Evolution of ICS Attacks and the Prospects for Future Disruptive Events

Evolution of ICS Attacks and the Prospects for Future Disruptive Events
复制标题

ICS 攻击的演变以及未来破坏性事件的前景

DOI:
--
复制
发表时间:
2019
期刊:
影响因子:
--
通讯作者:
J. Slowik
J. Slowik
中科院分区:
--
文献类型:
--
作者:
J. Slowik

文献摘要

被引文献

相似文献

头条新闻充斥着关于工业控制系统(ICS)攻击和对关键基础设施威胁的最新声明。但在每个重大事件的背后都有一个趋势,从2015年乌克兰停电到2017年沙特阿拉伯石油和天然气设施安全系统遭到攻击。在媒体报道之外,ICS攻击的演变过程中出现了两种清晰的模式:首先,初始攻击媒介越来越多地避免使用恶意软件和技术,这些技术是高级对手活动的迹象;其次,只有在入侵的最后阶段,才会引入复杂的恶意软件来编纂ics特定知识,使几乎任何计算机网络操作操作员都能够执行复杂的命令。对这些趋势的探索和研究揭示了未来攻击将如何在ICS领域发生的明确方向,因为攻击者在部署越来越先进的能力的同时,寻求满足逃避检测的看似相互排斥的目标。通过采用和理解针对ICS攻击方法的“完整杀伤链”方法,防御者(从ICS资产所有者和运营商到国家政府到政府间组织)可以开始制定防御计划,以检测和减轻未来的攻击。为了描述和捍卫这篇论文,将详细分析过去四年的ICS破坏性事件,以确定这些威胁是如何随着时间的推移而演变的,以及需要采取哪些补充措施来击败这些攻击。全面了解ICS攻击所带来的风险,将使ICS运营商和政策制定者的利益相关者能够开始识别和实施适当的控制和安全措施,以保护关键基础设施,防止未来潜在的灾难性攻击。
Headlines are full of proclamations covering the latest in industrial control system (ICS) attacks and threats to critical infrastructure. But behind each prominent event lies a trendline from the 2015 Ukraine power outage through the 2017 attack on safety systems at an oil and gas facility in Saudi Arabia. When moving beyond media reporting, two clear patterns emerge in how ICS attacks have evolved: first, initial attack vectors increasingly avoid using malware and techniques that are tell-tale signs of advanced adversary activity; second, only at the final, ICS-disruptive stages of intrusions is complex malware introduced to codify ICS-specific knowledge to enable nearly any computer network operations operator to execute complex commands. Exploration and examination of these trends reveals a definite direction in how future attacks will occur within the ICS space, as adversaries seek to satisfy the seemingly mutually-exclusive goals of evading detection while deploying increasingly advanced capabilities. By adopting and understanding a “complete kill-chain” approach to ICS attack methods, defenders – from ICS asset owners and operators to national governments to intergovernmental organizations – can begin formulating defensive plans to detect and mitigate future attacks. To describe and defend this thesis, ICS disruptive events from the past four years will be analysed in detail to identify how these threats have evolved over time, and what complementary measures are necessary to defeat these attacks. A thorough understanding of the risk posed by ICS attacks will allow stakeholders from ICS operators to policymakers to begin identifying and implementing appropriate controls and security measures to safeguard critical infrastructure and prevent future, potentially catastrophic attacks.