Towards Better Cyber Security Consciousness: The Ease and Danger of OSINT Tools in Exposing Critical Infrastructure Vulnerabilities


연구 분야: Infrastructure



학회: 2023 8th International Conference on Computer Science and Engineering (UBMK)


초록

This article explores open-source intelligence (OS-INT) to identify the vulnerabilities and loopholes in power grid systems, focusing on an electrical distribution company operating in Turkey. The study emphasizes the potential risks of sharing publicly available information on social media accounts, websites, reports, and press releases which most companies overlook. It highlights that individuals or adversaries can exploit this information to harm companies and countries that may not be fully aware of these vulnerabilities. OSINT tools can efficiently gather interpretable data on a company, which companies unknowingly share. By refining the collected data, the study aims to understand the technologies used, their software versions, and any associated vulnerabilities. Web scraping tools extract data from the company's website, which may contain critical information about updates, ongoing systems, and technologies. The article provides a comprehensive understanding of the potential risks and vulnerabilities associated with sharing sensitive information and the various OSINT tools and techniques that can be used to identify and address these vulnerabilities. The importance of vigilance against the potential harm that remote or unrelated individuals can inflict using OSINT capabilitiesis underscored. This study shows how easy it is to detect vulnerabilities in a critical infrastructure system using OSINT tools.


Author Profile
Muhammad Hasban Pervez

Dept. of Management Information Systems Kadir Has University Istanbul Türkiye

정보 없음
Author Profile
Mert Ilhan Ecevit

Cyber Security and Critical Infrastructure Research Center Kadir Has University Istanbul Türkiye

Andorra
Author Profile
Najiba Zainab Naqvi

Cyber Security Graduate Program Kadir Has University Istanbul Türkiye

정보 없음

📄 논문 정보

발행 연도 2023년
인용수 568
출판 국가 Germany, Andorra
사이트 IEEE
좋아요 수 0

연관 논문 목록 (5건)