I've worked on systems deployed in the financial sector in high risk environments.
This sort of monitoring doesn't happen in the real world.
This sort of monitoring doesn't happen in the real world.
Now this does not make it impossible, just very complex. In a more "controlled" environment such as a naval ship, i could see this actually working better, especially if the system is supposed to talk to very few external systems.
Security engineering is about tolerable failure modes. - Dan Geer (2014)
Except on extremely controlled networks, this would be very hard to detect. It gets even worse when you consider that the Chinese had/have a distributed network of compromised machines. Imagine using a Google edge server as a dead drop...