Security-X

Forum Security-X => News => Discussion démarrée par: igor51 le octobre 09, 2019, 11:00:26

Titre: [FireEye]The FireEye OT-CSIO: An Ontology to Understand, Cross-Compare, and Assess Operational Technology Cyber Security Incidents
Posté par: igor51 le octobre 09, 2019, 11:00:26
The FireEye OT-CSIO: An Ontology to Understand, Cross-Compare, and
Assess Operational Technology Cyber Security Incidents


The FireEye Operational Technology Cyber Security Incident Ontology (OT-CSIO)


 

While the number of     href="https://www.fireeye.com/solutions/industrial-systems-and-critical-infrastructure-security.html">threats
    to operational technology (OT) have significantly increased
  since the discovery of Stuxnet – driven by factors such as the growing
  convergence with information technology (IT) networks and the
  increasing availability of OT information, technology, software, and
  reference materials – we have observed only a small number of
  real-world OT-focused attacks. The limited sample size of
  well-documented OT attacks and lack of analysis from a macro level
  perspective represents a challenge for defenders and security leaders
  trying to make informed security decisions and risk assessments.


 

To help address this problem,     href="https://www.fireeye.com/solutions/cyber-threat-intelligence.html">FireEye
  Intelligence developed the OT Cyber Security Incident Ontology
  (OT-CSIO) to aid with communication with executives, and provide
  guidance for assessing risks. We highlight that the OT-CSIO focuses on
  high-level analysis and is not meant to provide in-depth insights into
  the nuances of each incident.


 

Our methodology evaluates four categories, which are targeting,
  impact, sophistication, and affected equipment architecture based on
  the Purdue Model (Table 7). Unlike other methodologies, such as
  MITRE's ATT&CK Matrix,
  FireEye Intelligence's OT-CSIO evaluates only the full aggregated
  attack lifecycle and the ultimate impacts. It does not describe the
  tactics, techniques, and procedures (TTPs) implemented at each step of
  the incident. Table 1 describes the four categories. Detailed
  information about each class is provided in Appendix 1.


 


      src="https://www.fireeye.com/content/dam/fireeye-www/blog/images/otontology/Picture1.jpg" alt="" />
 
   
 Table 1: Categories for FireEye Intelligence's OT-CSIO


 

The OT-CSIO In Action


 

In Table 2 we list nine real-world incidents impacting OT systems
  categorized according to our ontology. We highlight that the ontology
  only reflects the ultimate impact of an incident, and it does not
  account for every step throughout the attack lifecycle. As a note, we
  cite public sources where possible, but reporting on some incidents is
  available to FireEye Threat Intelligence customers only.


 
   
     
   
              width="125">

ICS-targeted

        width="125">

Medium

        width="125">

Disruption


   
     
                width="125">

Destruction


   
     
                width="125">

Destruction

          width="125">

Zone 4-5


   
              width="125">

ICS-targeted

        width="125">

Medium


   
              width="125">

ICS-targeted

        width="125">

High


   
              width="125">

Non-targeted

          width="125">

Zone 2-3


   
              width="125">

ICS-targeted

          width="125">

Zones 2-4


   
              width="125">

ICS-targeted

        width="125">

High

          width="125">

Zone Safety, 1-5


   
              width="125">

Low


   
              width="125">

Non-targeted

          width="125">

Zone 2/3


   
              width="125">

Non-targeted

          width="125">

Zone 2-3


          Incident


          Target


          Sophistication


          Impact


          Impacted Equipment


                      href="http://web.mit.edu/smadnick/www/wp/2017-09.pdf">Maroochy
            Shire Sewage Spill

(2000)

Zone
        3


                  href="https://www.langner.com/wp-content/uploads/2017/03/to-kill-a-centrifuge.pdf">Stuxnet


       

(2011)

ICS-targeted

High

Zones
        1-2


                  href="https://www.theregister.co.uk/2012/08/29/saudi_aramco_malware_attack_analysis/">Shamoon


       

(2012)

ICS-targeted

Low


                      href="https://www.fireeye.com/blog/threat-research/2016/01/ukraine-and-sandworm-team.html">Ukraine
            Power Outage

(2015)

Disruption,
        Destruction

Zone 2


                      href="https://www.welivesecurity.com/2017/06/12/industroyer-biggest-threat-industrial-control-systems-since-stuxnet/">Ukraine
            Power Outage

(2016)

Disruption


     

Zones 0-3


          WannaCry Infection
            on HMIs

(2017)

Low


     

Disruption


                      href="https://www.us-cert.gov/ncas/alerts/TA18-074A">TEMP.Isotope
            Reconnaissance Campaign

(2017)

Low


     

Data Theft


                      href="https://www.fireeye.com/blog/threat-research/2017/12/attackers-deploy-new-ics-attack-framework-triton.html">TRITON
        Attack

(2017)

Disruption
          (likely building destructive capability)


                      href="https://www.helpnetsecurity.com/2018/02/08/crypto-mining-malware-hits-scada-network/">Cryptomining
            Malware on European Water Utility

(2018)


     

Non-targeted

Degradation


     

Zone 2/3

Financially Motivated Threat Actor Accesses HMI
          While Searching for POS Systems

(2019)

Low


     

Compromise

Portable Executable File Infecting Malware
          Impacting Windows-based OT assets

(2019)

Low


     

Degradation


 


  Table 2: Categorized samples using the OT-CSIO


 

The OT-CSIO Matrix Facilitates Risk Management and Analysis


 

Risk management for OT cyber security is currently a big challenge
  given the difficulty of assessing and communicating the implications
  of high-impact, low-frequency events. Additionally,   href="https://pdfs.semanticscholar.org/eaed/881c3fc7be8cedd853e031d1d83cd29a07be.pdf">multiple
  risk assessment methodologies rely on background information to
  determine case scenarios. However, the quality of this type of
  analysis depends on the background information that is applied to
  develop the models or identify attack vectors. Taking this into
  consideration, the following matrix provides a baseline of incidents
  that can be used to learn about past cases and facilitate strategic
  analysis about future case scenarios for attacks that remain unseen,
  but feasible.


 


      src="https://www.fireeye.com/content/dam/fireeye-www/blog/images/otontology/Picture3.jpg" alt="" />
 
 Table 3: The FireEye OT-CSIO Matrix


 

As Table 3 illustrates, we have only identified examples for a
  limited set of OT cyber security incident types. Additionally, some
  cases are very unlikely to occur. For example, medium- and
  high-sophistication non-targeted incidents remain unseen, even if
  feasible. Similarly, medium- and high-sophistication data compromises
  on OT may remain undetected. While this type of activity may be
  common, data compromises are often just a component of the attack
  lifecycle, rather than an end goal.


 

How to Use the OT-CSIO Matrix


 

The OT-CSIO Matrix presents multiple benefits for the assessment of
  OT threats from a macro level perspective given that it categorizes
  different types of incidents and invites further analysis on cases
  that have not yet been documented but may still represent a risk to
  organizations. We provide some examples on how to use this ontology:


 
 

Outlook


 

FireEye Intelligence's OT-CSIO seeks to compile complex incidents
  into practical diagrams that facilitate communication and analysis.
  Categorizing these events is useful for visualizing the full threat
  landscape, gaining knowledge about previously documented incidents,
  and considering alternative scenarios that have not yet been seen in
  the wild. Given that the field of OT cyber security is still
  developing, and the number of well-documented incidents is still low,
  categorization represents an opportunity to grasp tendencies and
  ultimately identify     href="https://www.fireeye.com/services/mandiant-industrial-control-system-gap-assessment.html">security gaps.


 

Appendix 1: OT-CSIO Class Definitions


 


  Target


 

This category comprises cyber incidents that target industrial
  control systems (ICS) and non-targeted incidents that collaterally or
  coincidentally impact ICS, such as ransomware.


 


      src="https://www.fireeye.com/content/dam/fireeye-www/blog/images/otontology/Picture4.jpg" alt="" />
 
 Table 4: Target category


 


  Sophistication


 

Sophistication refers to the technical and operational
  sophistication of attacks. There are three levels of sophistication,
  which are determined by the analyst based on the following criteria.


 


      src="https://www.fireeye.com/content/dam/fireeye-www/blog/images/otontology/Picture5.jpg" alt="" />
 
 Table 5: Sophistication category


 


  Impact


 

The ontology reflects impact on the process or systems, not the
  resulting environmental impacts. There are five classes in this
  category, including data compromise, data theft, degradation,
  disruption, and destruction.


 


      src="https://www.fireeye.com/content/dam/fireeye-www/blog/images/otontology/Picture6.jpg" alt="" />
 
 Table 6: Impact category


 


  Impacted Equipment


 

This category is divided based on FireEye Intelligence's adaptation
  of the Purdue Model. For the purpose of this ontology, we add an
  additional zone for safety systems.


 


      src="https://www.fireeye.com/content/dam/fireeye-www/blog/images/otontology/Picture7.jpg" alt="" />
 
 Table 7: Impacted equipment


Source: The FireEye OT-CSIO: An Ontology to Understand, Cross-Compare, and
Assess Operational Technology Cyber Security Incidents (http://)