vulnerabilities
Man in the middle attack
pretends to be a legitimate sender who intercepts all the communication between the sender and reciever
Replay Attack
intercepts legitimate messages from valid communication and continously send the intercepted message to the target device to perform a denial of service attack or crash the target device
Forged Malicious Device
replace authentic IoT devices with malicious devices if they have physical access to the netwrok
Side-Channel Attack
performs attacks by extracting information about encryption keys by observing the emission of signals
Ransomware Attack
uses encryption to block a users access to their device, either by locking the screen or by locking the files
Client Impersonation
masquerades as a legitimate smart device or server using a malicious device and compromises on impersonating it to perform malicous activities
SQL Injection Attack
exploiting vulnerabilites in the mobile or web apps used to control the IoT devices
SDR-Based Attack
uses a software based radio communication system, can send spam messages to the interconnected devices
Fault Injection Attack
also known as perturbation attacks
Fault Injection Attack
occurs when an attacker tries to introduce fault behavior
Optical, Electromagnetic Fault Injection (EMFI), Body Bias Injection (BBI)
The main objective of these attacks is to inject faults into devices by projecting lasers and electromagnetic pulses that are used in analog blocks such as random number generators (RNGs) and for applying high-voltage pulses.
Power/Clock/Reset Glitching
These types of attacks occur when faults or glitches are injected into the power supply that can be used for remote execution, also causing the skipping of key instructions. Faults can also be injected into the clock network used for delivering a synchronized signal across the chip.
Frequency/Voltage Tampering
can also modify the level of the power supply and alter the clock frequency of the chip. The intention of the attackers is to introduce fault behavior into the chip to compromise the device security.
Temperature Attacks
This attack can be operated in non-nominal conditions.
Network Pivoting
uses a smart device to connect and again access to a closed server, and uses that connection to pivot other devices
DNS Rebinding Attack
obtaining access to a victims router using a malicious JavaScript code injected on a webpage
Firmanalyzer
Enables device vendors and security professionals to perform an automated security assessment of the
software that powers IoT devices (firmware) to identify configuration and application vulnerabilities. This tool
notifies users about the vulnerabilities discovered and assists in mitigating those in a timely manner.
Operational Technology
combination of software and hardware designed to detect or cause changes through direct monitoring/controlling of physical devices
Assets
components of OT are called
Zones and Conduits
used to isolate networks and assets to impose and maintain strong access control mechanisms
Industrial Network and Business Network
a collection of automated control systems
Industrial Protocols
used for serial communication and can also be used for communication over standard Ethernet using IP, along with transport layer protocols TCP or UDP
Network Perimeter/Electronic Security Perimeter
it is the outermost boundary of a network zone/a closed group of assets.
Network Perimeter/Electronic Security Perimeter
acts as point of separation between the interior and exterior of a zone.
Electronic Security Permiter
boundery between secure and insecure zones
Network Perimeter
where does cybersecurity controls are implemented?
Critical Infastructure
collection of physical and logical systems and assets
The Purdue Model
describes the internal connections and dependencies of important components in ICS networks
The Purdue Model
also known as Industrial Automation and Control System Reference Model
Enterprise Zone (IT Systems)
supply-chain management and scheduling are perforfmed using business systems such as SAP and ERP
Level 5 (Enterprise Network)
a corporate level network where business operations such as B2B and B2C services are performed
Level 5 (Enterprise Network)
Internet connecitivity and management can be handled in this level
Level 4 (Business Logistics Systems)
All the IT systems supporting the production process in the plant lie at this level
Manufacturing Zone (OT Systems)
All the devices, networks, control, and monitoring systems reside in this zone
Level 3 (Operational Systems/Site Operations)
In this level, production management, individual plant monitoring, and control functions are defined. Production workflows and output of the desired product are ensured at this level.
Level 2 (Control Systems/Area Supervisory Control)
Supervising, monitoring, and controlling the physical process is carried out at this level.
Level 1 (Basic Controls/Intelligent Devices
Analysis and alteration of the physical process can be done at this level. The operations in basic control include “start motors,” “open valves,” “move actuators,” etc.
Level 0 (Physical Process)
In this level, the actual physical process is defined, and the product is manufactured. Higher levels control and monitor operations at this level; therefore, this layer is also referred to as Equipment Under Control (EUC). A minor error in any of the devices at this level can affect overall operations.
Industrial Demilitarized Zone (IDMZ)
The demilitarized zone is a barrier between the manufacturing zone (OT systems) and the enterprise zone (IT systems) that enables a secure network connection between the two system
Industrial Demilitarized Zone (IDMZ)
The zone is created to inspect
the overall architecture. If any errors or intrusions compromise the working systems, the IDMZ holds the error and allows production to continue without interruption.
Maintenance and Administrative Threat
Attackers exploit zero-day vulnerabilities to target the maintenance and administration of the OT network.
Data Leakage
Attackers may exploit IT systems connected to the OT network to gain access to the IT/OT gateway and steal operationally significant data such as configuration files.
Protocol Abuse
many OT systems use outdated legacy protocols and interfaces such as Modbus and CAN bus
Potential Destruction of ICS Resources
Attackers exploit vulnerabilities in OT systems to disrupt or degrade the functionality of the OT infrastructure, leading to life- and safety-critical issues.
Reconnaissance Attacks
OT systems allow remote communication with minimal or no encryption or authentication mechanism
Denial-of-Service Attacks
Attackers exploit communication protocols such as Common Industrial Protocol (CIP) to perform DoS attacks on the target OT systems.
HMI-Based Attacks
often called Hacker–Machine Interface.human interaction and control over the operational process remain challenges due to underlying vulnerabilities.
Exploiting Enterprise-Specific Systems and Tools
inject malware by exploiting underlying protocols to detect hardware and systems used in communications, and further disrupt or damage their services.
Spear Phishing
Attackers send fake emails containing malicious links or attachments, seemingly originating from legitimate or well-known sources, to the victim.
Malware Attacks
Attackers are reusing legacy malware packages that were previously used to exploit IT systems to exploit OT system
Exploiting Unpatched Vulnerabilities
these vendors cannot develop patches for the identified vulnerabilities at the same speed as IT vendor
Side-Channel Attacks
to retrieve critical information from an OT system by observing its physical implementation
Buffer Overflow Attack
inject malicious data and commands to modify the normal behavior and operation of the systems.
Exploiting RF Remote Controller
lack built-in security for remote communication
ICS Exploitation Framework (ISF)
is an exploitation framework based on Python that is similar to the Metasploit framework. This tool provides various exploit modules that allow attackers to hack target ICS systems and networks.