Malware Ahead! (Fighting Cyberthreats on Board Ships)
摘要
In recent years there has been a worrying increase in cyber-attacks in the maritime domain. Due to their nature, special vulnerability and the range of possibilities they offer, the main element, ships, are prime targets of interest for the entire cyber threat ecosystem (from script-kiddies to Advanced Persistent Threats; from insignificant individual actors to powerful state actors) and for the entire spectrum of motivations (notoriety, hacktivism, terrorism, crime, espionage, cyberwarfare). All this in a context where multiple factors converge to aggravate the problem and make it difficult to solve, and where there is a serious lack of resources, very little awareness and excessive laxity in dealing with the problem. Given the great potential impact that a cyber-incident on board can have in this area, it is essential to adopt effective measures as soon as possible to reverse the situation described above. This paper deals with one of those possible solutions: on-board Security Operations Centers, which differ from traditional SOCs due to the peculiarities of ships.