-
CSE543 - Introduction to Computer and Network Security Page
CSE543 Computer and Network Security Module: Malware
Professor Trent Jaeger
1
1
CSE543 Computer and Network Security Module: Malware Professor - - PowerPoint PPT Presentation
CSE543 - Introduction to Computer and Network Security Page
1
1
CMPSC443 - Introduction to Computer and Network Security Page
2
2
CMPSC443 - Introduction to Computer and Network Security Page
3
3
CMPSC443 - Introduction to Computer and Network Security Page
4
4
CMPSC443 - Introduction to Computer and Network Security Page
5
5
CMPSC443 - Introduction to Computer and Network Security Page
6
6
CMPSC443 - Introduction to Computer and Network Security Page
7
7
CMPSC443 - Introduction to Computer and Network Security Page
8
8
CMPSC443 - Introduction to Computer and Network Security Page
9
9
CMPSC443 - Introduction to Computer and Network Security Page
10
10
CMPSC443 - Introduction to Computer and Network Security Page
11
11
CMPSC443 - Introduction to Computer and Network Security Page
500,000,000 1,000,000,000 1,500,000,000 2,000,000,000 2,500,000,000 3,000,000,000 3,500,000,000 4,000,000,000 4,500,000,000 5,000,000,000
12
12
CMPSC443 - Introduction to Computer and Network Security Page
13
13
CMPSC443 - Introduction to Computer and Network Security Page
dormant 28-31st)
14
14
CMPSC443 - Introduction to Computer and Network Security Page
15
15
CMPSC443 - Introduction to Computer and Network Security Page
16
500,000,000 1,000,000,000 1,500,000,000 2,000,000,000 2,500,000,000 3,000,000,000 3,500,000,000 4,000,000,000 4,500,000,000 5,000,000,00016
CMPSC443 - Introduction to Computer and Network Security Page
Operating System
Shield
Network Traffic
17
17
CMPSC443 - Introduction to Computer and Network Security Page
18
18
CMPSC443 - Introduction to Computer and Network Security Page
19
19
CMPSC443 - Introduction to Computer and Network Security Page
20
20
CMPSC443 - Introduction to Computer and Network Security Page
21
21
CMPSC443 - Introduction to Computer and Network Security Page
22
22
CMPSC443 - Introduction to Computer and Network Security Page
23
GlavMed SpamIt RX-Promotion Product Orders Revenue Orders Revenue Orders Revenue ED and Related 580K (73%) $55M (75%) 670K (79%) $70M (82%) 58K (72%) $5.3M (51%) Viagra 300K (38%) $28M (38%) 290K (34%) $31M (36%) 33K (41%) $2.7M (27%) Cialis 180K (23%) $19M (26%) 190K (22%) $23M (27%) 18K (22%) $1.9M (19%) Combo Packs 49K (6.1%) $3.9M (5.4%) 110K (14%) $8.4M (9.8%) 5100 (6.4%) $350K (3.4%) Levitra 32K (4.1%) $3.2M (4.4%) 35K (4.2%) $3.9M (4.5%) 1200 (1.5%) $150K (1.5%) Abuse Potential 48K (6.1%) $4.5M (6.1%) 64K (7.6%) $6.2M (7.3%) 11K (14%) $3.3M (32%) Painkillers 29K (3.7%) $2.4M (3.3%) 53K (6.3%) $4.7M (5.5%) 10K (13%) $3.0M (29%) Opiates — — — — 8000 (10%) $2.7M (26%) Soma/Ultram/Tramadol 20K (2.5%) $1.8M (2.4%) 46K (5.5%) $4.1M (4.8%) 1000 (1.3%) $150K (1.5%) Chronic Conditions 120K (15%) $9.5M (13%) 64K (7.6%) $5.2M (6.1%) 8500 (11%) $1.3M (13%) Mental Health 23K (2.9%) $2.1M (2.9%) 16K (1.9%) $1.4M (1.7%) 6000 (7.4%) $1.1M (11%) Antibiotics 25K (3.2%) $2.1M (2.9%) 16K (1.9%) $1.4M (1.6%) 1300 (1.6%) $97K (0.9%) Heart and Related 12K (1.5%) $770K (1.1%) 9700 (1.2%) $630K (0.7%) 390 (0.5%) $35K (0.3%) Uncategorized 48K (6.0%) $4.0M (5.5%) 47K (5.6%) $3.9M (4.6%) 2400 (3.0%) $430K (4.2%) Table 2: Product popularity in each of the three programs. Product groupings and categories are in italics; individual brands are without italics. Opiates are a further subcategory of Painkillers, and include Oxycodone, Hydrocodone, Vicodin, and Percocet.
23
CMPSC443 - Introduction to Computer and Network Security Page
24
24
CMPSC443 - Introduction to Computer and Network Security Page
25
25
CMPSC443 - Introduction to Computer and Network Security Page
26
26
CMPSC443 - Introduction to Computer and Network Security Page
27
industrial(control(system.(
programmable(logic(motor(controllers(from(just( two(vendors:(Vacon((Finland)(and(Fararo(Paya( (Iran)(
to(1210Hz.(Makes(the(frequency(of(those( controllers(vary(from(1410Hz(to(2Hz(to(1064Hz.(
2
27
CMPSC443 - Introduction to Computer and Network Security Page
28
– Does'not'have'signed'drivers'
– With'a'valid'cer>ficate'belonging'to'Realtek'Semiconductors'
– Verisign'revokes'Realtek'cer>ficate'
driver'
– 'With'a'valid'cer>ficate'belonging'to'JMicron'Technology'Corp'
SCADA'systems'
– Verisign'revokes'JMicron'cer>ficate'
28
CMPSC443 - Introduction to Computer and Network Security Page
29
– Each(PLC(is(configured(in(a(unique(manner( – Targeted(ICS’s(schemaCcs(needed( – Design(docs(stolen(by(an(insider?( – Retrieved(by(an(early(version(of(Stuxnet( – Stuxnet(developed(with(the(goal(of(sabotaging(a(specific(set(of(ICS.(
– Mirrored(development(Environment(needed(
– EsCmaCon((
29
CMPSC443 - Introduction to Computer and Network Security Page
30
– Two&digital&cer=ficates&were&compromised.& – High&probability&that&the&digital&cer=ficates/keys&were&stolen& from&the&companies&premises.& – Realtek&and&JMicron&are&in&close&proximity.&
– Stuxnet&needed&to&be&introduced&to&the&targeted&environment&
– Delivery&method&&
30
CMPSC443 - Introduction to Computer and Network Security Page
31
– Look&for&Windows&computer&that&program&the& PLC’s&
– ZeroHday&vulnerabili2es& – TwoHyear&old&vulnerability& – Spread&to&all&available&USB&drives&
– When&a&USB&drive&is&connected&to&the&Field&PG,& the&Infec2on&jumps&to&the&Field&PG&&
31
CMPSC443 - Introduction to Computer and Network Security Page
32
– Look&for&Specific&PLC&&
– Change&PLC&code&
– Command&and&Control&may¬&be&possible&
32
CMPSC443 - Introduction to Computer and Network Security Page
33
33