• CERTIFICATE
    • Eminent VARs of India
    • Best OEM 2023
  • SYNDICATION
    • AMD
    • DELL TECHNOLOGIES
    • HITACHI
    • LOGMEIN
    • MICROSOFT
    • RIVERBED
    • STORAGECRAFT
    • THALES
  • EVENTS
  • GO DIGITAL
  • INFOGRAPHICS
  • PRESS
    • Press Release PR News Wire
    • Press Release Business Wire
    • GlobeNewsWire
  • SPECIAL
    • WHITE PAPER
    • TECHNOMANIA
    • SME
    • SMART CITY
    • SERVICES
    • EDITOR SPEAK
    • CSR INITIATIVES
    • CHANNEL GURU
    • CHANNEL CHIEF
    • CASE STUDY
  • TECHTREND
    • VAR PANCHAYAT
    • TELECOM
    • SOFTWARE
    • POWER
    • PERIPHERALS
    • NETWORKING
    • LTE
    • CHANNEL BUZZ
    • ASK AN EXPERT
  • SUBSCRIBE
  • Apps
  • Gaming
  • KDS
  • Security
  • Telecom
  • WFH
  • Subscriber to Newsletter
  • April Issue
  • Blogs
  • Vlogs
  • Faceoff AI
    

HOME
NEWS

Industrial IoT: Finding pre-existing threats inside Industrial Control Systems


By VARINDIA - 2021-02-15
Industrial IoT: Finding pre-existing threats inside Industrial Control Systems

David Masson, Director of Enterprise Security

 

Industrial IoT (IIoT) devices are a pressing concern for security teams. Companies invest large sums of money to keep cyber-criminals out of industrial systems, but what happens when the hacker is already inside? Gateways and legacy security tools generally sit at the border of an organization and are designed to stop external threats, but are less effective once the threat is already inside. During this period, cyber-criminals carry out further reconnaissance, tamper with PLC settings, and subtly disrupt the production process.

 

Darktrace recently detected a series of pre-existing infections in Industrial IoT (IIoT) devices at a manufacturing firm in the EMEA region. The organization already had Darktrace in place in one area of the environment, but after seeing how the AI could successfully detect zero-day vulnerabilities and threats, they expanded the deployment, allowing Darktrace to actively monitor and defend interactions among its 5,000 devices, and dramatically improving visibility.

 

An unknown emerging threat was identified by Darktrace’s Industrial Immune System on multiple machines within hours of Darktrace being active in the environment. By casting light on this previously unknown threat, Darktrace enabled the customer to perform full incident response and threat investigation, before the attacker was able to cause any serious damage to the company.

 

Though it is unclear how long the devices had been infected, it is likely to have been first introduced manually via an infected USB. The affected endpoints were being used as part of a continuous production process and could not be installed with endpoint protection.

 

The Industrial Immune System, however, easily detects infections across the digital estate, regardless of the type of environment or technology. Darktrace AI does not rely on signature-based methods but instead continuously updates its understanding of what constitutes ‘normal’ in an industrial environment. This self-learning approach allows the AI to contain zero-days that have never been seen before in the wild, as well as detecting the new appearance of pre-existing attacks.

 

Industrial IoT attacked

 

Only a few hours after Darktrace AI had begun defending the wider connections and interactions across the manufacturing firm, the Industrial Immune System detected a highly unusual network scan. A timeline of events, from first scan to full incident response results and conclusions, is shown below:

Figure 1: Timeline of incident response across 28 hours

Darktrace’s AI recognized that the device was exploiting an SMBv1 protocol in order to attempt lateral movement. In addition to anonymous SMBv1 authentication, Darktrace detected the device abusing default vendor credentials for device enumeration.

The device made a large number of unusual connections, including connections to internal endpoints which the company had previously been unaware of. As these occurred, the Threat Visualizer, Darktrace’s user interface, provided a graphical visualization of the incident, illuminating the unusual activity’s spread from the infected device across the infrastructure in question.

Figure 2: The Darktrace Threat Visualizer

Darktrace’s Immune System identified that the infected IIoT device was making an unusually large number of internal connections, suggesting an effort to perform reconnaissance.

Darktrace’s Cyber AI Analyst launched an immediate investigation into the alert, surfacing an incident summary at machine speed with all the information the security team needed to act.

Figure 3: An example of an AI Analyst Report on a network scan

The Cyber AI Analyst further identified two other devices behaving in a similar way, and these were removed from the network by the customer in response. When investigated by the security team, these devices were shown to be infected with the Yalove and Renocide worms, and the Autoit trojan-dropper. Open source intelligence suggests these infections are often spread via removable media such as USB drives.

Using Darktrace’s Advanced Search function, the customer was able to investigate related model breaches to build a list of similar indicators of compromise (IoCs), including failed external connections to www.whatismyip[.]com and DYNDNS IP addresses on HTTP port 80.

Recurring infections: How to deal with a persistent attack

In total, Darktrace was used to identify 13 infected production devices. The customer contacted the equipment owner, whose response confirmed that they had seen similar attacks on other networks in the past, including recurring infections.

Recurring infections imply one of two things: either, that the malware has a persistence mechanism, where it uses a range of techniques to remain undetected on the exploited machine and achieve persistent access to the system. Alternatively, a recurring infection could mean that the IoT manufacturer was not able to find all infected devices when they were first alerted to the compromise, and thus did not shut down the attack in its entirety.

As the infected machines are owned by a third party, they could not be immediately remediated. Darktrace AI, however, contained this threat with minimal business disruption. The customer was able to leave the infected devices active, which were still needed for production, confident that Darktrace would alert them if the infection spread or changed in behavior.

