Learning Objective 4.1.A: Identify types of computing devices.
- 4.1.A.1 Server computers are devices that provide one or more services to other computers (e.g., DNS, DHCP, FTP). Any computer can be a server, and in an enterprise environment servers typically have more processing power and storage than a personal computer.
- 4.1.A.2 Personal computers are devices that are designed to be used by one person for work or recreational purposes (e.g., word processing, graphic design, web browsing, and media production or viewing). These include desktop, laptop, and notebook computers.
- 4.1.A.3 Handheld computers (also called mobile computers or information appliances) are smaller than personal computers and run on battery power. These include tablets, smartphones, and wearable technology like smart watches.
- 4.1.A.4 Embedded computers are devices that are part of a machine. Embedded devices have specific instruction sets for interfacing with the specialized components of the machine they’re embedded in. Embedded computers tend to be slower and cheaper than other computers and have minimal storage.
- 4.1.A.5 Everyday devices with embedded computers are often called Internet of Things (IoT) devices. Embedded computers are found in transportation (e.g., cars, trains, and airplanes), devices that operate critical infrastructure (e.g., operating circuit breakers at electrical substations and pumps at water treatment plants), medical equipment (e.g., IV pumps, MRI scanners, pacemakers, and insulin pumps), and everyday devices like washing machines, coffee makers, and thermostats.
Learning Objective 4.1.B: Identify the type of malware used in a cyberattack.
- 4.1.B.1 Malware is malicious software that can damage or destroy a device or network, or allow an adversary access to a device and the data on the device.
- 4.1.B.2 Malware is often used as a tool to accomplish part of an adversary’s plan to achieve their ultimate goal(s). There are many types of malware, such as:
- Viruses are malware that must be activated by a user executing or opening a file.
- Worms spread from one computer to another without human interaction.
- Trojans are malware embedded in other software that seems harmless. Remote access trojans (RATs) provide an adversary with remote access to the target system.
- Ransomware encrypts a device’s files, preventing the user from accessing files on the device. The ransomware typically presents the user with a screen demanding payment and promising to give the user a decryption key for their files if the user pays within a fixed amount of time.
- Spyware tracks a user’s actions on a computer and sends information back to an adversary.
- A keylogger is software or hardware that logs the users keystrokes and sends the information back to the adversary. Adversaries can often extract usernames and passwords from keylogger data.
- Logic bombs are set to trigger their effect only when a specific set of conditions are met; the conditions can include time and date, specific type or version of the operating system, character set the computer is using, etc.
- A rootkit is sophisticated malware that gets into the target computer’s operating system and can control nearly every aspect of the system, including making the rootkit itself invisible to detection.
- 4.1.B.3 While most malware is a file or a collection of files, fileless malware is malicious code that lives in RAM and uses legitimate programs already installed on a device to compromise it.
Learning Objective 4.1.C: Explain how adversaries can exploit common device vulnerabilities to cause loss, damage, disruption, or destruction.
- 4.1.C.1 Adversaries can develop exploits for known vulnerabilities in software (including operating systems). Devices with unpatched software are vulnerable to these exploits, which could allow an adversary to crash a system, view user actions, enable or disable various services or components on the device (e.g., turning on a webcam or microphone), or even take control of the device to issue their own commands including commands to steal or destroy information on the device.
- 4.1.C.2 Adversaries can take advantage of weak authentication requirements by guessing a user’s password or using social engineering to get a user to divulge their password.
- 4.1.C.3 When systems don’t have a password on the basic input output system (BIOS) or unified extensible firmware interface (UEFI), an adversary can boot a computer into a special mode (e.g., “recovery mode”) that gives them higher-level privileges. Without BIOS or UEFI protection, adversaries can load their own operating system onto a device from an external drive and use specialized tools to alter or create user profiles, including changing user passwords.
- 4.1.C.4 Adversaries can load malware onto an external drive, and if autorun is enabled, then a device will run the malware when the external drive is inserted.
