Zero-Day Exploit: Countdown to Darkness : Countdown to Darkness
|
Description
|
There exists a 0-day vulnerability in a particular line of SCADA Master products that are widely used in petrochemical facilities. Furthermore, since the telemetry between the Master and the RTUs (the units located at valves, gauges, etc.) is particularly fragile under attack, the attackers are able to take a two-tiered approach to the damage they cause. The vulnerability is designed to simply replace a small bit of code in the SCADA Master so that upon communication with the RTUs, it will unpredictably send invalid data; the way in which the communications are invalid also varies somewhat. The symptoms of this appear not at the Master level, but in the RTUs themselves, which have unpredictable results. The first set of disasters occur as valves fail to close or open, or particular RTUs cease providing data. It takes a bit of time for law enforcement to have a solid handle on things, as they are currently battling their own issues, but they notice the pattern. The SCADA systems are immediately segmented from other networks, and work begins on replacing RTUs. This, however, has no effect, and as time passes the ripples of the attack spread. Gas stations run out of gas, followed shortly by freight carriers. Private individuals and local police and fire departments are not far behind. Disaster can only be prevented by Reuben, an elite cyber-security researcher who stumbles across the plot while contracting for the federal government. |
Other books on Computer Security
Applied Security Visualization Ethical Hacking Intrusion Detection Systems (Advances in Information Security) VizSEC 2007: Proceedings of the Workshop on Visualization for Computer Security (Mathematics and Visualization) Crimeware: Understanding New Attacks and Defenses (Symantec Press) Insider Attack and Cyber Security: Beyond the Hacker (Advances in Information Security) Computer Security, Privacy and Politics: Current Issues, Challenges and Solutions Secure Computer and Network Systems: Modeling, Analysis and Design No Tech Hacking: A Guide to Social Engineering, Dumpster Diving, and Shoulder Surfing Netcat Power Tools Secrets Stolen, Fortunes Lost: Preventing Intellectual Property Theft and Economic Espionage in the 21st Century Hacking: The Art of Exploitation, 2nd Edition Smart Cards, Tokens, Security and Applications Digital Privacy: Theory, Technologies, and Practices Gray Hat Hacking, Second Edition
|
|