The Experts below are selected from a list of 12 Experts worldwide ranked by ideXlab platform
Morten Gjendemsjø - One of the best experts on this subject based on the ideXlab platform.
-
Creating a Weapon of Mass Disruption: Attacking Programmable Logic Controllers
2013Co-Authors: Morten GjendemsjøAbstract:A programmable logic controller (PLC) is a small industrial computer made to withstand the harsh environment it operates in. PLCs were designed for a closed, trusted network with little emphasis on security. Since their introduction, the automation world has changed, and the line between traditional IT and automation has slowly faded away. By integrating well known, low cost, technology such as commodity operating systems and TCP/IP into the automation realm, new threats are emerging. Security by obscurity was long deemed sufficient for industrial networks. If this was ever true, it is not anymore,especially when considering where PLCs are deployed; PLCs are part of virtually every industrial control system in the world and is at the heart of systems such as power production (including nuclear), pipelines, oil and gas refineries, water and waste, and weapon systems. A compromised system could mean financial loss, damage to equipment or in some cases, loss of life. This thesis looks at PLC security from an Attacker?s perspective. That is, given logical network access, what will an Attacker Attempt to accomplish and how will he or she proceed? In order to answer these questions, and more, this thesis discusses techniques and tools that can be used to compromise a PLC. Studying PLC security in detail, this thesis include both theoretical and practical aspects of security in PLCs. In-depth security tests are performed on a widely used PLC; uncovering several critical security vulnerabilities, including a new XML parser vulnerability accompanied by a zero day exploit allowing the adversary to perform a DoS attack that completely disables the PLC, including communication capabilities. Other exploits are also developed and their consequences run the gamut from arbitrary code execution, file read/write permissions, installing customized firmware, to manipulating actuators. The research culminates in a set of python scripts, an exploit suite, implementing all the exploits developed. This thesis shows that an adversary with network access can perform devastating attacks with relative ease. In the hands of the wrong people, the weaponized exploit suite, can cause tremendous damage. Shutting down, or altering, an industrial process will in many cases have severe financial and/or safety consequences.
Hidema Tanaka - One of the best experts on this subject based on the ideXlab platform.
-
leveraging man in the middle dos attack with internal tcp retransmissions in virtual network
International Conference on Information Systems Security, 2017Co-Authors: Son Duc Nguyen, Mamoru Mimura, Hidema TanakaAbstract:Denial of service (DoS) attacks recently pose great threat to cloud services since it can be able to cause serious damages to others virtual machines (VM) that are on the same physical server with the victim. This opens a new strategy of DoS attack, which is the Attacker Attempt to be co-resident with the victim server and execute a cross-VM DoS attack inside the cloud. Among DoS attack techniques, recent studies show that TCP retransmission can be abused for reflective amplification attacks. In a virtual environment, the virtual switch system itself can retransmit TCP packets and therefore it can be abused for amplification attack by an internal Attacker. In this paper, we leverage the attack by using both virtual switch’s internal TCP retransmission feature and Man-in-the-middle attack model.
M. Ganesh Karthik - One of the best experts on this subject based on the ideXlab platform.
-
Flooding attacks to internet threat monitors (ITM): Modeling and counter measures using botnet and honeypots
International Journal of Computer Science and Information Technology, 2011Co-Authors: K. Munivara Prasad, A. Rama Mohan Reddy, M. Ganesh KarthikAbstract:The Internet Threat Monitoring (ITM),is a globally scoped Internet monitoring system whose goal is to measure, detect, characterize, and track threats such as distribute denial of service(DDoS) attacks and worms. To block the monitoring system in the internet the Attackers are targeted the ITM system. In this paper we address flooding attack against ITM system in which the Attacker Attempt to exhaust the network and ITM's resources, such as network bandwidth, computing power, or operating system data structures by sending the malicious traffic. We propose an information-theoretic frame work that models the flooding attacks using Botnet on ITM. Based on this model we generalize the flooding attacks and propose an effective attack detection using Honeypots.
Son Duc Nguyen - One of the best experts on this subject based on the ideXlab platform.
-
leveraging man in the middle dos attack with internal tcp retransmissions in virtual network
International Conference on Information Systems Security, 2017Co-Authors: Son Duc Nguyen, Mamoru Mimura, Hidema TanakaAbstract:Denial of service (DoS) attacks recently pose great threat to cloud services since it can be able to cause serious damages to others virtual machines (VM) that are on the same physical server with the victim. This opens a new strategy of DoS attack, which is the Attacker Attempt to be co-resident with the victim server and execute a cross-VM DoS attack inside the cloud. Among DoS attack techniques, recent studies show that TCP retransmission can be abused for reflective amplification attacks. In a virtual environment, the virtual switch system itself can retransmit TCP packets and therefore it can be abused for amplification attack by an internal Attacker. In this paper, we leverage the attack by using both virtual switch’s internal TCP retransmission feature and Man-in-the-middle attack model.
K. Munivara Prasad - One of the best experts on this subject based on the ideXlab platform.
-
Flooding attacks to internet threat monitors (ITM): Modeling and counter measures using botnet and honeypots
International Journal of Computer Science and Information Technology, 2011Co-Authors: K. Munivara Prasad, A. Rama Mohan Reddy, M. Ganesh KarthikAbstract:The Internet Threat Monitoring (ITM),is a globally scoped Internet monitoring system whose goal is to measure, detect, characterize, and track threats such as distribute denial of service(DDoS) attacks and worms. To block the monitoring system in the internet the Attackers are targeted the ITM system. In this paper we address flooding attack against ITM system in which the Attacker Attempt to exhaust the network and ITM's resources, such as network bandwidth, computing power, or operating system data structures by sending the malicious traffic. We propose an information-theoretic frame work that models the flooding attacks using Botnet on ITM. Based on this model we generalize the flooding attacks and propose an effective attack detection using Honeypots.