The Ignorance towards Embedded Systems - - PowerPoint PPT Presentation

the ignorance towards embedded systems felix fx lindner
SMART_READER_LITE
LIVE PREVIEW

The Ignorance towards Embedded Systems - - PowerPoint PPT Presentation

The Ignorance towards Embedded Systems Felix FX Lindner, Fabian fabs Yamaguchi, Recurity Labs GmbH 22 nd FIRST Conference, Miami Your Other Network


slide-1
SLIDE 1
  • The Ignorance towards

Embedded Systems

Felix ‘FX’ Lindner, Fabian ‘fabs’ Yamaguchi, Recurity Labs GmbH 22nd FIRST Conference, Miami

slide-2
SLIDE 2
  • Your Other Network
slide-3
SLIDE 3
  • !
  • "

#$%& '"(

  • )
  • !!
  • A Matter of Perspective
slide-4
SLIDE 4
  • *

%'(

+!!,- !

+,- !

.*/ .*/ / !* !

A Matter of Perspective

slide-5
SLIDE 5
  • A Matter of Perspective
  • )
  • "$0"
  • #+
  • 1
  • #"
  • 23
  • 43%
  • %
slide-6
SLIDE 6
  • %

$* $ +

5!

!* !/ !6

#1

  • $+ !

#+!#1! !

Known Attacks in Enterprise Networks

slide-7
SLIDE 7
  • %!

! 1!!

%*!0 1

4!'66"++ ( '66%7/!( !/8 /!'66)(

Known Attacks in Enterprise Networks

slide-8
SLIDE 8

!" #$ 96 +

  • 1
  • "*9::!
  • %

5*,- !

;6 .

  • !

Known Attacks in Enterprise Networks

slide-9
SLIDE 9
  • )!5!

)1

!5!!

  • !

58

+!*55

,- +5

Known Attacks in Enterprise Networks

slide-10
SLIDE 10

%&&"

  • "$0"

"$!,- !!

2

",- !!!*!

  • %"$0"!

%! "$0"!

  • !5;::<

=%2'%2(!

  • "*
  • Known Attacks in Enterprise Networks
slide-11
SLIDE 11

' ()

  • #!

!

#! +!5!

  • " "%55

#!" #8*!5 !

  • 2/*#
  • Known Attacks in Enterprise Networks
slide-12
SLIDE 12

' ()

  • #!

!

#! +!5!

  • " "%55

#!" #8*!5 !

  • 2/*#
  • Known Attacks in Enterprise Networks
  • !"""""#$#"%

%&$'$$&'$ &$'$$&'$ &$'$$&'$ &$'$$&'$%

slide-13
SLIDE 13

* )1#>7:?! !!!@)

  • @)

!!

!@) !

  • )88!A9::15

Known Attacks in Enterprise Networks

>B96;-* 4 ;6:*.*;::C

slide-14
SLIDE 14

* )1#>7:?! !!!@)

  • @)

!!

!@) !

  • )88!A9::15

Known Attacks in Enterprise Networks

>B96;-* 4 ;6:*.*;::C

slide-15
SLIDE 15

'(&

  • #"
  • %#"#1
  • #"!!!

5

66!!+4+' (

  • !
  • #"D'66E(3%1
  • *#"
  • $>

Known Attacks in Enterprise Networks

>=0066000F:F0EE;::C:799E6

slide-16
SLIDE 16

(+#+,$

  • 23!

123'66(C:/ *!

  • %23!

!!5 !*!! !'66 (!

  • 23#"

!23!!

  • !23!!
  • !E
  • #!!23!!

Known Attacks in Enterprise Networks

slide-17
SLIDE 17

" !5'( !

8!"+

+

1 *

  • !*
  • 8"+

Known Attacks in Enterprise Networks

slide-18
SLIDE 18
  • +!

+

  • *E*;::;

)! !

  • ";::G*2H 5!
  • 35. I

! $ Known Attacks in Enterprise Networks

slide-19
SLIDE 19
  • Known Attacks in Enterprise Networks
slide-20
SLIDE 20
  • Known Attacks in Enterprise Networks
slide-21
SLIDE 21
  • Known Attacks in Enterprise Networks

( ( )&$'$$&$*%$+ ,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,, !- . / 0 0 !/0 1221"12#1"12*# !&''&$34$$$ !!"""%" ! !!""" !&$$4%'$%$1 !56"( "% ,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,, .'!- 7 %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%% 6/ 0 1221"12#1"12#*( 899: ! 9;( ; ; ( 9 (;< = 9>?@9 -

slide-22
SLIDE 22
  • .

