• COVID-19
  • About Us
  • Contact Us
  • Events
  • Industries
  • Partners
  • Products & Services
  • Contribute
  • Webinars

Aerospace

  • Québec’s CloudOps Will Build Telesat LightSpeed’s Cloud Network
  • Myriota and Goanna Ag Team Up on IoT Agriculture Solutions
  • Fleet Picks Swissto12 to Deliver Additively Manufactured All-Metal Patch Antennas

Chemical

  • POWER magazine and Chemical Engineering magazine announce Eastman Chemical as the Host Chemical Process Industries (CPI) Sponsor for the 5th annual Connected Plant Conference
  • Evonik deepens partnership with IBM to accelerate AI implementation
  • Achieving Plant Efficiency – the Digital Way

Cybersecurity

  • House Passes Eight Bipartisan Cyber, Homeland Security Bills
  • Biden Administration Targets Electric Utilities For Cybersecurity Protections
  • White House Attributes SolarWinds Hack To Russian Agency

Healthcare

  • CISA Services In High Demand Related To COVID Vaccine Response
  • AI tool detects COVID-19 by listening to patients’ coughs
  • Printing Wearable Sensors Directly onto Skin

Oil & Gas

  • Globalstar Wins Asset Tracking Order from Brazilian Oil and Gas Company
  • Cybersecurity: Continuous Vigilance Required
  • Repsol and Microsoft renew partnership developing AI-powered digital solutions

Power

  • POWER magazine and Chemical Engineering magazine announce Eastman Chemical as the Host Chemical Process Industries (CPI) Sponsor for the 5th annual Connected Plant Conference
  • Self-Tuning Artificial Intelligence Improves Plant Efficiency and Flexibility
  • How to Put the Power Grid to Work to Prevent Wildfires

Transportation

  • Swarm CEO Sara Spangelo Sets Disruptive Pricing on New Satellite IoT Service
  • Trump Issues Cyber Security Plan For Maritime Transportation System
  • Sabic Launches New Compounds for Automotive Radar Sensors

Webinars

  • Anticipating the Unknowns: Accelerating Incident Response Without Losing Control
  • Industrial Endpoint Protection in Operational Technology
  • Known and Unknown: Putting a Stop to OT and IT Threats Before they Act

Sign up today for our free weekly e-letter

sign up
CONNECTING INNOVATIONS
WITH INSIGHT
SIGN UP
LOG IN
  • Aerospace
    Québec's CloudOps Will Build Telesat LightSpeed's Cloud Network
    Read story View all articles
  • Chemical
    POWER magazine and Chemical Engineering magazine announce Eastman Chemical as the Host Chemical Process Industries (CPI) Sponsor for the 5th annual Connected Plant Conference
    Read story View all articles
  • Cybersecurity
    House Passes Eight Bipartisan Cyber, Homeland Security Bills
    Read story View all articles
  • Healthcare
    CISA Services In High Demand Related To COVID Vaccine Response
    Read story View all articles
  • Oil & Gas
    Globalstar Wins Asset Tracking Order from Brazilian Oil and Gas Company
    Read story View all articles
  • Power
    POWER magazine and Chemical Engineering magazine announce Eastman Chemical as the Host Chemical Process Industries (CPI) Sponsor for the 5th annual Connected Plant Conference
    Read story View all articles
  • Transportation
    Swarm CEO Sara Spangelo Sets Disruptive Pricing on New Satellite IoT Service
    Read story View all articles
Cybersecurity Power
March 12 2020 3:12 pm

ICS ATT&CK: Designed to Help Protect from Cyber Attacks

T

Travis Smith

Earlier this year, MITRE–a not-for-profit organization that works in the public interest across federal, state, and local governments, as well as with industry and academia–officially released the long-awaited industrial control systems (ICS) version of its popular ATT&CK knowledge base. ICS ATT&CK is the group's response to the unique attack surface that industrial networks are trying to defend. Over the years there have been multiple public examples of attacks targeted specifically toward industrial environments. Stuxnet, Industroyer, and BlackEnergy are some of the more widely known pieces of malware found to be targeting these systems.

