MITRE ATT&CK ICS
T0814

Denial of Service

Description

Adversaries may perform Denial-of-Service (DoS) attacks to disrupt expected device functionality. Examples of DoS attacks include overwhelming the target device with a high volume of requests in a short time period and sending the target device a request it does not know how to handle. Disrupting device state may temporarily render it unresponsive, possibly lasting until a reboot can occur. When placed in this state, devices may be unable to send and receive requests, and may not perform expected response functions in reaction to other events in the environment. Some ICS devices are particularly sensitive to DoS events, and may become unresponsive in reaction to even a simple ping sweep. Adversaries may also attempt to execute a Permanent Denial-of-Service (PDoS) against certain devices, such as in the case of the BrickerBot malware. (Citation: ICS-CERT April 2017) Adversaries may exploit a software vulnerability to cause a denial of service by taking advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Vulnerabilities may exist in software that can be used to cause a denial of service condition. Adversaries may have prior knowledge about industrial protocols or control devices used in the environment through [Remote System Information Discovery](https://attack.mitre.org/techniques/T0888). There are examples of adversaries remotely causing a [Device Restart/Shutdown](https://attack.mitre.org/techniques/T0816) by exploiting a vulnerability that induces uncontrolled resource consumption. (Citation: ICS-CERT August 2018) (Citation: Common Weakness Enumeration January 2019) (Citation: MITRE March 2018)

Mapped SPARTA techniques

3 techniques

  • T0814 'Denial of Service' addresses adversary disruption of expected device functionality through resource overload; SPARTA DE-0009.05 covers overload of ground-based SDA systems as one mechanism (the other being corruption). Cross-tactic moderate (inhibit-response-function vs defense-evasion).

  • EX-0013FloodingST0004
    addresses
    moderate

    T0814 'Denial of Service' addresses adversary attacks that prevent legitimate operations of a target; SPARTA EX-0013 'Flooding' parent-level activity (overwhelming the command receiver, OBC parser, or bus) is the same DoS pattern. Cross-tactic moderate (T0814 in inhibit-response-function vs SPARTA EX-0013 execution).

  • EX-0013.02Erroneous InputST0004
    addresses
    moderate

    Flooding with erroneous/malformed input causes denial of service via parser exhaustion and error-handling overhead; T0814 'Denial of Service' covers this DoS-via-flooding pattern at cross-tactic moderate level.

Cite as SafeMode Space, mitre-attack-ics T0814.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.