Facility Security Flashcards

1
Q

What is a CAN in Facility Security?

A

Controller Area Network. Digital Serial Communications network within vehicles

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the primary interface for a CAN in a vehicle

A

ODB-II (on-board diagnostics)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the security concerns with CANs

A

There is no concept of source addressing or message authentication in a CAN bus

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How can CAN busses be exploited

A

Attach an exploit to the OBD-11 bus
Exploit onboard cellular connection
Exploit over wifi

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is IOT

A

A group of objects, electronic or not, that are connected to the wider internet using embedded electronic components

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the typical OS for most smart devices

A

An embedded version of linux or Android

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What should occur when vulnerabilities for smart devices are identified?

A

Efforts must be taken to patch vulnerabilities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is an embedded system

A

Computer system designed to perform a specific or dedicated function.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are some of the security concerns with embedded systems

A

They are considered state environments where frequesnt changes are not made or allowed.

They often have very little support for finding and correcting security vulnerabilities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is a PLC

A

Programmable Logic Controllers are a type of computer that are designed for industrial or outdoor settings

They can automate and monitor mechanical systems.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Can PLC Firmware be patched or reprogrammed?

A

Yes, the firmware can be patched and reprogrammed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is a SoC

A

System on a chip is processor that integrates the platform functionality of multiple logical controllers onto a single chip.

Combines PLCs into a single chip

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Are SoCs power efficient?

A

yes, when used with an embedded system, SoCs are power efficient

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is an RTOS

A

A Real Time Operating System is an OS that prioritizes deterministic executions of operations to ensure consistent response for time critical tasks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are some operational concerns with Embedded Systems

A

They typically cannot tolerate reboots or crashes

and must have response times that are predictable within microseconds.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is an FPGA

A

A Field Programmable Gate Array is a processor that con be programed to perform a specific function by a customer rather then being programmed at the time of manufacture.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Can SoCs be reprogrammed?

A

No, once they are programmed, they cannot be over written/

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What is a benefit of a FPGA

A

They allow customers to configure the programming logic to run a specific application instead of using ASIC ( Application Specific Integrated Circuits)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What is OT

A

Operational Technology communication network designed to implement an ICS (Industrial Control System) rather than a data networking system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Describe an ICS

A

Industrial Control Systems prioritize Availability and Integrity over security over confidentiality.

It is a network that manages embedded devices

Makes use of Field Bus for its communication protocol.

Powers things such as Water supplies, manufacturing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What is FieldBus

A

Digital Serial Data communications used in OT networks to link PLCs

22
Q

What is an HMI

A

Human Machine interfaces are an I/O panel that allows users to configure and moniutor the system

23
Q

Describe how an ICS system works

A

ICS manages the process automation by linking together PLCs using a fieldbus to make changes in the physical world.

24
Q

What is a Data Historian

A

Software that aggregates and catalogues data from multiple sources wihtin an ICS

25
Q

What is SCADA

A

Supervisory Control and Data Acquisition

Type of ICS that manages large scale, multiple site devices and equipment over a large area.

26
Q

How does SCADA fit into an organization

A

Typically ran as software on an ordinary computer.

It gathers data from and manages plant devices and equipment with embedded PLCs that are connected over a WAN

27
Q

What is ModBus

A

Communications protocol used in OR networks.

OT does not use TCP/IP Stack, it uses ModBus.

28
Q

What does ModBus do

A

It gives control servers and SCADA hosts the ability to query and change the configuration of PLCs

29
Q

What are the four steps to mitigating vulnerabilities for specialized systems as outlined by the NIST

A
  1. Establish administrative control over OT networks by recruiting staff with relevant experience
  2. Implement the minimum network links by disabling unnecessary links, services, and protocols.
  3. Develop and test a patch management program for OT networks.
  4. Perform regulate audits of logical and physical access to systems to detect possible vulnerabilities and intrusions.
30
Q

What is an important warning for OT security audits

A

enumeration tools and active vulnerability scans can cause issues with OT networks.

31
Q

What is a Premise System

A

Systems used for building automation and physical access systems

Many physical system designs allow for monitoring from corporate date networks over lan

32
Q

What is a BAS

A

Building Automation Systems are components and protocols that facilitate the centralized configuration and monitoring of systems in an office.

33
Q

What are some vulnerabilities of BAS

A

Process and memory vulnerabilities in PLCs

Plaintext credentials or keys in application code.

Code injections against web-user interface`

34
Q

What are some DOS concerns within a BAS

A

DOS conditions could be caused by an attack on a BAS that affects items such as HVAC.

If HVAC is interrupted and a server room gets too hot, the servers may shut down to prevent damage to the hardware.

35
Q

What is a PACS system

A

Physical Access Control systems are components and protocols that facilitates the centralized configuration and monitoring of security mechanisms within offices and data centers

36
Q

Can PACS be implemented both as part of a BAS or be an independent system?

A

Yes, they can be both.

One concern is that if implemented by a vendor, they can fall outside of Threat Hunting as they are managed by a vendor

37
Q

What are the types of cameras used in physical security monitoring

A

PTZ ( Pan Tilt Zoom)
CCTV (Closed Circuit TV)

38
Q

Types of door locks used in physical security

A

Keys, PINS, Wireless Signals (NFC, RFID), or Biometrics

39
Q

Describe biometric readers

A

PACs that rely on the physical characteristics of a person to identify them.

Biometrics are considered a “Something you are: authentication method.

40
Q

What is an FAR in for biometric readers?

A

(False Acceptance Rate )
Rate that a system authenticates a user as authorized or validated when they should not have been granted access to the system

41
Q

What is the FRR for biometric readers?

A

False Rejection Rate is the rate at which a user is rejected when they should have been validated.

42
Q

What is the CER for biometric readers?

A

Crossover Error Rate is where the false acceptance rate and false rejection rate are equal.

CER measures the effectiveness of a biometric system.

43
Q

What are type A hand held extinguishers used for

A

Ordinary solid combustibles - Wood, Paper, Fabrics, Rubber.

They are Water based

Green Triangles with an A

44
Q

What are type B hand held extinguishers used for

A

Flammable Liquids and gasses:
Gasoline, Oils, Paint, Lacquer

They are a dry chemical or CO2 based

Red squares with a B

45
Q

What are type C hand held extinguishers used for

A

Fire involving live electrical equipment
1- shut down power

CO2 based extinguisher

Blue circle with a C

46
Q

What are type D hand held extinguishers used for

A

Combustible metals or metal alloys:
Lithium Fires from batteries

Golden Star with a D

47
Q

What are type K hand held extinguishers used for

A

Fire in cooking appliances that involve combustible cooking media:

Vegetable or animals oils or fats.

48
Q

What are the two types of sprinklers

A

Wet pipe - Puptes filled with water ready for the tips to be melted off

Dry pipe - Pipes filled with air through which water is pushed when needed

Pre action - Will activate when heat or a fire is detected

49
Q

What is special hazard protection

A

Clean Agent Syetem that uses inert gas to fight fires where there is live electrical equipment. Can use HALON gas or FM-200, or Co2

50
Q

What should the level of humidity for HVAC be allowed

A

40% humidity

Too high, the moisture may cause corrosion on the hardware
Too low, electrostatic discharge may damage hardware

HVAC may be managed via ICS or SCADA

51
Q

What is the Tempest designation

A

US Gov standard for the level of shielding required in a building to ensure that emissions and interference cannot enter or exit the facilities.

Also EMP resistant.