Industrial IoT: Shining a light on pre-existing threats

The mass adoption of IIoT devices has made industrial environments more complex and more vulnerable than ever. This blog demonstrates the prevalent threat that attackers are already on the inside, and the importance for security teams to expand visibility over their full industrial system. In this case, the customer was able to use Darktrace’s AI to illuminate a previous blind spot and contain a persistent attack, while minimizing disruption to operations. Crucially, this ‘unknown known’ threat was detected without any prior knowledge of the devices, their supplier, or patch history, and without using malware signatures or IoCs.

The customer was made aware of the infection via the Darktrace SOC service. Yet the same outcome could have been obtained with other workflows provided by Darktrace, such as email alerting, notifications through the Darktrace mobile app, seamlessly integrating Darktrace with a SIEM solution, or alerting via an internal SOC.

Cyber AI Analyst enabled the customer to perform immediate incident response. While waiting for a reinstallation date with the equipment owner, the customer could keep the production devices online, knowing Darktrace would be monitoring the outstanding risk. In an industrial setting, trade-offs like this are often necessary to sustain production. Darktrace helps organizations maintain the vigilance they need to do this securely, and when remediation does become possible, Darktrace can be used to reliably locate the full extent of the infection.

Thanks to Darktrace analyst Oakley Cox for his insights on the above threat find.

See What’s Next in Tech With the Fast Forward Newsletter

SECURITY
View All
Zscaler announces AI innovations to its Data Protection Platform
Technology

Zscaler announces AI innovations to its Data Protection Platform

by VARINDIA 2024-05-20
SHIELD to enhance Swiggy’s fraud prevention and detection capabilities
Technology

SHIELD to enhance Swiggy’s fraud prevention and detection capabilities

by VARINDIA 2024-05-20
Axis Communications announces its first thermometric camera designed for Zone/Division 2
Technology

Axis Communications announces its first thermometric camera designed for Zone/Division 2

by VARINDIA 2024-05-20
SOFTWARE
View All
Hitachi Vantara and Veeam announce Global Strategic Alliance
Technology

Hitachi Vantara and Veeam announce Global Strategic Alliance

by VARINDIA 2024-05-16
Adobe launches Acrobat AI Assistant for the Enterprise
Technology

Adobe launches Acrobat AI Assistant for the Enterprise

by VARINDIA 2024-05-11
Oracle Database 23ai offers the power of AI to Enterprise Data and Applications
Technology

Oracle Database 23ai offers the power of AI to Enterprise Data and Applications

by VARINDIA 2024-05-10
START - UP
View All
Data Subject Access Request is an integrated module within ID-REDACT®
Technology

Data Subject Access Request is an integrated module within ID-REDACT®

by VARINDIA 2024-04-30
SiMa.ai Secures $70M Funds from Maverick Capital
Technology

SiMa.ai Secures $70M Funds from Maverick Capital

by VARINDIA 2024-04-05
Sarvam AI collaborates with Microsoft to bring its Indic voice LLM to Azure
Technology

Sarvam AI collaborates with Microsoft to bring its Indic voice LLM to Azure

by VARINDIA 2024-02-08

Tweets From @varindiamag

Nothing to see here - yet

When they Tweet, their Tweets will show up here.

CIO - SPEAK
Automation has the potential to greatly improve efficiency and production

Automation has the potential to greatly improve efficiency and production

by VARINDIA
Various approaches are followed to enhance efficiency, productivity, and cost-effectiveness

Various approaches are followed to enhance efficiency, productivity, and cost-effectiveness

by VARINDIA
Technology can be leveraged in several ways to boost efficiency, productivity and reduce cost

Technology can be leveraged in several ways to boost efficiency, productivity and reduce cost

by VARINDIA
Start-Up and Unicorn Ecosystem
GoDaddy harnesses AI power for new domain name recommendations

GoDaddy harnesses AI power for new domain name recommendations

by VARINDIA
UAE’s du Telecom selects STL as a strategic fibre partner

UAE’s du Telecom selects STL as a strategic fibre partner

by VARINDIA
JLR and Dassault Systèmes extend partnership for All Vehicle Programs worldwide

JLR and Dassault Systèmes extend partnership for All Vehicle Programs worldwide

by VARINDIA
Rapyder partners with AWS to accelerate Generative AI led innovation

Rapyder partners with AWS to accelerate Generative AI led innovation

by VARINDIA
ManageEngine integrates its SIEM solution with Constella Intelligence

ManageEngine integrates its SIEM solution with Constella Intelligence

by VARINDIA
Elastic replaces traditional SIEM game with AI-driven security analytics

Elastic replaces traditional SIEM game with AI-driven security analytics

by VARINDIA
Infosys and ServiceNow to transform customer experiences with generative AI-powered solutions

Infosys and ServiceNow to transform customer experiences with generative AI-powered solutions

by VARINDIA
Crayon Software Experts India inaugurates its ISV Incubation Center in Kolkata

Crayon Software Experts India inaugurates its ISV Incubation Center in Kolkata

by VARINDIA
Dassault Systèmes to accelerate EV charging infrastructure development in India

Dassault Systèmes to accelerate EV charging infrastructure development in India

by VARINDIA
Tech Mahindra and Atento to deliver GenAI powered business transformation services

Tech Mahindra and Atento to deliver GenAI powered business transformation services

by VARINDIA
×

Reproduction in whole or in part in any form or medium without express written permission of Kalinga Digital Media Pvt. Ltd. is prohibited.

  • Distributors & VADs
  • Industry Associations
  • Telco's in India
  • Indian Global Leaders
  • Edit Calendar
  • About Us
  • Advertise Us
  • Contact Us
  • Disclaimer
  • Privacy Statement
  • Sitemap

Copyright varindia.com @1999-2024 - All rights reserved.