Reporting Message
Parent: T1692
Description
Adversaries may spoof reporting messages in control system environments for evasion and to impair process control. In control systems, reporting messages contain telemetry data (e.g., I/O values) pertaining to the current state of equipment and the industrial process. Reporting messages are important for monitoring the normal operation of a system or identifying important events such as deviations from expected values. If an adversary has the ability to Spoof Reporting Messages, they can impact the control system in many ways. The adversary can Spoof Reporting Messages that state that the process is operating normally, as a form of evasion. The adversary could also Spoof Reporting Messages to make the defenders and operators think that other errors are occurring in order to distract them from the actual source of a problem.(Citation: Bonnie Zhu, Anthony Joseph, Shankar Sastry 2011)
Mapped SPARTA techniques
2 techniques
T1692.002 'Reporting Message' addresses adversary unauthorised reporting messages — sensor deception is achieved by injecting falsified sensor reports/measurements into the SSA/SDA processing pipeline, creating exactly this kind of unauthorised reporting message. Cross-tactic moderate (T1692.002 in evasion AND impair-process-control while SPARTA DE-0009.04 is defense-evasion — partial tactic alignment with evasion).
T1692.002 'Reporting Message' specifically addresses unauthorised reporting/telemetry messages; SPARTA EX-0014.03 'Sensor Data' spoofing creates exactly this kind of unauthorised reporting message (falsified sensor readings injected on sensor lines). Cross-tactic moderate (evasion/impair vs execution); direct sub-technique concept match.
Cite as SafeMode Space, mitre-attack-ics T1692.002.