A Review of An Emerging Cyber Kill Chain Threat Model
Lokman Mohd Fadzil, Selvakumar Manickam, Mahmood A. Al-Shareeda · 2023
This paper proposed a review of how Industrial Control Systems (ICS) have facilitated the evolution of today's legacy machines from purely mechanical fabrications to electrical, mechanical, hydraulic, and pneumatic, respectively. The increasing machine connectivity and digitalization are leading to an increase in cybersecurity issues affecting ICS as these systems are updated to conform to the new Industry 4.0, IoT, and cloud computing infrastructure to achieve specific industrial goals. For this case study, we explore the threat posed by Ransomware-as-a-Service (RAAS) and the business model propagated by the criminal organization DarkSide for using RAAS to launch a cyberattack against the ICS of the Colonial Oil and Gas Company. The current approach of implementing a response after a cyber-attack prompted shifting to in-progress response mechanisms as cyber-attacks become more complex and time-consuming. Based on prior work by Lockheed Martin and Varonis, a new and improved Cyber Kill Chain Framework is proposed. This framework details the eight steps of a cyberattack: surveillance, intrusion, exploitation, privilege escalation, lateral movement, obfuscation/anti-forensics, denial of service, and exfiltration. The Detect-Deny-Disrupt mitigation actions may need to be continuously updated to better the framework and ICS cyber-attack mitigation efforts.