Le Lézard
Classified in: Science and technology
Subject: SVY

Pervasive OT & IoT Network Anomalies Raise Red Flags as Threats to Critical Infrastructure Become More Sophisticated


Network anomalies and attacks are the most prevalent threat to OT and IoT environments, according to new research from Nozomi Networks Labs

SAN FRANCISCO, Feb. 8, 2024 /PRNewswire/ -- The latest Nozomi Networks Labs OT & IoT Security Report released today finds that network anomalies and attacks were the most prevalent threat to OT and IoT environments. Vulnerabilities within critical manufacturing also surged 230% ? a cause for concern as threat actors have far more opportunities to access networks and cause these anomalies.    

Real World Telemetry
Unique telemetry from Nozomi Networks Labs, collected from OT and IoT environments covering a variety of use cases and industries across 25 countries, finds network anomalies and attacks represented the most significant portion (38%) of threats during the second half of 2023. The most concerning of these network anomalies, which can indicate highly sophisticated threat actors being involved, increased 19% over the previous reporting period.

"Network scans" topped the list of Network Anomalies and Attacks alerts, followed closely by "TCP flood" attacks which involve sending large amounts of traffic to systems aiming to cause damage by bringing those systems down or making them inaccessible. "TCP flood" and "anomalous packets" alert types exhibited significant increases in both total alerts and averages per customer in the last six months, increasing more than 2x and 6x respectively.  

"These trends should serve as a warning that attackers are adopting more sophisticated methods to directly target critical infrastructure, and could be indicative of rising global hostilities," said Chris Grove, Director of Cybersecurity Strategy at Nozomi Networks. "The significant uptick in anomalies could mean that the threat actors are getting past the first line of defense while penetrating deeper than many would have initially believed, which would require a high level of sophistication. The defenders have gotten better at protecting against the basics, but these alerts tell us that the attackers are quickly evolving in order to bypass them."

Alerts on access control and authorization threats jumped 123% over the previous reporting period. In this category "multiple unsuccessful logins" and "brute force attack" alerts increased 71% and 14% respectively. This trend highlights the continued challenges in unauthorized access attempts, showing that identity and access management in OT and other challenges associated with user-passwords persist.

Below is the list of top critical threat activity seen in real-world environments over the last six months:

  1. Network Anomalies and Attacks ? 38% of all alerts
  2. Authentication and Password Issues ? 19% of all alerts
  3. Access Control and Authorization Problems ? 10% of all alerts
  4. Operational Technology (OT) Specific Threats ? 7% of all alerts
  5. Suspicious or Unexpected Network Behavior ? 6% of all alerts

ICS Vulnerabilities
With this spike in network anomalies top of mind, Nozomi Networks Labs has detailed the industries that should be on highest alert, based on analysis of all ICS security advisories released by CISA over the past six months. Manufacturing topped the list with the number of Common Vulnerabilities and Exposures (CVEs) in that sector rising to 621, an alarming 230% increase over the previous reporting period. Manufacturing, Energy and Water/Wastewater remained the most vulnerable industries for a third consecutive reporting period ? though the total number of vulnerabilities reported in the Energy sector dropped 46% and Water/Wastewater vulnerabilities dropped 16%. Commercial Facilities and Communications moved into the top five, replacing Food & Agriculture and Chemicals (which both dropped out of the top 10). Of note, Healthcare & Public Health, Government Facilities, Transportation Systems and Emergency Services all made the top 10. In the second half of last year:

Data from IoT Honeypots
Nozomi Networks Labs also analyzed a wealth of data on malicious activities against IoT devices, revealing several notable trends for these industries to consider. According to the findings, malicious IoT botnets remain active this year, and botnets continue to use default credentials in attempts to access IoT devices.

From July through December 2023, Nozomi Networks honeypots found:

Nozomi Networks Labs "OT & IoT Security Report: Assessing the Threat Landscape" provides security professionals with the latest insights needed to re-evaluate risk models and security initiatives, along with actionable recommendations for securing critical infrastructure.

Related Resources:

About Nozomi Networks
Nozomi Networks protects the world's critical infrastructure from cyber threats. Our platform uniquely combines network and endpoint visibility, threat detection, and AI-powered analysis for faster, more effective incident response. Customers rely on us to minimize risk and complexity while maximizing operational resilience. www.nozominetworks.com 

Read the Nozomi Networks Blog ? Follow Nozomi Networks on Twitter and LinkedIn

 

SOURCE Nozomi Networks


These press releases may also interest you

at 12:04
Spectrum Mobile, the nation's fastest-growing mobile provider¹, is making it easier than ever for customers to switch and save money with its latest offering ? a phone balance buyout program. Beginning today, when a customer switches to Spectrum...

at 12:03
ADGM, the international financial centre (IFC) of the UAE's capital, continues its solid performance paving the way for another strong year as the...

at 12:01
Vantiva (Euronext Paris: VANTI), a global technology leader enabling Network Service Providers (NSPs) to connect consumers around the world, today announced that it has strengthened its longstanding partnership with Vodafone UK, the largest full...

at 12:00
The American Society for Gastroenterology and Endoscopy (ASGE) announced today the launch of the Artificial Intelligence Institute for Gastroenterology, a milestone initiative to integrate artificial intelligence (AI) into gastrointestinal (GI) care,...

at 12:00
As You Are, the nation's leading telehealth provider of pediatric autism evaluations, announces a collaboration with Included Health, a new kind of healthcare company delivering virtual care and navigation for millions of people nationwide....

at 12:00
Con Edison Chairman and CEO Tim Cawley addressed the company's shareholders today, outlining plans to support New York's transition to clean energy and execute on investments that will enable the company to grow its business. "Never have the effects...



News published on and distributed by: