The FireEye OT-CSIO: An Ontology to Understand, Cross-Compare, and
Assess Operational Technology Cyber Security IncidentsThe FireEye Operational Technology Cyber Security Incident Ontology (OT-CSIO)
While the number of href="https://www.fireeye.com/solutions/industrial-systems-and-critical-infrastructure-security.html">threats
to operational technology (OT) have significantly increased
since the discovery of Stuxnet – driven by factors such as the growing
convergence with information technology (IT) networks and the
increasing availability of OT information, technology, software, and
reference materials – we have observed only a small number of
real-world OT-focused attacks. The limited sample size of
well-documented OT attacks and lack of analysis from a macro level
perspective represents a challenge for defenders and security leaders
trying to make informed security decisions and risk assessments.
To help address this problem, href="https://www.fireeye.com/solutions/cyber-threat-intelligence.html">FireEye
Intelligence developed the OT Cyber Security Incident Ontology
(OT-CSIO) to aid with communication with executives, and provide
guidance for assessing risks. We highlight that the OT-CSIO focuses on
high-level analysis and is not meant to provide in-depth insights into
the nuances of each incident.
Our methodology evaluates four categories, which are targeting,
impact, sophistication, and affected equipment architecture based on
the Purdue Model (Table 7). Unlike other methodologies, such as
MITRE's ATT&CK Matrix,
FireEye Intelligence's OT-CSIO evaluates only the full aggregated
attack lifecycle and the ultimate impacts. It does not describe the
tactics, techniques, and procedures (TTPs) implemented at each step of
the incident. Table 1 describes the four categories. Detailed
information about each class is provided in Appendix 1.
src="https://www.fireeye.com/content/dam/fireeye-www/blog/images/otontology/Picture1.jpg" alt="" />
Table 1: Categories for FireEye Intelligence's OT-CSIO
The OT-CSIO In Action
In Table 2 we list nine real-world incidents impacting OT systems
categorized according to our ontology. We highlight that the ontology
only reflects the ultimate impact of an incident, and it does not
account for every step throughout the attack lifecycle. As a note, we
cite public sources where possible, but reporting on some incidents is
available to FireEye Threat Intelligence customers only.
Incident | Target | Sophistication | Impact | Impacted Equipment |
href="http://web.mit.edu/smadnick/www/wp/2017-09.pdf">Maroochy Shire Sewage Spill (2000) | | width="125">ICS-targeted
| width="125">Medium
| width="125">Disruption
Zone 3 |
href="https://www.langner.com/wp-content/uploads/2017/03/to-kill-a-centrifuge.pdf">Stuxnet
(2011) | ICS-targeted |
High | | width="125">Destruction
Zones 1-2 |
href="https://www.theregister.co.uk/2012/08/29/saudi_aramco_malware_attack_analysis/">Shamoon
(2012) | ICS-targeted |
Low | | width="125">Destruction
| width="125">Zone 4-5
href="https://www.fireeye.com/blog/threat-research/2016/01/ukraine-and-sandworm-team.html">Ukraine Power Outage (2015) | | width="125">ICS-targeted
| width="125">Medium
Disruption, Destruction | Zone 2 |
href="https://www.welivesecurity.com/2017/06/12/industroyer-biggest-threat-industrial-control-systems-since-stuxnet/">Ukraine Power Outage (2016) | | width="125">ICS-targeted
| width="125">High
Disruption | Zones 0-3 |
WannaCry Infection on HMIs (2017) | | width="125">Non-targeted
Low | Disruption | | width="125">Zone 2-3
href="https://www.us-cert.gov/ncas/alerts/TA18-074A">TEMP.Isotope Reconnaissance Campaign (2017) | | width="125">ICS-targeted
Low | Data Theft | | width="125">Zones 2-4
href="https://www.fireeye.com/blog/threat-research/2017/12/attackers-deploy-new-ics-attack-framework-triton.html">TRITON Attack (2017) | | width="125">ICS-targeted
| width="125">High
Disruption (likely building destructive capability) | | width="125">Zone Safety, 1-5
href="https://www.helpnetsecurity.com/2018/02/08/crypto-mining-malware-hits-scada-network/">Cryptomining Malware on European Water Utility (2018) | Non-targeted | | width="125">Low
Degradation | Zone 2/3 |
Financially Motivated Threat Actor Accesses HMI While Searching for POS Systems (2019) | | width="125">Non-targeted
Low | Compromise | | width="125">Zone 2/3
Portable Executable File Infecting Malware Impacting Windows-based OT assets (2019) | | width="125">Non-targeted
Low | Degradation | | width="125">Zone 2-3
Table 2: Categorized samples using the OT-CSIO
The OT-CSIO Matrix Facilitates Risk Management and Analysis
Risk management for OT cyber security is currently a big challenge
given the difficulty of assessing and communicating the implications
of high-impact, low-frequency events. Additionally, href="https://pdfs.semanticscholar.org/eaed/881c3fc7be8cedd853e031d1d83cd29a07be.pdf">multiple
risk assessment methodologies rely on background information to
determine case scenarios. However, the quality of this type of
analysis depends on the background information that is applied to
develop the models or identify attack vectors. Taking this into
consideration, the following matrix provides a baseline of incidents
that can be used to learn about past cases and facilitate strategic
analysis about future case scenarios for attacks that remain unseen,
but feasible.
