Industrial Control System Security Overview Peter Maynard, PhD - - PowerPoint PPT Presentation

industrial control system security overview
SMART_READER_LITE
LIVE PREVIEW

Industrial Control System Security Overview Peter Maynard, PhD - - PowerPoint PPT Presentation

Industrial Control System Security Overview Peter Maynard, PhD Researcher # ?? @CSIT_QUB What is ICS and SCADA Industrial Control Systems (ICS): Chemical, water, gas processing. Transportation, electricity, nuclear systems.


slide-1
SLIDE 1

# ?? @CSIT_QUB

Industrial Control System Security Overview

Peter Maynard, PhD Researcher

slide-2
SLIDE 2

What is ICS and SCADA

  • Industrial Control Systems (ICS):
  • Chemical, water, gas processing.
  • Transportation, electricity, nuclear systems.
  • Supervisory Control And Data Acquisition (SCADA):
  • SCADA provides remote telemetry control for ICS.
slide-3
SLIDE 3

Security Threats to ICS

  • ICS systems have a 40 year life span.
  • Used to use fjrewall air-gapping to separate

the networks.

  • Systems often left un-patched due to system

maintainability concerns.

  • SCADA protocols developed in the 70s-80s

still widely in use.

  • Provide no form of encryption or authenticity.

Not implemented in industry.

slide-4
SLIDE 4

What we have been working on

  • European FP7 Project.
  • Worked with Linz Strom GmbH.

Austrian Electrical Distribution Operator.

  • Access to real world testbed.
slide-5
SLIDE 5

Man-In-The-Middle Attack

  • Using our custom Ettercap plugin we’re

able to hide an earth fault from the

  • perator.
  • Using ARP Spoofjng.
  • Packet manipulation.
slide-6
SLIDE 6

Detection of attacks on ICS

  • Current signature based systems, SNORT, Bro.

Unable to detect Zero day.

Unable to identify suspicious traffjc. e.g. malware, backdoors

  • Anomaly Detection using Machine Learning.

ICS networks are fairly consistent and predictable.

slide-7
SLIDE 7

Questions ?