Adversaries may repetitively or successively change I/O point values to perform an action. Brute Force I/O may be achieved by changing either a range of I/O point values or a single point value repeatedly to manipulate a process function. The adversary's goal and the information they have about the target environment will influence which of the options they choose. In the case of brute forcing a range of point values, the adversary may be able to achieve an impact without targeting a specific point. In the case where a single point is targeted, the adversary may be able to generate instability on the process function associated with that particular point. Adversaries may use Brute Force I/O to cause failures within various industrial processes. These failures could be the result of wear on equipment or damage to downstream equipment.

Linked Issues

Issuelinks
Linktype Issue
is related to Techniques
is related to Intelligent Electronic Device (IED)
is related to Programmable Logic Controller (PLC)
is related to Distributed Control System (DCS) Controller
is related to Human-Machine Interface (HMI)
is related to Control Server
is related to Remote Terminal Unit (RTU)
is related to Safety Controller
is related to Programmable Automation Controller (PAC)
is blocked by Network Allowlists
is blocked by Network Segmentation
is blocked by Filter Network Traffic
is blocked by Software Process and Device Authentication
is blocked by Detection of Brute Force I/O
Impressum German English