Adversaries may spoof reporting messages in control system environments for evasion and to impair process control. In control systems, reporting messages contain telemetry data (e.g., I/O values) pertaining to the current state of equipment and the industrial process. Reporting messages are important for monitoring the normal operation of a system or identifying important events such as deviations from expected values. If an adversary has the ability to Spoof Reporting Messages, they can impact the control system in many ways. The adversary can Spoof Reporting Messages that state that the process is operating normally, as a form of evasion. The adversary could also Spoof Reporting Messages to make the defenders and operators think that other errors are occurring in order to distract them from the actual source of a problem.(Citation: Bonnie Zhu, Anthony Joseph, Shankar Sastry 2011)

Linked Issues

Issuelinks
Linktyp Issue
is related to Techniques
is related to Control Server
is related to Safety Controller
is related to Human-Machine Interface (HMI)
is related to Data Gateway
is related to Programmable Automation Controller (PAC)
is related to Intelligent Electronic Device (IED)
is related to Remote Terminal Unit (RTU)
is related to Programmable Logic Controller (PLC)
is related to Distributed Control System (DCS) Controller
is blocked by Network Allowlists
is blocked by Network Segmentation
is blocked by Filter Network Traffic
is blocked by Detection of Spoof Reporting Message
is blocked by Software Process and Device Authentication
is blocked by Communication Authenticity
Impressum Deutsch Englisch