LogicLocker

Programmable Logic Controller Rack
Allen Bradley Programmable Logic Controller

LogicLocker, is a cross-vendor ransomware worm that targets Programmable Logic Controllers (PLCs) used in Industrial Control Systems (ICS).[1] First described in a research paper released by the Georgia Institute of Technology,[2][1] the malware is capable of hijacking multiple PLCs from various popular vendors. The researchers, using a water treatment plant model, were able to demonstrate the ability to display false readings, shut valves and modify Chlorine release to poisonous levels using a Schneider Modicon M241, Schneider Modicon M221 and an Allen Bradley MicroLogix 1400 PLC. The ransomware is designed to bypass weak authentication mechanisms found in various PLCs and lock out legitimate users while planting a logicbomb into the PLC. As of 14 February 2017, it is noted that there are over 1,400 of the same PLCs used in the proof-of-concept attack that were accessible from the internet as found using Shodan.[3][4][5][2]

Attack method

The attack method used with LogicLocker employs five stages. Initial infection, Horizontal and Vertical movement, locking, encryption and negotiation. Initial infection can take place through various vulnerability exploits. As ICS devices are typically in an always on state, this gives Cyber-criminals ample time to attempt the compromise of the PLC. PLCs generally do not have strong authentication mechanisms in place to assist in protecting themselves from potential attack.[1] Initial infection could take place through a users clicking of a potentially malicious email attachment.[1][2] Upon initial infection of the PLC, horizontal or vertical movement can be achieved from the PLC to the corporate network depending on the capabilities of the PLC. The next stage of the attack is locking in which the attacker locks out legitimate users to inhibit or prevent restoration efforts. This can be done through password changes, OEM Locking, over-utilization of PLC resources or changing IP/Ports. These different locking methods offer varying degrees of success and strengths. To further ensure a successful attack Encryption is employed to follow traditional cryptoransomware practices for future negotiations. Lastly, negotiations are conducted between the attacker and victim for service restoration. Some PLCs contain an email capability that can be used to send the ransom message as was the case with the MicroLogix 1400 PLC used in the proof-of-concept attack.[1][4]

Defense strategies

To assist in defense and vulnerability mitigation efforts there are several strategies that can be employed.

Endpoint security

Endpoint security techniques such as password changes, disabling of unused ports and protocols and implementation of Access Control Lists (ACL), maintaining proper backups and firmware updates should be used. This can significantly reduce the attack surface presented cyber-criminals.[1]

Network security

Increased and vigilant network monitoring should be used to detect abnormalities. Protocol whitelisting on firewalls, network segmentation and automated backups can provide additional security and provide decreased restoration time provided the backups are not compromised in the attack.[1]

Policy

The training of employees to properly identify phishing emails, prohibition of USB devices and incorporating a comprehensive incident response plan should be used to assist in countering this threat.[1]

See also

References

  1. ^ a b c d e f g h Formby, D., Durbha, S., & Beyah, R. (n.d.). Out of Control : Ransomware for Industrial Control Systems. Retrieved from http://www.cap.gatech.edu/plcransomware.pdf
  2. ^ a b c "A Malware Experiment Foreshadows Factories Held for Ransom". 16 February 2017.
  3. ^ Chirgwin, Richard (15 February 2017). "Meet LogicLocker: Boffin-built SCADA ransomware". The Register. Retrieved 2017-02-20.
  4. ^ a b "Proof-of-concept ransomware locks up the PLCs that control power plants". Boing Boing. 2017-02-14. Retrieved 2017-02-20.
  5. ^ Khandelwal, Swati. "This Ransomware Malware Could Poison Your Water Supply If Not Paid". The Hacker News. Retrieved 2017-02-20.

Read other articles:

BousínMunicipality BenderaLambang kebesaranBousínKoordinat: 49°27′18″N 16°53′24″E / 49.45500°N 16.89000°E / 49.45500; 16.89000Koordinat: 49°27′18″N 16°53′24″E / 49.45500°N 16.89000°E / 49.45500; 16.89000Country CekoRegionOlomoucDistrictProstějovLuas • Total3,41 km2 (132 sq mi)Ketinggian611 m (2,005 ft)Populasi (2007) • Total122 • Kepadatan0,36/km2 (...

 

 

Peta daur hidup rilis peranti lunak Daur hidup rilis perangkat lunak (Inggris: software release life cyclecode: en is deprecated ) adalah jumlah fase perkembangan dari sebuah perangkat lunak mulai dari masa awal pembuatan hingga versi terakhir yang dirilis ke pengguna, dan meliputi versi terbarukan dari versi rilisnya untuk membantu meningkatkan kegunaan perangkat lunak atau memperbaiki bug yang masih ada dalam perangkat lunak terkini. Lihat pula Pemeliharaan perangkat lunak Pengujian perangk...

