Adversaries may cause a sustained or permanent loss of view where the ICS equipment will require local, hands-on operator intervention; for instance, a restart or manual operation. By causing a sustained reporting or visibility loss, the adversary can effectively hide the present state of operations. This loss of view can occur without affecting the physical processes themselves. [1] [2] [3]
ID | Name | Description |
---|---|---|
S1157 | Fuxnet |
Fuxnet impaired sensor communication to impacted devices resulting in a loss of view condition for overall system monitoring.[4] |
S0604 | Industroyer |
Industroyer's data wiper component removes the registry image path throughout the system and overwrites all files, rendering the system unusable. [5] |
S0607 | KillDisk |
KillDisk erases the master boot record (MBR) and system logs, leaving the system unusable. [6] |
S0372 | LockerGoga |
Some of Norsk Hydro's production systems were impacted by a LockerGoga infection. This resulted in a loss of view which forced the company to switch to manual operations. [7] [8] |
C0031 | Unitronics Defacement Campaign |
During the Unitronics Defacement Campaign, the CyberAv3ngers replaced the existing graphic on the Programmable Logic Controller (PLC) Human-Machine Interface (HMI) with their own, thereby preventing PLC owners and operators from viewing PLC information on the HMI.[9][10] |
ID | Mitigation | Description |
---|---|---|
M0953 | Data Backup |
Take and store data backups from end user systems and critical servers. Ensure backup and storage systems are hardened and kept separate from the corporate network to prevent compromise. Maintain and exercise incident response plans [11], including the management of gold-copy back-up images and configurations for key systems to enable quick recovery and response from adversarial activities that impact control, view, or availability. |
M0810 | Out-of-Band Communications Channel |
Provide operators with redundant, out-of-band communication to support monitoring and control of the operational processes, especially when recovering from a network outage [12]. Out-of-band communication should utilize diverse systems and technologies to minimize common failure modes and vulnerabilities within the communications infrastructure. For example, wireless networks (e.g., 3G, 4G) can be used to provide diverse and redundant delivery of data. |
M0811 | Redundancy of Service |
Hot-standbys in diverse locations can ensure continued operations if the primarily system are compromised or unavailable. At the network layer, protocols such as the Parallel Redundancy Protocol can be used to simultaneously use redundant and diverse communication over a local network. [13] |