No... It's called "doxxing".
DDoS is completely different.
No... It's called "doxxing".
DDoS is completely different.
The user just near about doxx'd themselves by all the OSINT that was available. That's not particularly interesting. Trolling with IRL effects is a the better peer as well, in that case. It's also similar to malicious pop-ups in a browser, but a browser never had the life-governance abilities that a smart phone has now.
What is interesting, from an exploit dev standpoint, is that in a sense you can DDoS someone's life by overwhelming their human data intake systems of notification-based services, which they use to govern their own behaviors.
Think of this in terms of a notification == a connection, and human == router.
* Baseline: 5 notifications per hour -> parseable by a human with 1 brain and a single iphone to triage them. No discernable effect on ability to rely on other key notifications (calendar alerts, banking messages, so on).
* Elevated from baseline: 5 notifications per 10 mins: odd, but still parseable, maybe calendar alerts and watching for an important email take a back seat.
* Malicious DDoS: 5 notifications per minute, on repeat: you don't know what's going on, it is overwhelming, you can't particularly turn off a phone because you still need the calendar app, and so on.
When the notification system, taken in aggregate, is providing some key service to how a person runs their life, overwhelming that system is a DDoS.
Another vector: many calendars such as Gcal and especially with recreational users, allow appointments to be dropped onto the calendar. This is a common sales tactic too. Generate N appointments, overwhelm a calendar, and it's up to the user to remove malicious appointments manually vs. a very bulk, automated appointment attack. DDoS as well.
Like I sort of referenced in my OP, it's part of a group of exploits which still lacks firm industry terminology, but definitely are out there.
The only firm things I can ID so far in this cyber<>physical attack space is:
- cyber<>cyber TTPs definitely apply in a certain way
- Vulns->exploits can start with CIA-like threat modeling (so ID'd starting point)
- the indicators of compromise show up both in the cyber domain, and physical domain, as part of a single attack
- it's a greenfield on defining what an IOC in the physical domain part of this attack is. If you attack plant watering system, is there anything unique on the outcome of plants that indicate it's definitely cyber?
- The physics of the real world play a large role in governing how the physical aspect of the attack occurs(my human ability to read, process notifications at certain scales of notification receipt)
Another example is "AI/ML" can generate financial reports that are believable. If you consider the behavior that a lot of folks trade purely on Twitter news, you can model exploits via thinking how you could compromise the integrity and availability of financial reports that people trade off of (I and A in CIA) by:
- Integrity: if you can get the fake report to get uptake on Twitter on key nodes, "the truth" of a company's finances can be replaced via this false report, as you have a legion of twitter traders following a much smaller legion of key accounts for trading views
- Availability: if you generate enough volume of this fake report vs. the real report, a metric humans use to eval the truth of things is "is it in every newspaper," so you can reduce the availability of the real report as it is drowned out.
And so on... there's definitely real attacks here, but they exist a bit outside of current security models. Very cool area.
"A DoS attack is a denial of service attack where a computer is used to flood a server with TCP and UDP packets. A DDoS attack is where multiple systems target a single system with a DoS attack. The targeted network is then bombarded with packets from multiple locations."
Multiple apps engaged to notify 1 human, multiple systems attack -> single system.... DDoS.