src="https://www.fireeye.com/content/dam/fireeye-www/blog/images/otontology/Picture3.jpg" alt="" />
Table 3: The FireEye OT-CSIO Matrix
As Table 3 illustrates, we have only identified examples for a
limited set of OT cyber security incident types. Additionally, some
cases are very unlikely to occur. For example, medium- and
high-sophistication non-targeted incidents remain unseen, even if
feasible. Similarly, medium- and high-sophistication data compromises
on OT may remain undetected. While this type of activity may be
common, data compromises are often just a component of the attack
lifecycle, rather than an end goal.
How to Use the OT-CSIO Matrix
The OT-CSIO Matrix presents multiple benefits for the assessment of
OT threats from a macro level perspective given that it categorizes
different types of incidents and invites further analysis on cases
that have not yet been documented but may still represent a risk to
organizations. We provide some examples on how to use this ontology:
- Classify different types of attacks and develop cross-case
analysis to identify differences and similarities. Knowledge about
past incidents can be helpful to prevent similar scenarios and to
think about threats that have not been evaluated by an
organization. - Leverage the FireEye OT-CSIO Matrix for
communication with executives by sharing a visual representation of
different types of threats, their sophistication and possible
impacts. This tool can make it easier to communicate risk despite
the limited data available for high-impact, low-frequency events.
The ontology provides an alternative to assess risk for different
types of incidents based on the analysis of sophistication and
impact, where increased sophistication and impact generally equates
to higher risk. - Develop additional case scenarios to
foresee threats that have not been observed yet but may become
relevant in the future. Use this information as support while
working on risk assessments.
Outlook
FireEye Intelligence's OT-CSIO seeks to compile complex incidents
into practical diagrams that facilitate communication and analysis.
Categorizing these events is useful for visualizing the full threat
landscape, gaining knowledge about previously documented incidents,
and considering alternative scenarios that have not yet been seen in
the wild. Given that the field of OT cyber security is still
developing, and the number of well-documented incidents is still low,
categorization represents an opportunity to grasp tendencies and
ultimately identify href="https://www.fireeye.com/services/mandiant-industrial-control-system-gap-assessment.html">security gaps.
Appendix 1: OT-CSIO Class Definitions
Target
This category comprises cyber incidents that target industrial
control systems (ICS) and non-targeted incidents that collaterally or
coincidentally impact ICS, such as ransomware.
src="https://www.fireeye.com/content/dam/fireeye-www/blog/images/otontology/Picture4.jpg" alt="" />
Table 4: Target category
Sophistication
Sophistication refers to the technical and operational
sophistication of attacks. There are three levels of sophistication,
which are determined by the analyst based on the following criteria.
src="https://www.fireeye.com/content/dam/fireeye-www/blog/images/otontology/Picture5.jpg" alt="" />
Table 5: Sophistication category
Impact
The ontology reflects impact on the process or systems, not the
resulting environmental impacts. There are five classes in this
category, including data compromise, data theft, degradation,
disruption, and destruction.
src="https://www.fireeye.com/content/dam/fireeye-www/blog/images/otontology/Picture6.jpg" alt="" />
Table 6: Impact category
Impacted Equipment
This category is divided based on FireEye Intelligence's adaptation
of the Purdue Model. For the purpose of this ontology, we add an
additional zone for safety systems.
src="https://www.fireeye.com/content/dam/fireeye-www/blog/images/otontology/Picture7.jpg" alt="" />
Table 7: Impacted equipment
Source:
The FireEye OT-CSIO: An Ontology to Understand, Cross-Compare, and
Assess Operational Technology Cyber Security Incidents