Monday, March 8, 2021
  • Setup menu at Appearance » Menus and assign menu to Top Bar Navigation
Advertisement
  • AI Development
    • Artificial Intelligence
    • Machine Learning
    • Neural Networks
    • Learn to Code
  • Data
    • Blockchain
    • Big Data
    • Data Science
  • IT Security
    • Internet Privacy
    • Internet Security
  • Marketing
    • Digital Marketing
    • Marketing Technology
  • Technology Companies
  • Crypto News
No Result
View All Result
NikolaNews
  • AI Development
    • Artificial Intelligence
    • Machine Learning
    • Neural Networks
    • Learn to Code
  • Data
    • Blockchain
    • Big Data
    • Data Science
  • IT Security
    • Internet Privacy
    • Internet Security
  • Marketing
    • Digital Marketing
    • Marketing Technology
  • Technology Companies
  • Crypto News
No Result
View All Result
NikolaNews
No Result
View All Result
Home Internet Security

Security surprise: Four zero-days spotted in attacks on researchers’ fake networks

June 21, 2020
in Internet Security
Security surprise: Four zero-days spotted in attacks on researchers’ fake networks
586
SHARES
3.3k
VIEWS
Share on FacebookShare on Twitter

Four new zero-day attacks were discovered when hackers employed them against fake systems set up by researchers studying hacking attempts on industrial systems.

Industrial control systems (ICS) are used to manage a vast range of critical devices, anything from chemical processing through to power generation or even building automation – like fire-suppression systems.

You might also like

Maza Russian cybercriminal forum suffers data breach

Okta and Auth0: A $6.5 billion bet that identity will warrant its own cloud

CISA issues emergency directive to agencies: Deal with Microsoft Exchange zero-days now

Many of these use old communications systems that assume they are connected via dedicated, secure networks. But now many are using IP-based networks, including the internet, to communicate, creating potentially huge security problems. 

SEE: How to become a cybersecurity pro: A cheat sheet (TechRepublic)    

Bugs in these systems are rarely patched by vendors or users, and few of the industrial protocols use authentication or encryption, which means they will trust most commands sent to them, regardless of who sends them.

“Together, these factors result in a vulnerable industrial environment and create unique security challenges,” the researchers note.

To examine the security threats to industrial systems, the researchers used a network of 120 high-interaction honeypots – fake industrial infrastructure – in 22 countries to mimic programmable logic controllers and remote terminal units.

Over a period of 13 months, there were 80,000 interactions with the honeypots – mostly scans – and nine interactions that made malicious use of an industrial protocol.

While that might sound like a small number, four of the nine interactions also featured previously unknown attacks, or zero-days, one being the first use of a previously identified proof-of-concept attack in the wild. 

The attack types include denial-of-service and command-replay attacks. These vulnerabilities and associated exploits were disclosed to the device manufacturers.

“While the yield was small, the impact was high, as these were skilled, targeted exploits previously unknown to the ICS community,” the researchers said. The research was presented at a NATO-backed cybersecurity conference.

Mikael Vingaard, industrial security researcher at Industrial Defenica, and one of the authors of the study, said the dataset is the largest used – so far – in academic research, and that the number of zero days discovered was a reflection of how believable the honeypots were.

SEE: Google removes 106 Chrome extensions for collecting sensitive user data

Michael Dodson at the Department of Computer Science and Technology at the University of Cambridge, another of the authors, told ZDNet that if used against a real device rather than a honeypot, the denial-of-service attacks would have meant the devices would have either shut down completely during the attack or been unable to communicate over the network.

For the replay attacks, the sky is the limit, he said. “If you can replay commands to change state or write to registers, then you have full control over the device’s behaviour, and therefore over whatever part of the process it controls.”

However, it’s also a reflection of the generally dismal state of ICS security that one honeypot could turn up four zero-day attacks.

“There are so few people looking at ICS device security, the landscape is so heterogeneous, and the software is largely proprietary, so I don’t think it’s surprising that any attack you happen to observe might be ‘new’ to the community,” he said.