Many of the attacks that have been made public in the past relied on some type of bridge between information technology (IT) and operational technology (OT) systems. For example, Stuxnet executed on Windows operating systems before targeting industrial systems. Because of this, it is important to realize that ICS ATT&CK should be viewed as complementary information to Enterprise ATT&CK. The larger Enterprise ATT&CK knowledge base remains valuable as another layer of defense against the entire ecosystem protecting industrial systems.

Within ICS ATT&CK, the matrix is broken out into multiple tactics, such as Execution and Impair Process Control, with various techniques listed. Some of these tactic and technique names are shared with the Enterprise world. For example, Execution can be found in both Enterprise ATT&CK and ICS ATT&CK. However, other tactics, such as Impair Process Control, are unique to the ICS world.

There are also techniques that can be found across both versions of ATT&CK, for example, Valid Accounts. Even though the names are shared, and the overall theme of the technique is the same, there are specific examples or mitigations unique to industrial systems.

Some of the new elements within the techniques are Assets and Levels. Assets are the hardware and software that are unique to industrial systems. Instead of Platforms, such as Windows, ICS includes Engineering Workstations, Data Historians, and Human-Machine Interfaces.

Levels are mapped to the Purdue Enterprise Reference Architecture. Level 3 and above are specific to what is expected in typical IT environments. These are the levels that are heavily covered in Enterprise ATT&CK. Level 2 and below are specific to industrial systems and range from engineering workstations down to low-level relays controlling physical equipment. Similar to the Platforms information, Assets and Levels can help scope ICS ATT&CK to systems that users are attempting to analyze.

What made Enterprise ATT&CK so popular years ago, and what makes ICS ATT&CK so great today, is accessibility. All of the information the knowledge bases contain was already largely available online, but it was spread across vendor blogs or in recorded presentations from security conferences. Having all of this information collated into a single website reduces the cost of entry for anyone trying to break into ICS security.

As attacks focused on industrial systems increase, understanding the scope of the problem is the first step. ICS ATT&CK is that first step into creating a more secure industrial world. As a first release, it is still in its infancy. MITRE does an excellent job at curating the ATT&CK knowledge bases across Pre, Mobile, and Enterprise, but it needs help. Tripwire has contributed to these tools in the past. In fact, these knowledge bases aren't possible without the contributions from those within the industry.

All ICS users and administrators play a role in defending industrial environments. If something is observed to be missing or incorrect in the knowledge base, anyone should feel empowered to contact MITRE and let its team know. The shared experiences are a net gain for everyone trying to defend against some of the more well-funded adversaries on the internet.

–Travis Smith is a principal security researcher at Tripwire. He has more than 10 years of experience in security, holds a Master of Business Administration degree with a concentration in information security, and multiple certifications including CISSP, GIAC, and GPEN. He specializes in integrating various technologies and processes, with a passion for forensics and security analytics, and a goal of helping customers identify and mitigate real threats.

Sign up today for our free weekly e-letter

sign up

Aerospace

Chemical

Cybersecurity

Healthcare

Oil & Gas

Power

Quiz

Transportation

Webinars

About Us

IIoT Connection delivers the latest news, trends, insights, events and research surrounding the dynamic and disruptive Industrial Internet of Things (IIoT) marketplace. Brought to you by the publisher of must-read publications Defense Daily, OR Manager, POWER and Chemical Engineering, as well as the conference producers of SATELLITE, Global Connected Aircraft Summit, Connected Plant Conference and ELECTRIC POWER, IIoT Connection is committed to providing the most comprehensive compilation of products and services dedicated to the Industrial Internet of Things. Key verticals with associated products and services include: aerospace, chemical, cybersecurity, healthcare, oil & gas, power, and transportation.


Advertise

  • Privacy Policy
© 2021 Access Intelligence, LLC - All Rights Reserved.
  • × UPS Partners with Wingcopter to Develop, Certify Drone Delivery Fleet
    Read story View all articles
  • × How Industrial Managers Can Identify and Prevent Failures in Facilities
    Read story View all articles
  • × Federal Agencies Partner To Improve Cyber Security Cooperation In Energy Sector
    Read story View all articles
  • × New service lines can create opportunities for ORs
    Read story View all articles
  • × Equinor and Shell to collaborate on digital solutions
    Read story View all articles
  • × Dobroflot to Manage Fuel Savings With IOT Solution By Orange Business Services
    Read story View all articles
  • × The Future of 5G & IoT Technologies in the Transportation Industry
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles