课题基金 / 基金详情

Moving Target Cyber Defence for Operational Technology

Moving Target Cyber Defence for Operational Technology
运营技术的移动目标网络防御
批准号:
2746196
负责人:
金额:
$0.0万
依托单位:
依托单位国家:
英国
项目类别:
Studentship
财政年份:
2022
资助国家:
英国
项目状态:
未结题
起止时间:
2022 至 --

项目摘要

项目成果

相似基金

相关文献

中文摘要
翻译
迄今为止,在公共领域看到的针对操作技术(OT)的攻击(例如Stuxnet、Triton、CrashOverride、乌克兰的BlackEnergy)表明,攻击者需要特定的OT环境知识才能成功攻击。如果信息不准确或攻击程序错误(如Triton),攻击就会变得脆弱,往往会失败。因此,一个关键问题是,我们能否增加OT攻击的脆弱性,并提高OT系统的弹性?正如在ICS网络杀伤链中建模的那样,攻击者在收集必要的信息以开发OT有效载荷并执行成功的攻击上花费了大量的早期努力和活动。如果此信息发生变化,则必须重复此信息收集过程,并更新恶意软件有效载荷。因此,如果目标系统以“常规”时间间隔进行更改,那么攻击者收集的任何信息都将具有与之相关的有用性过期时间。如果目标系统的变化足够频繁,那么这实际上可能是一个“永无止境”的活动循环,或者至少会给攻击者施加压力,迫使他们迅速采取行动。这种做法的最终结果至少可以实现两个结果;使目标攻击不那么有效,挫败攻击者足以阻止他们针对特定的OT系统。当然,要达到平衡,在不影响系统业务需求的情况下,OT系统可以改变多少?是否存在这样一个点,即这些更改过于频繁,从而对系统的可靠性/弹性产生负面影响?因此,需要对这种缓解方法进行研究,以确定可行性、可扩展性和最佳方法,以最小的运营影响实现防御效益。主要目标**************目前的技术水平是什么?之前对移动目标防御的研究结果是什么?2. 确定哪些标准是“可移动的”,即OT系统的哪些方面是可以改变的,一旦知道哪些方面在干扰OT系统中的攻击方面提供了最佳的“回报”,同时也最大限度地减少了对OT系统的操作影响。3. 可以在OT系统中实施的机制将其付诸实践。4. 了解实现这一目标的其他挑战,例如安全、不情愿、培训等。预期交付成果*********************感谢博士们这是一个不断变化的目标,但给一个期望的想法;1. 根据目前的“技术状况”,概述如何在技术上实现这一目标。2. 一个概念证明,展示了这在实际的OT系统中是如何潜在地工作的(注意,这可能是简化的,泰雷兹将提供一个“真实”的系统进行测试)。3. 关于如何克服这种威胁缓解的潜在障碍的建议。
英文摘要
Those targeted Operation Technology (OT) attacks seen in the public domain to date (e.g. Stuxnet, Triton, CrashOverride, BlackEnergy in Ukraine) demonstrate that attackers require specific OT environment knowledge for their attacks to succeed. Where information is either inaccurate or the attacks mi-programmed (e.g. as with Triton) the attacks become fragile and often fail. Therefore a key question is could we increase the fragility of OT attacks and improve the resiliency of the OT system? As modelled in the ICS Cyber Kill Chain, an attacker spends a lot of their early effort and activities on gathering the necessary information to develop OT payloads and execute a successful attack. If this information changes then this information gathering process must repeat and the malware payloads updated. Therefore if the target system is changed at "regular" time intervals, then any information gathered by an attacker would have an expiration time on usefulness associated with it. If the target system changes frequently enough, this effectively could be a "never ending" loop of activity, or at the very least put pressure on the attacker to act very quickly. The net result of this approach could achieve at least two outcomes; render targeted attacks less effective, frustrate the attackers sufficiently to deter them from targeted that specific OT system. There is of course a balance to be struck, how much can an OT system be changed without impacting the business requirement of that system? Is there a point at which these changes are too frequent and the reliability / resilience of the system is negatively impacted? Therefore, this mitigation approach needs to be investigated to determine the viability, scalability and optimum approach to achieve the defensive benefits with the minimum amount of operational impact.Key Objectives ************** 1. What is the state of the art and what are the results of previous research into moving target defence generally and then also more specifically in the OT sector? 2. Identify what criteria is "moveable" i.e. what are the aspects of an OT system that can be changed, and once known which offer the best "return" in terms of interfering with attacks in an OT system, whilst also minimizing operational impact on the OT system. 3. The mechanisms that could be implemented within OT systems that put this into practice. 4. Understand the other challenges to making this a reality e.g. safety, reluctance, training, etc.. Expected Deliverables ********************* Appreciate with PhDs this is a moving target but to give an idea of expectation; 1. An overview of how this could be achieved technically based on the current "state of art". 2. A proof of concept showing how this could potentially work, practically, in a real OT system (note this is likely to be simplified, Thales will provide a 'real' system to test with). 3. Recommendations on how the potential blockers to such a threat mitigation might be overcome.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
国内基金
海外基金
应用Target-Seq技术对肉牛生长性状显著关联基因组区域进行精细定位