Exploring Ransomware Attacks on Smart Inverters

BoHyun Ahn, Alycia M. Jenkins,Taesic Kim,Jianwu Zeng, Lifford McLauchlan,Sung-won Park

2023 IEEE Energy Conversion Congress and Exposition (ECCE)(2023)

引用 0|浏览1
暂无评分
摘要
The prevalence of ransomware threats has been rapidly increased, positioning them as a distinct malware form of cyberattacks. It is anticipated that financially motivated ransomware groups will increasingly focus their efforts on targeting critical power system infrastructures. Meanwhile, as traditional power grids keep progressing towards inverter-dominant smart grids and inverters are getting smarter (i.e., smart inverters) by incorporating real-time remote access and seamless firmware update. Therefore, the ransomware attackers may directly target smart inverters by coordinated malware attacks to manipulate critical power infrastructures leading to physical, financial, and societal disruption. This paper explores potential ransomware attacks on a commercial smart inverter and impacts on the overall inverter system. Firstly, two practical ransomware attack scenarios (remote access and physical access) are modeled by reverse engineering findings of the smart inverter and leveraging MITRE ATT&CK for ICS Matrix. Then, we conduct an assumed-breached penetration testing of the physical access ransomware attack scenario to demonstrate the current vulnerability and real impacts on the smart inverter system.
更多
查看译文
关键词
cyberattack,malware,penetration testing,ransomware,smart inverter
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要