data privacy Midterm

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/84

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 3:11 PM on 10/1/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

85 Terms

1
New cards

Internet of Things (IoT)

also known as the Internet of Everything (IoE)

2
New cards

Internet of Things (IoT)

refers to computing devices that are web-enabled and have the capability of sensing, collecting, and sending data using sensors, and the communication hardware and processors that are embedded within the device.

3
New cards

“thing”

refers to a device that is implanted in a natural, human-made, or machine-made object and has the functionality of communicating over a network.

4
New cards

connectivity, sensors, artificial intelligence, small devices, and active engagement.

key features of the IoT are

5
New cards

Sensing Technology

Sensors embedded in the devices sense a wide variety of information from their surrounding

6
New cards

IoT Gateways

are used to bridge the gap between an IoT device (internal network) and the end-user (external network)

7
New cards

IoT Gateways

allows them to connect and communicate with each other. The data collected by the sensors in the IoT device is sent to the connected user or cloud through the gateway.

8
New cards

Cloud Server/ Data Storage

collected data arrives at the cloud, where it is stored and undergoes data analysis. The processed data is then transmitted to the user, who can take certain actions based on the information received

9
New cards

Remote Control using Mobile App

takes a specific action on IoT devices from a remote location

10
New cards

IoT Architecture

includes several layers designed to meet the requirements of various sectors, including societies, industry, enterprises, goverments.

11
New cards

Edge Technology Layer

consists of all the hardware components, including sensors, radio-frequency identification tags (RFID), readers.

12
New cards

Edge Technology Layer

These entries are the primary part of the data sensors that are deployed in the field for monitoring or sensing various phenomena

13
New cards

Access Gateway Layer

helps to bridge the gap between two endpoints

14
New cards

Access Gateway Layer

data handling takes place in this layer. carries out message routing, message identification, and subscribing

15
New cards

Internet Layer

it serves as the main component in carrying out communication between two endpoints, such as device to device etc.

16
New cards

Middleware Layer

operates in two-way mode. it sits in the middle of the application layer and the hardware layer. which becomes the interface

17
New cards

Middleware Layer

responsible for functions such as data management, device management, and various issues like data analysis, data aggregation, data filtering, device information discovery, and access control

18
New cards

Application Layer

placed at the top of the stack

19
New cards

Application Layer

responsible for the delivery of services to the relevant users from different sectors, including building, industrial etc.

20
New cards

DDoS Attack

converts the devices into an army of botnets to target a specific system

21
New cards

Attack on HVAC Systems

are connected to the networks of various buildings, which means that data can be targeted

22
New cards

Rolling Code Attack or Hopping Code

locks or unlocks a car garage

23
New cards

Rolling Code Attack or Hopping Code

a keyless entry system to prevent replay attacks. can be captured by an eavesdropper

24
New cards

Blue Borne Attack

connects to nearby devices and exploit it using Bluetooth protocol

25
New cards

Jamming Attack

communications between wireless IoT devices are jammed to compromise them

26
New cards

Jamming Attack

overwhelming volume of malicous code traffic is sent

27
New cards

Remote Access using Backdoor

uses a backdoor to gain access to a network

28
New cards

Remote Access using Telnet

exploits an open Telnet port to obtain information that is shared between the connected devices, both hardware and software

29
New cards

Sybil Attack

uses multiple forged identities to create a strong illusion of traffic congestion

30
New cards

Exploit Kits

malicious script used by the attackers to exploit poorly patched vulnerabilities

31
New cards

Man in the middle attack

pretends to be a legitimate sender who intercepts all the communication between the sender and reciever

32
New cards

Replay Attack

intercepts legitimate messages from valid communication and continously send the intercepted message to the target device to perform a denial of service attack or crash the target device

33
New cards

Forged Malicious Device

replace authentic IoT devices with malicious devices if they have physical access to the netwrok

34
New cards

Side-Channel Attack

performs attacks by extracting information about encryption keys by observing the emission of signals

35
New cards

Ransomware Attack

uses encryption to block a users access to their device, either by locking the screen or by locking the files

36
New cards

Client Impersonation

masquerades as a legitimate smart device or server using a malicious device and compromises on impersonating it to perform malicous activities

37
New cards

SQL Injection Attack

exploiting vulnerabilites in the mobile or web apps used to control the IoT devices

38
New cards

SDR-Based Attack

uses a software based radio communication system, can send spam messages to the interconnected devices

39
New cards

Fault Injection Attack

also known as perturbation attacks

40
New cards

Fault Injection Attack

occurs when an attacker tries to introduce fault behavior

41
New cards

Optical, Electromagnetic Fault Injection (EMFI), Body Bias Injection (BBI)

The main objective of these attacks is to inject faults into devices by projecting lasers and electromagnetic pulses that are used in analog blocks such as random number generators (RNGs) and for applying high-voltage pulses.

42
New cards

Power/Clock/Reset Glitching

These types of attacks occur when faults or glitches are injected into the power supply that can be used for remote execution, also causing the skipping of key instructions. Faults can also be injected into the clock network used for delivering a synchronized signal across the chip.

43
New cards

Frequency/Voltage Tampering

can also modify the level of the power supply and alter the clock frequency of the chip. The intention of the attackers is to introduce fault behavior into the chip to compromise the device security.

44
New cards

Temperature Attacks

This attack can be operated in non-nominal conditions.

45
New cards

Network Pivoting

uses a smart device to connect and again access to a closed server, and uses that connection to pivot other devices

46
New cards

DNS Rebinding Attack

obtaining access to a victims router using a malicious JavaScript code injected on a webpage

47
New cards

Firmanalyzer

Enables device vendors and security professionals to perform an automated security assessment of the

software that powers IoT devices (firmware) to identify configuration and application vulnerabilities. This tool

notifies users about the vulnerabilities discovered and assists in mitigating those in a timely manner.

48
New cards

Operational Technology

combination of software and hardware designed to detect or cause changes through direct monitoring/controlling of physical devices

49
New cards

Assets

components of OT are called

50
New cards

Zones and Conduits

used to isolate networks and assets to impose and maintain strong access control mechanisms

51
New cards

Industrial Network and Business Network

a collection of automated control systems

52
New cards

Industrial Protocols

used for serial communication and can also be used for communication over standard Ethernet using IP, along with transport layer protocols TCP or UDP

53
New cards

Network Perimeter/Electronic Security Perimeter

it is the outermost boundary of a network zone/a closed group of assets.

54
New cards

Network Perimeter/Electronic Security Perimeter

acts as point of separation between the interior and exterior of a zone.

55
New cards

Electronic Security Permiter

boundery between secure and insecure zones

56
New cards

Network Perimeter

where does cybersecurity controls are implemented?

57
New cards

Critical Infastructure

collection of physical and logical systems and assets

58
New cards

The Purdue Model

describes the internal connections and dependencies of important components in ICS networks

59
New cards

The Purdue Model

also known as Industrial Automation and Control System Reference Model

60
New cards

Enterprise Zone (IT Systems)

supply-chain management and scheduling are perforfmed using business systems such as SAP and ERP

61
New cards

Level 5 (Enterprise Network)

a corporate level network where business operations such as B2B and B2C services are performed

62
New cards

Level 5 (Enterprise Network)

Internet connecitivity and management can be handled in this level

63
New cards

Level 4 (Business Logistics Systems)

All the IT systems supporting the production process in the plant lie at this level

64
New cards

Manufacturing Zone (OT Systems)

All the devices, networks, control, and monitoring systems reside in this zone

65
New cards

Level 3 (Operational Systems/Site Operations)

In this level, production management, individual plant monitoring, and control functions are defined. Production workflows and output of the desired product are ensured at this level.

66
New cards


Level 2 (Control Systems/Area Supervisory Control)

Supervising, monitoring, and controlling the physical process is carried out at this level.

67
New cards


Level 1 (Basic Controls/Intelligent Devices

Analysis and alteration of the physical process can be done at this level. The operations in basic control include “start motors,” “open valves,” “move actuators,” etc.

68
New cards


Level 0 (Physical Process)

In this level, the actual physical process is defined, and the product is manufactured. Higher levels control and monitor operations at this level; therefore, this layer is also referred to as Equipment Under Control (EUC). A minor error in any of the devices at this level can affect overall operations.

69
New cards

Industrial Demilitarized Zone (IDMZ)

The demilitarized zone is a barrier between the manufacturing zone (OT systems) and the enterprise zone (IT systems) that enables a secure network connection between the two system

70
New cards

Industrial Demilitarized Zone (IDMZ)

The zone is created to inspect

the overall architecture. If any errors or intrusions compromise the working systems, the IDMZ holds the error and allows production to continue without interruption.

71
New cards

Maintenance and Administrative Threat

Attackers exploit zero-day vulnerabilities to target the maintenance and administration of the OT network.

72
New cards

Data Leakage

Attackers may exploit IT systems connected to the OT network to gain access to the IT/OT gateway and steal operationally significant data such as configuration files.

73
New cards

Protocol Abuse

many OT systems use outdated legacy protocols and interfaces such as Modbus and CAN bus

74
New cards

Potential Destruction of ICS Resources

Attackers exploit vulnerabilities in OT systems to disrupt or degrade the functionality of the OT infrastructure, leading to life- and safety-critical issues.


75
New cards

Reconnaissance Attacks

OT systems allow remote communication with minimal or no encryption or authentication mechanism

76
New cards

Denial-of-Service Attacks

Attackers exploit communication protocols such as Common Industrial Protocol (CIP) to perform DoS attacks on the target OT systems.


77
New cards

HMI-Based Attacks

often called Hacker–Machine Interface.human interaction and control over the operational process remain challenges due to underlying vulnerabilities.

78
New cards

Exploiting Enterprise-Specific Systems and Tools

inject malware by exploiting underlying protocols to detect hardware and systems used in communications, and further disrupt or damage their services.

79
New cards

Spear Phishing

Attackers send fake emails containing malicious links or attachments, seemingly originating from legitimate or well-known sources, to the victim.

80
New cards

Malware Attacks

Attackers are reusing legacy malware packages that were previously used to exploit IT systems to exploit OT system

81
New cards

Exploiting Unpatched Vulnerabilities

these vendors cannot develop patches for the identified vulnerabilities at the same speed as IT vendor


82
New cards

Side-Channel Attacks

to retrieve critical information from an OT system by observing its physical implementation


83
New cards

Buffer Overflow Attack

inject malicious data and commands to modify the normal behavior and operation of the systems.

84
New cards

Exploiting RF Remote Controller

lack built-in security for remote communication

85
New cards

ICS Exploitation Framework (ISF)

is an exploitation framework based on Python that is similar to the Metasploit framework. This tool provides various exploit modules that allow attackers to hack target ICS systems and networks.