 

 

Artikel ini sebatang kara, artinya tidak ada artikel lain yang memiliki pranala balik ke halaman ini.Bantulah menambah pranala ke artikel ini dari artikel yang berhubungan atau coba peralatan pencari pranala.Tag ini diberikan pada Februari 2023. Simbol π terbalik, sering digunakan untuk merepresentasikan prima Belfegor.[1] Bilangan prima Belfegor (Inggris: Belphegor's primecode: en is deprecated ) adalah bilangan prima palindromik 1 000 000 000 000 066 6...

Caping gunung khas Jawa. Tradisi Gejog Lesung di masyarakat Yogyakarta dengan melantunkan langgam Caping Gunung Caping Gunung (Carakan: ꦕꦥꦶꦁ​​ꦒꦸꦤꦸꦁ​) adalah lagu langgam Jawa yang diciptakan oleh Gesang Martohartono. Lagu ini sangat populer oleh masyarakat Jawa, apalagi setelah dibawakan oleh Waljinah. Caping Gunung merupakan lagu daerah Daerah Istimewa Yogyakarta.[1] Lirik lagu Lirik asli (bahasa Jawa) Terjemahan bahasa Indonesia Dhek jaman berjuang Njur kelin...

 

 

Pour les articles homonymes, voir Arbogast. Luc Arbogast Luc Arbogast au Fensch Viking Fest à Florange le 30 septembre 2023Informations générales Naissance 2 novembre 1975 (48 ans)à La Rochelle Genre musical Musique d'inspiration médiévale, musique celtique Années actives Depuis 1996 Labels Universal MusicCP records Site officiel lucarbogast.fr modifier Luc Arbogast, né le 2 novembre 1975 à La Rochelle, est un musicien et chanteur français, qui s'inspire de la musique médiév...

 

 

Harashta Haifa ZahraHarashta pasca dinobatkan sebagai Puteri Indonesia 2024, Maret 2024LahirHarashta Haifa Zahra5 September 2003 (umur 20)Garut, Jawa Barat, IndonesiaPendidikanInstitut Teknologi Nasional Bandung (Teknik Lingkungan)AlmamaterSMA Negeri 2 BandungPekerjaanModelaktivis lingkunganpemegang gelar kontes kecantikanTinggi1,73 m (5 ft 8 in)Pemenang kontes kecantikanGelarPuteri Indonesia Jawa Barat 2024Puteri Indonesia 2024Warna rambutCokelat gelapWarna mataCokelat g...

Pour les articles homonymes, voir The X-Files et Aux frontières du réel. X-Files : Aux frontières du réel Logo original de la série. Données clés Titre original The X-Files Autres titresfrancophones Aux frontières du réel (saisons 1 et 2)The X-Files : Aux frontières du réel (saisons 2 à 9)Aux frontières du réel (version remastérisée des saisons 1 à 9)X-Files (saisons 10 et 11) Genre Policier, thriller, science-fiction, fantastique, horreur Acteurs principaux David ...

 

 

This article may require cleanup to meet Wikipedia's quality standards. The specific problem is: Replace redlinks with Template:Interlanguage links where possible. Please help improve this article if you can. (July 2023) (Learn how and when to remove this message) This is a chronological list of films produced in Korea while it was part of Japan as well as the united country of Korea before it officially became divided in September 1948. The first domestic Korean film was shown in 1919. The ...

 

 

This is a list of properties and districts listed on the National Register of Historic Places in Alaska. There are approximately 400 listed sites in Alaska. Each of the state's 30 boroughs and census areas has at least two listings on the National Register, except for the Kusilvak Census Area, which has none. Contents: Boroughs and census areas in AlaskaBorough names are highlighted in bold Aleutians East • Aleutians West • Anchorage • Bethel • Bristol Bay • Chugach • Copper Rive...

Politics of Kuwait Member State of the Arab League Constitution Monarchy Emir Mishal Al-Ahmad Al-Jaber Al-Sabah Crown Prince Vacant House of Sabah Government Prime Minister Ahmad Al-Abdullah Al-Sabah Cabinet No-Confidence Votes Judiciary Legal system of Kuwait Administration Governorates Areas Foreign relations Ministry of Foreign Affairs Minister: Salem Abdullah Al-Jaber Al-Sabah Diplomatic missions of / in Kuwait Nationality law Passport Visa requirements Visa policy Related topics Demogra...

 

 

Pour les articles homonymes, voir La Valette (homonymie), Valette, Lavalette et Valetta (homonymie). La Valette Il-Belt (mt)Valletta (en) Héraldique Drapeau De haut : la ligne d'horizon, la batterie de salutation , les jardins Lower Barrakka , la co-cathédrale Saint-Jean et les remparts de la ville Administration Pays Malte Île Malte Région Région Sud-Est District Port Sud Maire Mandat Alfred Zammit (PL) (2019-2024) Code postal VLT Démographie Gentilé Valettins (en maltais :...