- 4.1.C.5 Adversaries can leverage open ports to connect to a device.
- 4.1.C.6 Adversaries can send malicious data to devices to disrupt them or attempt to take control of them. Devices that have no firewall (or a misconfigured firewall) cannot filter out this malicious data.
- 4.1.C.7 Adversaries often attempt to install malware on a device to disrupt or control it. Devices lacking anti-malware software are more vulnerable to this type of attack.
Learning Objective 4.1.D: Assess and document risks from device vulnerabilities.
- 4.1.D.1 Risk from device vulnerabilities can come from unauthorized access or malware that allow an adversary to impersonate an authorized user, remotely control a device, encrypt a device’s drive to ransom the data, or wipe a device’s memory, destroying data or rendering the device inoperable. The level of risk varies depending on the criticality of the device or the services the device provides or data it stores.
- 4.1.D.2 High risks from device vulnerabilities involve potentially compromising sensitive data or critical operations.
- Illustrative examples for 4.1.D.2:
- An organization has not installed the most recent update for their email server which included a patch for a known critical vulnerability.
- Illustrative examples for 4.1.D.2:
- 4.1.D.3 Moderate risks from device vulnerabilities can arise from weak authentication requirements or from vulnerabilities that would be less likely to be exploited.
- Illustrative examples for 4.1.D.3:
- A water treatment plant has embedded systems controlling pumps. The pumps can be remotely accessed via username and password for remote management for the plant, but the devices do not require multi-factor authentication (MFA).
- Illustrative examples for 4.1.D.3:
- 4.1.D.4 Low risks from device vulnerabilities are typically related to vulnerabilities that, if exploited, would have little impact.
- Illustrative examples for 4.1.D.4:
- An employee’s laptop has telnet port 23 open.
- Illustrative examples for 4.1.D.4:
วัตถุประสงค์การเรียนรู้ 4.1.A: ระบุประเภทของอุปกรณ์คอมพิวเตอร์
- 4.1.A.1 คอมพิวเตอร์เซิร์ฟเวอร์คืออุปกรณ์ที่ให้บริการหนึ่งหรือหลายอย่างแก่คอมพิวเตอร์อื่น ๆ (เช่น DNS, DHCP, FTP) คอมพิวเตอร์เครื่องใดก็สามารถเป็นเซิร์ฟเวอร์ได้ และในสภาพแวดล้อมระดับองค์กร เซิร์ฟเวอร์มักจะมีความสามารถในการประมวลผลและความจุในการจัดเก็บข้อมูลมากกว่าคอมพิวเตอร์ส่วนบุคคล
- 4.1.A.2 คอมพิวเตอร์ส่วนบุคคลคืออุปกรณ์ที่ออกแบบมาเพื่อใช้โดยบุคคลเดียวเพื่อการทำงานหรือความบันเทิง (เช่น การพิมพ์เอกสาร, การออกแบบกราฟิก, การท่องเว็บ, และการผลิตหรือรับชมสื่อ) รวมถึงคอมพิวเตอร์เดสก์ท็อป แล็ปท็อป และโน้ตบุ๊ค
- 4.1.A.3 คอมพิวเตอร์พกพา (หรือเรียกว่าคอมพิวเตอร์มือถือ หรืออุปกรณ์สารสนเทศ) มีขนาดเล็กกว่าคอมพิวเตอร์ส่วนบุคคลและใช้พลังงานจากแบตเตอรี่ รวมถึงแท็บเล็ต สมาร์ทโฟน และเทคโนโลยีสวมใส่ เช่น นาฬิกาอัจฉริยะ
- 4.1.A.4 คอมพิวเตอร์ฝังตัวคืออุปกรณ์ที่เป็นส่วนหนึ่งของเครื่องจักร อุปกรณ์ฝังตัวจะมีชุดคำสั่งเฉพาะสำหรับการเชื่อมต่อเข้ากับส่วนประกอบพิเศษของเครื่องจักรที่ฝังอยู่ คอมพิวเตอร์ฝังตัวมักจะมีความเร็วต่ำกว่าและมีราคาถูกกว่าคอมพิวเตอร์ทั่วไป และมีพื้นที่จัดเก็บข้อมูลน้อยมาก
- 4.1.A.5 อุปกรณ์ในชีวิตประจำวันที่มีคอมพิวเตอร์ฝังตัวมัก被称为 Internet of Things (IoT) devices คอมพิวเตอร์ฝังตัวพบได้ในยานพาหนะ (เช่น รถยนต์, เรือ, เครื่องบิน), อุปกรณ์ที่ดำเนินการโครงสร้างพื้นฐานสำคัญ (เช่น การเปิด-ปิดเบรกเกอร์ในสถานีไฟฟ้าแรงสูง และปั๊มในระบบบำบัดน้ำ), อุปกรณ์ทางการแพทย์ (เช่น ปั๊มหยดน้ำ, เครื่อง MRI, จังหวะหัวใจเทียม, และปั๊มอินซูลิน), และอุปกรณ์ในชีวิตประจำวัน เช่น เครื่องซักผ้า, เครื่องชงกาแฟ, และเทอร์โมสตัท
วัตถุประสงค์การเรียนรู้ 4.1.B: ระบุประเภทของมัลแวร์ที่ใช้ในการโจมตีทางไซเบอร์
- 4.1.B.1 มัลแวร์คือซอฟต์แวร์ที่เป็นอันตรายที่สามารถทำลายหรือทำให้เสียหายต่ออุปกรณ์หรือเครือข่าย หรือเปิดโอกาสให้ผู้โจมตีเข้าถึงอุปกรณ์และข้อมูลบนอุปกรณ์นั้นได้
- 4.1.B.2 มัลแวร์มักใช้เป็นเครื่องมือเพื่อให้ผู้โจมตีบรรลุเป้าหมายหลักของตน มีมัลแวร์หลายประเภท เช่น:
- ไวรัสคือมัลแวร์ที่ต้องถูกเปิดใช้งานโดยผู้ใช้通过开展หรือเปิดไฟล์
- เวิร์มกระจายจากคอมพิวเตอร์หนึ่งไปยังอีกเครื่องหนึ่งโดยไม่ต้องมีการกระทำจากมนุษย์
- Trojan คือมัลแวร์ที่ถูกฝังอยู่ในซอฟต์แวร์อื่น ๆ ที่ดู无害 Remote access trojans (RATs) เปิดโอกาสให้ผู้โจมตีเข้าถึงระบบเป้าหมายจากระยะไกล
- Ransomware จะเข้ารหัสไฟล์ของอุปกรณ์ ทำให้ผู้ใช้ไม่สามารถเข้าถึงไฟล์บนอุปกรณ์ได้ โดยปกติแล้ว Ransomware จะแสดงหน้าจอให้ผู้ใช้กรอกค่าไถ่และสัญญาว่าจะมอบกุญแจถอดรหัสให้กับผู้ใช้หากชำระภายในกำหนดเวลา
- Spyware จะติดตามการกระทำของผู้ใช้บนคอมพิวเตอร์และส่งข้อมูลกลับไปยังผู้โจมตี
- Keylogger คือซอฟต์แวร์หรือฮาร์ดแวร์ที่บันทึกการกดแป้นพิมพ์ของผู้ใช้และส่งข้อมูลกลับไปยังผู้โจมตี ผู้โจมตีมักจะดึงชื่อผู้ใช้และรหัสผ่านออกจากข้อมูลของ keylogger ได้
- Logic bombs ถูกตั้งไว้เพื่อกระตุ้นผลลัพธ์เฉพาะเมื่อเงื่อนไขที่กำหนดเป็นจริง; เงื่อนไขอาจรวมถึงเวลาและวันที่, ประเภทหรือเวอร์ชันของระบบปฏิบัติการ, ชุดอักขระที่คอมพิวเตอร์กำลังใช้ ฯลฯ
- Rootkit คือมัลแวร์ที่มีความซับซ้อนซึ่งแทรกเข้าสู่ระบบปฏิบัติการของคอมพิวเตอร์เป้าหมายและสามารถควบคุมเกือบทุกด้านของระบบ รวมถึงการทำให้อัตโนมัติตัวเองไม่ปรากฏต่อการตรวจจับ
- 4.1.B.3 แม้มัลแวร์ส่วนใหญ่จะเป็นไฟล์หรือกลุ่มไฟล์ แต่ Fileless malware คือโค้ดที่เป็นอันตรายที่อาศัยอยู่ใน RAM และใช้โปรแกรมที่ถูกติดตั้งอยู่แล้วบนอุปกรณ์เพื่อทำลายมัน
วัตถุประสงค์การเรียนรู้ 4.1.C: อธิบายวิธีการที่ผู้โจมตี可以利用ความเปราะบางทั่วไปของอุปกรณ์เพื่อก่อให้เกิดความสูญเสีย ความเสียหาย การหยุดชะงัก หรือการทำลาย
- 4.1.C.1 ผู้โจมตีสามารถสร้างช่องโหว่ exploitation สำหรับจุดอ่อนที่ทราบแล้วในซอฟต์แวร์ (รวมถึงระบบปฏิบัติการ) อุปกรณ์ที่มีซอฟต์แวร์ไม่ได้รับการอัปเดตเพื่อปิดช่องโหว่จะเสี่ยงต่อ exploitation เหล่านี้ ซึ่งอาจทำให้ผู้โจมตีสามารถทำให้ระบบล่ม ดูการกระทำของผู้ใช้ เปิดหรือปิดบริการหรือส่วนประกอบต่างๆ บนอุปกรณ์ (เช่น การเปิดกล้องเว็บแคมหรือไมโครโฟน) หรือแม้แต่ยึดควบคุมอุปกรณ์เพื่อออกคำสั่งของตนเอง รวมถึงคำสั่งเพื่อขโมยหรือทำลายข้อมูลบนอุปกรณ์
- 4.1.C.2 ผู้โจมตีสามารถใช้ประโยชน์จากข้อกำหนดการยืนยันตัวตนที่อ่อนแอโดยการเดารหัสผ่านของผู้ใช้หรือใช้เทคนิคทางสังคมวิทยา (social engineering) เพื่อให้ผู้ใช้เปิดเผยรหัสผ่านของตน
- 4.1.C.3 เมื่อระบบไม่มีรหัสผ่านสำหรับ basic input output system (BIOS) หรือ unified extensible firmware interface (UEFI) ผู้โจมตีสามารถบูตคอมพิวเตอร์เข้าสู่โหมดพิเศษ (เช่น “recovery mode”) ที่ให้สิทธิ์ระดับสูงแก่พวกเขา โดยไม่มีการป้องกัน BIOS หรือ UEFI ผู้โจมตีสามารถโหลดระบบปฏิบัติการของตนเองลงบนอุปกรณ์จากไดรฟ์ภายนอกและใช้เครื่องมือเฉพาะเจาะจงในการแก้ไขหรือสร้างโปรไฟล์ผู้ใช้ใหม่ รวมถึงการเปลี่ยนรหัสผ่านของผู้ใช้
- 4.1.C.4 ผู้โจมตีสามารถโหลดมัลแวร์ลงบนไดรฟ์ภายนอก และหากเปิดใช้งาน autorun แล้ว อุปกรณ์จะรันมัลแวร์เมื่อเสียบไดรฟ์ภายนอกเข้าไป
- 4.1.C.5 ผู้โจมตีสามารถใช้พอร์ตที่เปิดอยู่เพื่อเชื่อมต่อกับอุปกรณ์
- 4.1.C.6 ผู้โจมตีสามารถส่งข้อมูลที่เป็นอันตรายไปยังอุปกรณ์เพื่อยึดครองหรือขัดขวางการทำงาน และอุปกรณ์ที่ไม่มีไฟวอลล์ (หรือมีไฟวอลล์ที่ตั้งค่าผิดพลาด) จะไม่สามารถกรองข้อมูลที่เป็นอันตรายเหล่านี้ได้
- 4.1.C.7 ผู้โจมตีมักพยายามติดตั้งมัลแวร์บนอุปกรณ์เพื่อยึดครองหรือขัดขวางการทำงาน อุปกรณ์ที่ขาดซอฟต์แวร์ป้องกันมัลแวร์จะมีความเสี่ยงต่อการโจมตีประเภทนี้มากกว่า
วัตถุประสงค์การเรียนรู้ 4.1.D: ประเมินและบันทึกความเสี่ยงจากช่องโหว่ของอุปกรณ์
- 4.1.D.1 ความเสี่ยงจากช่องโหว่ของอุปกรณ์อาจมาจากการเข้าถึงโดยไม่ได้รับอนุญาตหรือมัลแวร์ที่อนุญาตให้ผู้โจมตีปลอมตัวเป็นผู้ใช้ที่ได้รับอนุญาต ควบคุมอุปกรณ์จากระยะไกล เข้ารหัสไดรฟ์ของอุปกรณ์เพื่อเรียกค่าไถ่ข้อมูล หรือลบความจำของอุปกรณ์ ทำให้ข้อมูลหายหรือทำให้อุปกรณ์ใช้งานไม่ได้ ระดับความเสี่ยงจะแตกต่างกันไปตามความสำคัญของอุปกรณ์ บริการที่อุปกรณ์ให้บริการ หรือข้อมูลที่เก็บรักษาไว้
- 4.1.D.2 ความเสี่ยงสูงจากช่องโหว่ของอุปกรณ์เกี่ยวข้องกับการถูกทำลายข้อมูลสำคัญหรือกระบวนการสำคัญอย่างมีนัยสำคัญ
- ตัวอย่างประกอบสำหรับ 4.1.D.2:
- องค์กรไม่ได้ติดตั้งการอัปเดตล่าสุดสำหรับเซิร์ฟเวอร์อีเมลซึ่งรวมถึงการปิดช่องโหว่สำหรับจุดอ่อนที่ทราบแล้วที่มีระดับวิกฤต
- ตัวอย่างประกอบสำหรับ 4.1.D.2:
- 4.1.D.3 ความเสี่ยงปานกลางจากช่องโหว่ของอุปกรณ์อาจเกิดขึ้นจากข้อกำหนดการยืนยันตัวตนที่อ่อนแอหรือจากช่องโหว่ที่จะถูกนำไปใช้ประโยชน์น้อยกว่า
- ตัวอย่างประกอบสำหรับ 4.1.D.3:
- โรงงานบำบัดน้ำมีระบบฝังตัวควบคุมปั๊มน้ำ ปั๊มสามารถเข้าถึงจากระยะไกลผ่านชื่อผู้ใช้และรหัสผ่านสำหรับการจัดการระยะไกลสำหรับโรงงาน แต่อุปกรณ์ไม่ต้องการการยืนยันตัวตนหลายขั้นตอน (MFA)
- ตัวอย่างประกอบสำหรับ 4.1.D.3:
- 4.1.D.4 ความเสี่ยงต่ำจากช่องโหว่ของอุปกรณ์มักเกี่ยวข้องกับช่องโหว่ที่จะมีผลกระทบเล็กน้อยหากถูกนำไปใช้ประโยชน์
- ตัวอย่างประกอบสำหรับ 4.1.D.4:
- แล็ปท็อปของพนักงานมีพอร์ต telnet 23 เปิดอยู่
- ตัวอย่างประกอบสำหรับ 4.1.D.4:

