Top Banner
© 2013 UNIVERSITY OF TEXAS ARLINGTON - DIVISION FOR ENTERPRISE DEVELOPMENT Protecting Public Works Infrastructure: Cyber Risk Rick McCreary Ashley Mathews
21

Protecting Public Works Infrastructure: Cyber Risk › Assets › uploads › docs › ...Cyber Emergency Response Team (ICS-CERT) • 200 cyber attacks October 2012 - May 2013 •

Jul 03, 2020

Download

Documents

dariahiddleston
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Protecting Public Works Infrastructure: Cyber Risk › Assets › uploads › docs › ...Cyber Emergency Response Team (ICS-CERT) • 200 cyber attacks October 2012 - May 2013 •

© 2013 UNIVERSITY OF TEXAS ARLINGTON - DIVISION FOR ENTERPRISE DEVELOPMENT

Protecting Public Works Infrastructure: Cyber Risk

Rick McCreary Ashley Mathews

Page 2: Protecting Public Works Infrastructure: Cyber Risk › Assets › uploads › docs › ...Cyber Emergency Response Team (ICS-CERT) • 200 cyber attacks October 2012 - May 2013 •

© 2013 UNIVERSITY OF TEXAS ARLINGTON - DIVISION FOR ENTERPRISE DEVELOPMENT

Technology Advances and Expansion

Page 3: Protecting Public Works Infrastructure: Cyber Risk › Assets › uploads › docs › ...Cyber Emergency Response Team (ICS-CERT) • 200 cyber attacks October 2012 - May 2013 •

© 2013 UNIVERSITY OF TEXAS ARLINGTON - DIVISION FOR ENTERPRISE DEVELOPMENT

Growing Dependence

• Technological advances create greater dependence – Mobile banking – Electronic payments

Page 4: Protecting Public Works Infrastructure: Cyber Risk › Assets › uploads › docs › ...Cyber Emergency Response Team (ICS-CERT) • 200 cyber attacks October 2012 - May 2013 •

© 2013 UNIVERSITY OF TEXAS ARLINGTON - DIVISION FOR ENTERPRISE DEVELOPMENT

$210 Million

Page 5: Protecting Public Works Infrastructure: Cyber Risk › Assets › uploads › docs › ...Cyber Emergency Response Team (ICS-CERT) • 200 cyber attacks October 2012 - May 2013 •

© 2013 UNIVERSITY OF TEXAS ARLINGTON - DIVISION FOR ENTERPRISE DEVELOPMENT

Cyber Risk & Infrastructure

• “Black Hat Researchers Remotely Hack Into SCADA Systems on Oil Rigs” – Demonstrated ability to send commands and

fake data, which could cause pipe to burst and a tank to overflow

Page 6: Protecting Public Works Infrastructure: Cyber Risk › Assets › uploads › docs › ...Cyber Emergency Response Team (ICS-CERT) • 200 cyber attacks October 2012 - May 2013 •

© 2013 UNIVERSITY OF TEXAS ARLINGTON - DIVISION FOR ENTERPRISE DEVELOPMENT

Multiple Attacks in 2013

• DHS has set up the Industrial Control Systems Cyber Emergency Response Team (ICS-CERT)

• 200 cyber attacks October 2012 - May 2013 • 53% targeted the energy sector • Manufacturing was second with 17% • These were the ones that were reported to

DHS!

Page 7: Protecting Public Works Infrastructure: Cyber Risk › Assets › uploads › docs › ...Cyber Emergency Response Team (ICS-CERT) • 200 cyber attacks October 2012 - May 2013 •

© 2013 UNIVERSITY OF TEXAS ARLINGTON - DIVISION FOR ENTERPRISE DEVELOPMENT

Evolving Threat Landscape

• Sophisticated means and methods • Global threat • Benefit from technology advancement

Page 8: Protecting Public Works Infrastructure: Cyber Risk › Assets › uploads › docs › ...Cyber Emergency Response Team (ICS-CERT) • 200 cyber attacks October 2012 - May 2013 •

© 2013 UNIVERSITY OF TEXAS ARLINGTON - DIVISION FOR ENTERPRISE DEVELOPMENT

Cyber Risk

Page 9: Protecting Public Works Infrastructure: Cyber Risk › Assets › uploads › docs › ...Cyber Emergency Response Team (ICS-CERT) • 200 cyber attacks October 2012 - May 2013 •

© 2013 UNIVERSITY OF TEXAS ARLINGTON - DIVISION FOR ENTERPRISE DEVELOPMENT

Critical Infrastructure

Page 10: Protecting Public Works Infrastructure: Cyber Risk › Assets › uploads › docs › ...Cyber Emergency Response Team (ICS-CERT) • 200 cyber attacks October 2012 - May 2013 •

© 2013 UNIVERSITY OF TEXAS ARLINGTON - DIVISION FOR ENTERPRISE DEVELOPMENT

Some Common Cyber Attacks

• Distributed Denial of Service (DDoS) • Phishing and Spear Phishing • Web Application Attacks • Advanced Persistent Threats

Page 11: Protecting Public Works Infrastructure: Cyber Risk › Assets › uploads › docs › ...Cyber Emergency Response Team (ICS-CERT) • 200 cyber attacks October 2012 - May 2013 •

© 2013 UNIVERSITY OF TEXAS ARLINGTON - DIVISION FOR ENTERPRISE DEVELOPMENT

Distributed Denial of Service (DDoS)

Page 12: Protecting Public Works Infrastructure: Cyber Risk › Assets › uploads › docs › ...Cyber Emergency Response Team (ICS-CERT) • 200 cyber attacks October 2012 - May 2013 •

© 2013 UNIVERSITY OF TEXAS ARLINGTON - DIVISION FOR ENTERPRISE DEVELOPMENT

DDOS Attacks on Financial Institutions

Page 13: Protecting Public Works Infrastructure: Cyber Risk › Assets › uploads › docs › ...Cyber Emergency Response Team (ICS-CERT) • 200 cyber attacks October 2012 - May 2013 •

© 2013 UNIVERSITY OF TEXAS ARLINGTON - DIVISION FOR ENTERPRISE DEVELOPMENT

Phishing

Goal is identity theft.

Phishing generally relies on nonspecific coercive

“carrot-and-stick” language to compel users into falling for attackers’

schemes.

Page 14: Protecting Public Works Infrastructure: Cyber Risk › Assets › uploads › docs › ...Cyber Emergency Response Team (ICS-CERT) • 200 cyber attacks October 2012 - May 2013 •

© 2013 UNIVERSITY OF TEXAS ARLINGTON - DIVISION FOR ENTERPRISE DEVELOPMENT

Real World Example - Spear Phishing

• Associated Press Twitter Account hacked

• Syrian Electronic Army took credit

• Widespread repercussions

Source: Allison, A. (2013, Apr 23). Hackers compromise ap twitter account, sends stocks plunging. Retrieved from http://www.wset.com/story/22054869/hackers-compromise-ap-twitter-account-sends-stocks-plunging

Page 15: Protecting Public Works Infrastructure: Cyber Risk › Assets › uploads › docs › ...Cyber Emergency Response Team (ICS-CERT) • 200 cyber attacks October 2012 - May 2013 •

© 2013 UNIVERSITY OF TEXAS ARLINGTON - DIVISION FOR ENTERPRISE DEVELOPMENT

Web Application Attacks

Allows ANY to connect to Web Server via HTTP/HTTPS

Transport layer HTTP/HTTPS over TCP/IP

Allow SQL

SQL query evaluates as ‘true’

SQL Database

Form field accepts user input no validation

Web Server Attacker

Attacker injects code into web form field

Firewalls

Entire Database contents returned with query

Database Server

Page 16: Protecting Public Works Infrastructure: Cyber Risk › Assets › uploads › docs › ...Cyber Emergency Response Team (ICS-CERT) • 200 cyber attacks October 2012 - May 2013 •

© 2013 UNIVERSITY OF TEXAS ARLINGTON - DIVISION FOR ENTERPRISE DEVELOPMENT

Advanced Persistent Threat (APT)

• Complex cyber-attacks against specific targets • Establish and extend access into network • Remain undetected • Undermine/impeded critical aspects

“0wN3d”

Page 17: Protecting Public Works Infrastructure: Cyber Risk › Assets › uploads › docs › ...Cyber Emergency Response Team (ICS-CERT) • 200 cyber attacks October 2012 - May 2013 •

© 2013 UNIVERSITY OF TEXAS ARLINGTON - DIVISION FOR ENTERPRISE DEVELOPMENT

APT Process

• Once workstation compromised – Remotely access network – Elevate privileges – Gain admin control – Compromise other systems through network – Retrieve targeted data – Erase their tracks

Page 18: Protecting Public Works Infrastructure: Cyber Risk › Assets › uploads › docs › ...Cyber Emergency Response Team (ICS-CERT) • 200 cyber attacks October 2012 - May 2013 •

© 2013 UNIVERSITY OF TEXAS ARLINGTON - DIVISION FOR ENTERPRISE DEVELOPMENT

• Financial • Reputational • Legal • Personal

Implications and Consequences

Who are the victims?

Page 19: Protecting Public Works Infrastructure: Cyber Risk › Assets › uploads › docs › ...Cyber Emergency Response Team (ICS-CERT) • 200 cyber attacks October 2012 - May 2013 •

© 2013 UNIVERSITY OF TEXAS ARLINGTON - DIVISION FOR ENTERPRISE DEVELOPMENT

Consequences

Page 20: Protecting Public Works Infrastructure: Cyber Risk › Assets › uploads › docs › ...Cyber Emergency Response Team (ICS-CERT) • 200 cyber attacks October 2012 - May 2013 •

© 2013 UNIVERSITY OF TEXAS ARLINGTON - DIVISION FOR ENTERPRISE DEVELOPMENT

Cyber Risk

Page 21: Protecting Public Works Infrastructure: Cyber Risk › Assets › uploads › docs › ...Cyber Emergency Response Team (ICS-CERT) • 200 cyber attacks October 2012 - May 2013 •

© 2013 UNIVERSITY OF TEXAS ARLINGTON - DIVISION FOR ENTERPRISE DEVELOPMENT

Questions