Skip to content

Availability

  • paramount and well-understood in the OT world
  • still can be problematic, e.g., integrity is part of availability

Description

Primitive (D)Dos attacks

  • (replace todo in the future)
  • (D)DoS attacks
  • potentially against control infrastructure
    • are there documented attacks against sensor? seems not feasible

Real-Time Communication Safety

  • real-time communication safety
  • 'timing-attacks'?
  • special protocols and hardware needed?
  • do we see this as part of availability?

Availability and Integrity

  • availability vs. integrity -- flooding with fake data
  • while this is not direct availability, if you cannot trust your data, the datasource become unavailable
  • might introduce a performance overhead (that would be neglectable in the IT world but can be problematic in old OT hardware)

Availability and Software Updates

  • think about software updates, quality assurance (crowdstrike incident)

Rationale

  • why did we include this item in the top 10?

Known Attacks/Examples

Potential Sources

How-To Test (have to discuss)

  • maybe add this to a separate section?

Mitigation/Countermeasures

Design and Implementation

  • mitigations for developers/builders

Operational

  • mitigations for integrators/builders

References

Standards

  • links to relevant standards

Background information

  • links to blogs, etc.

Tooling

  • for testing, etc.