Notification mechanism for malware detected by Microsoft Defender for IoT in industrial networks

Marian Hristov, Maria Nenova, Zlatka Valkova-Jarvis, Viktoria Dimitrova · 2023

Nowadays, threats against industrial networks such as factories, plants, and laboratories are becoming more dangerous and carry severe consequences. Progressively, threat actors are targeting these industries, attempting to steal intellectual property and/or cause financial damage. Security vendors, such as Microsoft, constantly evolve their products in order to respond to emerging threats, however, in many cases the hackers are one step ahead. This paper aims to propose a notification mechanism for malware in industrial networks detected by Microsoft Defender for IoT (D4IoT). When applied, an analyst in a Cyber Threat Analytics Center (CTAC) can instantly detect malicious activity (e.g. outbound connection attempts toward a suspicious destination, or malformed Domain Name System (DNS) queries) and respond to it. Prompt responses and adequate measurements can save significant amounts of resources and, in some cases, even human lives. The proposed solution works on top of D4IoT implementation in an industrial network with Microsoft Sentinel integration.

Read the paper · More papers on PaperTik