industrial control system security overview
play

Industrial Control System Security Overview Peter Maynard, PhD - PowerPoint PPT Presentation

Industrial Control System Security Overview Peter Maynard, PhD Researcher # ?? @CSIT_QUB What is ICS and SCADA Industrial Control Systems (ICS): Chemical, water, gas processing. Transportation, electricity, nuclear systems.


  1. Industrial Control System Security Overview Peter Maynard, PhD Researcher # ?? @CSIT_QUB

  2. What is ICS and SCADA • Industrial Control Systems (ICS): • Chemical, water, gas processing. • Transportation, electricity, nuclear systems. • Supervisory Control And Data Acquisition (SCADA): • SCADA provides remote telemetry control for ICS.

  3. Security Threats to ICS ICS systems have a 40 year life span. ● Used to use fjrewall air-gapping to separate ● the networks. Systems often left un-patched due to system ● maintainability concerns. SCADA protocols developed in the 70s-80s ● still widely in use. Provide no form of encryption or authenticity. ● Not implemented in industry. –

  4. What we have been working on • European FP7 Project. • Worked with Linz Strom GmbH. Austrian Electrical Distribution – Operator. • Access to real world testbed.

  5. Man-In-The-Middle Attack Using our custom Ettercap plugin we’re ● able to hide an earth fault from the operator. Using ARP Spoofjng. ● Packet manipulation. ●

  6. Detection of attacks on ICS • Current signature based systems, SNORT, Bro. Unable to detect Zero day. – Unable to identify suspicious traffjc. e.g. malware, backdoors – • Anomaly Detection using Machine Learning. ICS networks are fairly consistent and predictable. –

  7. Questions ?

Download Presentation
Download Policy: The content available on the website is offered to you 'AS IS' for your personal information and use only. It cannot be commercialized, licensed, or distributed on other websites without prior consent from the author. To download a presentation, simply click this link. If you encounter any difficulties during the download process, it's possible that the publisher has removed the file from their server.

Recommend


More recommend