Summary
CERT-EU Security Whitepaper 17-004 Network devices – such as routers, switches, firewalls – are essential components of every IT infrastructure. All traffic (encrypted or not) has to go through several such network devices. Compromising network devices allows an adversary to steal sensitive data, corrupt communications, or disrupt activity of the targeted organization. The range of attacks against network devices has been growing for the past years, from exploitation of undocumented access to development of complex implants modifying the behavior of devices. Known attacks go from passive monitoring to large-scale denial-of-service attacks The purpose of this document is to provide recommendations on how to assess, prevent, and detect network devices compromise. Additionally, some ideas on how to deal with devices outside of the organization’s perimeter are provided.