4. of Denial of Service (alternative 2022 deck)
An attacker can drain a battery that’s hard to replace (sealed in a phone, an implanted medical device, or in a hard-to-reach location) (battery, persist).
Threat |
|
You’ve decided to add remote access to a new pacemaker you are developing without considering all the possible risks this could introduce. Some medical devices such as pacemakers are configurable remotely via radio and need to have low energy consumption because they have either rechargeable or long-life batteries. An attacker is continually sending meaningless data to the device though, and it must decide whether that data is meaningful, which wastes the clock cycles of the microprocessor and consequently energy. |
|
CAPEC |
CAPEC-262 – Manipulate system resources CAPEC-130 – Excessive allocation... |