Open Source Intelligence for Energy Sector Cyberattacks

Open Source Intelligence for Energy Sector Cyberattacks
复制标题

能源部门网络攻击的开源情报

DOI:
--
复制
发表时间:
2019
期刊:
Advanced Sciences and Technologies for Security Applications
影响因子:
--
通讯作者:
Michail Maniatakos
Michail Maniatakos
中科院分区:
--
文献类型:
--
作者:
A. Keliris;Charalambos Konstantinou;Marios Sazos;Michail Maniatakos

文献摘要

被引文献

相似文献

2018年3月,美国国土安全部和联邦调查局发布了俄罗斯威胁行为者正在进行的针对美国政府实体和关键基础设施部门的联合重大警报(TA18-074A)。该活动主要针对能源部门的关键基础设施组织,并使用开源情报(OSINT)等技术来提取信息。为了了解OSINT可以收集的信息的范围和质量,我们对威胁行为者进行了跟踪,并探索了可以生成与全球电力系统相关的情报的公开可用资源。我们对一个真实的大型电力系统进行了案例研究,利用OSINT资源构建电力系统模型,对其进行验证,并最终对其进行处理以确定其关键位置。我们的目标是证明利用公共资源进行详尽研究的可行性,并告知电力系统利益相关者评估向公众发布关键信息的风险。
In March 2018, the U.S. DHS and the FBI issued a joint critical alert (TA18-074A) of an ongoing campaign by Russian threat actors targeting U.S. government entities and critical infrastructure sectors. The campaign targets critical infrastructure organizations mainly in the energy sector and uses, among other techniques, Open Source Intelligence (OSINT) to extract information. In an effort to understand the extent and quality of information that can be collected with OSINT, we shadow the threat actors and explore publicly available resources that can generate intelligence pertinent to power systems worldwide. We undertake a case study of a real, large-scale power system, where we leverage OSINT resources to construct the power system model, validate it, and finally process it for identifying its critical locations. Our goal is to demonstrate the feasibility of conducting elaborate studies leveraging public resources, and inform power system stakeholders in assessing the risks of releasing critical information to the public.