 

 

Maguindanao del SurProvinsi Lambang   Lokasi Maguindanao del Sur di FilipinaOpenStreetMap NegaraFilipinaRegionBangsamoroDidirikan18 September 2022Ibu kotaBuluanPemerintahan • GubernurBai Mariam Sangki-Mangudadatu • Wakil GubernurDatu Nathaniel S. MidtimbangLuas[1] • Total4,973,48 km2 (1,920,27 sq mi)Populasi (Script error: The function "getQualifierDateValue" does not exist.)[2] • Total741,...

This article's lead section may be too short to adequately summarize the key points. Please consider expanding the lead to provide an accessible overview of all important aspects of the article. (December 2015) 7th episode of the 8th season of How I Met Your Mother The Stamp TrampHow I Met Your Mother episodeEpisode no.Season 8Episode 7Directed byPamela FrymanWritten byTami SagherOriginal air dateNovember 19, 2012 (2012-11-19)Guest appearances Joe Manganiello as Brad Joe ...

 

 

Disambiguazione – Giacobini rimanda qui. Se stai cercando altri significati, vedi Giacobini (disambigua). Disambiguazione – Se stai cercando il movimento politico britannico del XVII/XVIII secolo, vedi Giacobitismo. Stampa propagandista della Prima Repubblica Francese durante il periodo del governo giacobino con diversi simboli e il motto Unità e Indivisibilità della Repubblica. Libertà, Uguaglianza, Fratellanza o la Morte (FR) «Vivre libre ou mourir» (IT) «Vivere liberi o ...

 

 

Halaman ini berisi artikel tentang film. Untuk musikal, lihat Musikal Billy Elliot. Billy ElliotSutradaraStephen DaldryProduserGreg BrenmanJon FinnDitulis olehLee HallCeritaLee HallPemeranJamie BellJulie WaltersGary LewisJamie DravenPenata musikStephen WarbeckSinematograferBrian TufanoPenyuntingJohn WilsonPerusahaanproduksiBBC FilmsTiger Aspect PicturesStudioCanalWorking Title FilmsDistributorUniversal PicturesFocus FeaturesTanggal rilis 29 September 2000 (2000-09-29) Durasi110 men...

Electric vehicle charging standard developed by Tesla North American Charging System (SAE J3400) NACS alternating current (AC)/direct current (DC) connector (center), shown between SAE J1772 (left) and Type 2 (right) AC connectors. Non-NACS DC connectors are even larger.Type Electric vehicle chargingProduction historyDesigner Tesla, Inc.Designed 2021Standardized pendingManufacturer Tesla, VolexGeneral specificationsPins 5ElectricalMax. voltage 277 Volt (V) AC500 or 1,000 V DCMa...

 

 

1971 live album by Various artistsWoodstock TwoLive album by Various artistsReleasedMarch 1971 (1971-March)RecordedAugust 15–18, 1969VenueWoodstock Festival, Bethel, New YorkGenreRock, folkLength86:49[1]LabelCotillion in US, Atlantic in EuropeProducerEric BlacksteadWoodstock albums chronology Woodstock: Music from the Original Soundtrack and More(1970) Woodstock Two(1971) The Best of Woodstock(1994) Professional ratingsReview scoresSourceRatingAllMusic[2]Ch...

 

 

Dutch tennis player Seda NoorlanderSeda Noorlander, Z'voort 2001Country (sports) NetherlandsResidenceThe Hague, NetherlandsBorn (1974-05-22) 22 May 1974 (age 50)The HagueTurned pro1993Retired2006PlaysRight-handed (two-handed backhand)Prize money$623,689SinglesCareer record347–343Career titles0 WTA, 3 ITFHighest rankingNo. 80 (3 December 1999)Grand Slam singles resultsAustralian Open2R (1999)French Open1R (1999,2000,2002)Wimbledon3R (1999)US Open2...

College ice hockey team season 1906–07 Columbia men's ice hockey seasonConference5th IHAHome iceSt. Nicholas RinkRecordOverall0–5–0Conference0–4–0Home0–4–0Neutral0–1–0Coaches and captainsHead coachJ. C. CoolicanAssistant coachesRudolph Von BernuthCaptain(s)David ArmstrongColumbia men's ice hockey seasons« 1905–06 1907–08 » The 1906–07 Columbia men's ice hockey season was the 11th season of play for the program. Season Coolican served as coach while form...

 

 

  لمعانٍ أخرى، طالع سالامانكا (توضيح).   هذه المقالة عن مدينة سلمنكا (سلمنقة أو شلمنقة) الإسبانية. لمدينة سلمنكا المكسيكية، طالع سلمنكا (المكسيك). شلمنقة    علم شعار الاسم الرسمي (بالإسبانية: Salamanca)‏[1]    الإحداثيات 40°57′54″N 5°39′51″W / 40.965°N 5.66...