Kastersky-2018上半年工业自动化系统威胁报告(英文)-2018.9-30页-1mb
报告摘要
Summary of the Threat Landscape for Industrial Automation Systems (H1 2018)
Core Content
This report provides an overview of the threat landscape for industrial automation systems (ICS) during the first half of 2018, highlighting key vulnerabilities, malware incidents, and cybersecurity trends. It is based on the findings of Kaspersky Lab's Industrial Control Systems Cyber Emergency Response Team (ICS CERT) and emphasizes the growing risks to critical infrastructure and industrial networks.
Main Events and Trends
1. Spectre and Meltdown Vulnerabilities
- Discovered in early 2018, these vulnerabilities affected Intel, ARM64, and AMD processors.
- They allowed unauthorized access to virtual memory content, with Meltdown enabling kernel memory access.
- Impact: Affecting ICS computers, SCADA servers, and network devices globally.
- Vulnerable Products: Cisco, PHOENIX CONTACT, Yokogawa, Siemens, Schneider Electric, ABB, and OSisoft.
2. Energetic Bear/Crouching Yeti APT Group
- APT group targeting energy and industrial sectors, with a focus on Europe, the US, and Turkey.
- Attack Methods: Phishing emails, watering hole attacks, and exploitation of vulnerable servers.
- Tools Used: Publicly available open-source tools hosted on GitHub.
- Link to Russian Government: According to US-CERT and UK National Cyber Security Centre.
3. Cryptominers in Industrial Networks
- A rise in cryptocurrency mining malware targeting ICS systems.
- Examples: Wastewater treatment plant, Tesla's cloud servers.
- Impact: Increased load on industrial systems, potentially affecting operational stability.
- Statistics: The percentage of ICS computers attacked by cryptominers increased by 6%–4.2% in the first half of 2018 compared to the previous six months.
4. Large-scale Attacks on Cisco Switches
- Exploited the CVE-2018-0171 vulnerability in Cisco Smart Install Client.
- Targeted Countries: Russia and Iran.
- Impact: Disrupted internet providers, data centers, and websites.
5. VPNFilter Malware
- Affects 500,000+ routers and NAS devices in 54 countries.
- Functions: Network traffic collection, Modbus protocol monitoring, and Tor-based communication.
- Risks: Stealing credentials, detecting SCADA equipment, and participating in botnets.
6. Attack on Satellite Systems
- Originated from computers in China, targeting telecom operators, a satellite communications operator, and defense contractors in the US and Southeast Asia.
- Malware Detected: Rikamanu, Syndicasec, Catchamas, Mycicil, and Spedear.
- Tools Used: PsExec, Mimikatz, WinSCP, and LogMeln to conceal activity.
7. Triton Malware
- Specifically targets Triconex SIS systems from Schneider Electric.
- Method: Reverse-engineered TriStation 1131 software to communicate with Triconex systems.
- Impact: Caused a malfunction in an emergency protection system in December 2017.
8. IoT Botnet Activity
- Rise in botnets composed of IoT devices, including Hide 'N Seek (HNS) and Mirai variants.
- Targets: IP cameras, routers, and other smart devices.
- Risks: DDoS attacks on critical services, such as financial institutions.
9. Ransomware Attacks
- Despite a global decrease in ransomware incidents, the percentage of ICS computers affected increased.
- Example: Attack on a Russian medical institution, disrupting emergency brain surgery.
- Impact: Financial loss, data leaks, and operational disruption.
10. RAT-Based Attacks
- Phishing Emails: Containing malicious attachments that install RATs like TeamViewer and RMS.
- Malware Chain: RATs used to download additional malware, including Necus botnet agents and ransomware.
- Implications: Increased risk of unauthorized access and data theft.
Threat Statistics
- Percentage of ICS Computers Attacked: Increased by 3.5 percentage points in H1 2018 compared to H2 2017, reaching 41.2%.
- Geographical Distribution:
- Top 20 Countries: Highlighting higher attack percentages in certain regions.
- Lowest 10 Countries: Mostly advanced economies with high per capita GDP.
- Correlation: A strong positive correlation between per capita GDP and the percentage of ICS computers attacked (R = 0.84, P < 0.001).
Main Sources of Infection
- Internet: The primary source of infection, affecting 27.3% of ICS computers in H1 2018.
- Removable Media: Second most common source, with stable infection rates.
- Email Clients: Third most common source, with phishing and malicious attachments being a significant threat.
- Other Sources: Contributions less than 1%, remaining consistent with previous periods.
Recommendations
- Security Awareness: Industrial enterprises must increase awareness of cybersecurity threats.
- Regular Updates: Ensure all systems and software are up to date to mitigate known vulnerabilities.
- Network Segmentation: Implement strict network segmentation to isolate ICS systems from potential threats.
- Monitoring and Detection: Use advanced monitoring tools to detect and respond to suspicious activity.
- Training and Phishing Prevention: Educate employees on the risks of phishing and the importance of secure practices.
- Investment in Cybersecurity: Allocate more resources to protect ICS infrastructure, especially in developing countries.
Conclusion
The threat landscape for industrial automation systems in H1 2018 was marked by a significant increase in cyberattacks, driven by new vulnerabilities, sophisticated malware, and the growing use of IoT devices in botnets. The report highlights the importance of robust cybersecurity measures, especially in regions with lower per capita GDP, where ICS systems are more vulnerable.
试读结束,高清完整版pdf/doc/ppt,请点下载