High Impact Malware Targeting Maritime Infrastructure
摘要
Malware, of varying degrees of sophistication, is a growing problem for any and all computing devices. With computing devices becoming more integrated into daily life across all sectors, malware has a more diverse cyberspace to affect. There is existent research examining the problem of malware from various perspectives: Personal Computers, smartphones, Internet of Things devices, etc. The majority of this research has, in the past, focused on Information Technology (IT) devices and IT issues. More recently, there is an emerging body of work with a focus on Operational Technology (OT), in various domains, such as power grids, communication infrastructure, and factories. Unlike IT, OT directly monitors and/or controls industrial equipment, assets, processes and events. There is a belief in some sub-communities that security research and solutions for OT are no different to those for IT. We postulate that this is not true, and that there are some sectors where the difference is more pronounced than others. In this paper, we present the construction of a relatively simple example of malware specifically designed to target cyber-physical vulnerabilities in maritime transport, to demonstrate how sector-specific information can be exploited to create an extremely high-impact incident.