Cyber-Physical Systems Security

  1. Threat Landscape Analysis
    1. Threat Actor Categories
      1. Nation-State Actors
        1. Capabilities and Resources
          1. Strategic Objectives
            1. Attack Sophistication
            2. Cybercriminal Groups
              1. Financial Motivations
                1. Ransomware Operations
                  1. Data Theft
                  2. Hacktivists
                    1. Ideological Motivations
                      1. Publicity Seeking
                        1. Disruption Goals
                        2. Insider Threats
                          1. Privileged Access Abuse
                            1. Unintentional Actions
                              1. Malicious Intent
                              2. Terrorist Organizations
                                1. Physical Damage Goals
                                  1. Psychological Impact
                                2. Attack Vectors and Methods
                                  1. Network-Based Attacks
                                    1. Protocol Exploitation
                                      1. Network Scanning
                                        1. Lateral Movement
                                        2. Physical Access Attacks
                                          1. Device Tampering
                                            1. Unauthorized Access
                                              1. Hardware Modification
                                              2. Supply Chain Attacks
                                                1. Component Compromise
                                                  1. Software Supply Chain
                                                    1. Third-Party Risks
                                                    2. Social Engineering
                                                      1. Phishing Attacks
                                                        1. Pretexting
                                                          1. Baiting
                                                          2. Wireless Attacks
                                                            1. Signal Interception
                                                              1. Jamming Attacks
                                                                1. Rogue Access Points
                                                              2. CPS-Specific Attack Types
                                                                1. Sensor Data Manipulation
                                                                  1. False Data Injection
                                                                    1. Sensor Spoofing
                                                                      1. Data Replay Attacks
                                                                      2. Control Logic Compromise
                                                                        1. PLC Programming Changes
                                                                          1. Logic Bomb Insertion
                                                                            1. Control Algorithm Modification
                                                                            2. Denial of Service Attacks
                                                                              1. Network Flooding
                                                                                1. Resource Exhaustion
                                                                                  1. Communication Disruption
                                                                                  2. Man-in-the-Middle Attacks
                                                                                    1. Communication Interception
                                                                                      1. Data Modification
                                                                                        1. Command Injection