Remote Firmware Update Monitoring
Definition
Monitoring of remote firmware update commands to identify unauthorized software installations.
How it works
By deploying sensors within the OT environment to passively monitor network traffic, tools can leverage deep packet inspection to identify protocol-specific commands and generate logs of relevant firmware activity. Additionally, these tools may incorporate behavioral and signature-based analysis to enhance detection and alerting capabilities.
Artifact Relationships:
This defensive technique is related to specific artifacts. Click the artifact node for more information.
References
The following references were used to develop the Remote Firmware Update Monitoring knowledge-base article.
(Note: the consideration of references does not imply specific functionality exists in an offering.)