$!! 15

+,- 15

! !E

"

+E 15'(

Known Attacks in Enterprise Networks

slide-23
SLIDE 23

/,0(

  • 43!!
  • 43

"/5 43

  • 43!*

!

!5 !43!

  • +

Known Attacks in Enterprise Networks

slide-24
SLIDE 24

/,0(

  • 43!!
  • 43

"/5 43

  • 43!*

!

!5 !43!

  • +

Known Attacks in Enterprise Networks

<( % (%&$'$%$$' A%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%A B B B B%%%%%%%%%%%%%%%%%%%%%%A%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%B B( B3*C . B B%%%%%%%%%%%%%%%%%%%%%%A%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%B BD B5 (B B%%%%%%%%%%%%%%%%%%%%%%A%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%B B( BC B B%%%%%%%%%%%%%%%%%%%%%%A%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%B B( B B B%%%%%%%%%%%%%%%%%%%%%%A%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%B B E BDB B%%%%%%%%%%%%%%%%%%%%%%A%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%B BC FB'&"$3"$4B B%%%%%%%%%%%%%%%%%%%%%%A%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%B BC - B B B%%%%%%%%%%%%%%%%%%%%%%A%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%B B FB$&"$3"'$B B%%%%%%%%%%%%%%%%%%%%%%A%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%B BG? FB6 &&$'$B B%%%%%%%%%%%%%%%%%%%%%%A%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%B B

  • B5. ) 5F +B

B%%%%%%%%%%%%%%%%%%%%%%A%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%B B.DB.%&$'$%$HH'B A%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%A A%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%A B5 B 3* ( B BB 675 B BB (5 B BB B BB 675 (5B BB B A%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%A

slide-25
SLIDE 25

0" & 8

+* +!!

  • +J!!!

)"%22D2 %!.%.

  • J

Known Attacks in Enterprise Networks

slide-26
SLIDE 26

+ "!(1 +)"% +/ 2

!

%!2

")"% )!,- 5

Known Attacks in Enterprise Networks

slide-27
SLIDE 27

!2 / "!

$!#

!5*

,!- !>

!!! !;;<! )!!/ ++5 )!!/ ! Known Attacks in Enterprise Networks

>=00660;:9:0:90;C0E!E!0

slide-28
SLIDE 28

!2 / "!

$!#

!5*

,!- !>

!!! !;;<! )!!/ ++5 )!!/ ! Known Attacks in Enterprise Networks

>=00660;:9:0:90;C0E!E!0

slide-29
SLIDE 29

)3

slide-30
SLIDE 30

. . = !@) !

@ @$! How These Attacks Are Used

slide-31
SLIDE 31

4+5 = + )) "

!!!!!'(

@5

4

How These Attacks Are Used

slide-32
SLIDE 32

*. = #" $+0#+) "!

KEEK !!>

How These Attacks Are Used

>=00!!6!60

slide-33
SLIDE 33
slide-34
SLIDE 34

43 !

$'66 $( !*! *E#1!

!

66#))%$L!)

%D $#"

Network Level Protections

slide-35
SLIDE 35
  • 4

EE !!

  • "

$!

Network Level Protections

slide-36
SLIDE 36

(%* .

  • %1

1

.

%8

)1 .

Network Level Protections

slide-37
SLIDE 37

)6 # =

$M "!M !!5!M !!!M "!M

!1

.*8! .!*8!

Policy Level Protections

slide-38
SLIDE 38

+ !M !!N

! +! !!!D!

#

K! !

Policy Level Protections

slide-39
SLIDE 39

(7&). 8

$ D"+ !!! E"+"+ %

"!E"+*

E"+

Policy Level Protections

slide-40
SLIDE 40

)" %

!

!!!!

"! 8

!!!

) 4!!!!!

!5

+!

Patching Embedded Systems

slide-41
SLIDE 41

83 !!

,!1!-

)!!

  • !

!

!!

!

+/! "/*/!!!

Patching Embedded Systems

slide-42
SLIDE 42
slide-43
SLIDE 43
  • +
  • +

" "

  • 5

)8!8 )8!!

  • )D

+ Your Other Network

slide-44
SLIDE 44

)9 Questions? Felix ‘FX’ Lindner, Fabian ‘fabs’ Yamaguchi, Recurity Labs GmbH