Credit: Zdnet

Previous Post

US H1B visa ban would affect needed AI job workers for banks

Next Post

Skymind passionate in making Malaysia 'AI Nation' - New Straits Times

Related Posts

Maza Russian cybercriminal forum suffers data breach
Internet Security

Maza Russian cybercriminal forum suffers data breach

March 7, 2021
Okta and Auth0: A $6.5 billion bet that identity will warrant its own cloud
Internet Security

Okta and Auth0: A $6.5 billion bet that identity will warrant its own cloud

March 7, 2021
CISA issues emergency directive to agencies: Deal with Microsoft Exchange zero-days now
Internet Security

CISA issues emergency directive to agencies: Deal with Microsoft Exchange zero-days now

March 7, 2021
Linux distributions: All the talent and hard work that goes into building a good one
Internet Security

Linux distributions: All the talent and hard work that goes into building a good one

March 7, 2021
Check to see if you’re vulnerable to Microsoft Exchange Server zero-days using this tool
Internet Security

Check to see if you’re vulnerable to Microsoft Exchange Server zero-days using this tool

March 7, 2021
Next Post
Skymind passionate in making Malaysia ‘AI Nation’ – New Straits Times

Skymind passionate in making Malaysia 'AI Nation' - New Straits Times

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

Plasticity in Deep Learning: Dynamic Adaptations for AI Self-Driving Cars

Plasticity in Deep Learning: Dynamic Adaptations for AI Self-Driving Cars

January 6, 2019
Microsoft, Google Use Artificial Intelligence to Fight Hackers

Microsoft, Google Use Artificial Intelligence to Fight Hackers

January 6, 2019

Categories

  • Artificial Intelligence
  • Big Data
  • Blockchain
  • Crypto News
  • Data Science
  • Digital Marketing
  • Internet Privacy
  • Internet Security
  • Learn to Code
  • Machine Learning
  • Marketing Technology
  • Neural Networks
  • Technology Companies

Don't miss it

Here’s an adorable factory game about machine learning and cats
Machine Learning

Here’s an adorable factory game about machine learning and cats

March 8, 2021
How Machine Learning Is Changing Influencer Marketing
Machine Learning

How Machine Learning Is Changing Influencer Marketing

March 8, 2021
Video Highlights: Deep Learning for Probabilistic Time Series Forecasting
Machine Learning

Video Highlights: Deep Learning for Probabilistic Time Series Forecasting

March 7, 2021
Machine Learning Market Expansion Projected to Gain an Uptick During 2021-2027
Machine Learning

Machine Learning Market Expansion Projected to Gain an Uptick During 2021-2027

March 7, 2021
Maza Russian cybercriminal forum suffers data breach
Internet Security

Maza Russian cybercriminal forum suffers data breach

March 7, 2021
Clinical presentation of COVID-19 – a model derived by a machine learning algorithm
Machine Learning

Clinical presentation of COVID-19 – a model derived by a machine learning algorithm

March 7, 2021
NikolaNews

NikolaNews.com is an online News Portal which aims to share news about blockchain, AI, Big Data, and Data Privacy and more!

What’s New Here?

  • Here’s an adorable factory game about machine learning and cats March 8, 2021
  • How Machine Learning Is Changing Influencer Marketing March 8, 2021
  • Video Highlights: Deep Learning for Probabilistic Time Series Forecasting March 7, 2021
  • Machine Learning Market Expansion Projected to Gain an Uptick During 2021-2027 March 7, 2021

Subscribe to get more!

© 2019 NikolaNews.com - Global Tech Updates

No Result
View All Result
  • AI Development
    • Artificial Intelligence
    • Machine Learning
    • Neural Networks
    • Learn to Code
  • Data
    • Blockchain
    • Big Data
    • Data Science
  • IT Security
    • Internet Privacy
    • Internet Security
  • Marketing
    • Digital Marketing
    • Marketing Technology
  • Technology Companies
  • Crypto News

© 2019 NikolaNews.com - Global Tech Updates