Top Banner
Measuring the Cyber-exposure on Todays Modern assets Abdelnaser Eid Security Consultant [email protected]
23

Measuring the Cyber-exposure on Todays Modern …(2012, 2016) Hackers steal Calpine Corp’s critical power plant design and system passwords (2013-15) Havex & Dragonfly information

Jul 22, 2020

Download

Documents

dariahiddleston
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Measuring the Cyber-exposure on Todays Modern …(2012, 2016) Hackers steal Calpine Corp’s critical power plant design and system passwords (2013-15) Havex & Dragonfly information

Measuring the Cyber-exposure on Todays Modern assets

Abdelnaser Eid Security Consultant [email protected]

Page 2: Measuring the Cyber-exposure on Todays Modern …(2012, 2016) Hackers steal Calpine Corp’s critical power plant design and system passwords (2013-15) Havex & Dragonfly information

VirtualThe move from tin every time to virtual first, created dynamic environments

CloudCritical infrastructure starts to migrate to the Cloud reduces cost but impacts security’s control

IoT/OTEverything has an IP. Heavy industry exposed to everyday IT risks.

ContainersDevOps decreases the time to delivery for IT services but increases the lack of visibility

The Attack Surface is Changing

Traditional ITDeploying a new server involved a phone call and a screwdriver

Page 3: Measuring the Cyber-exposure on Todays Modern …(2012, 2016) Hackers steal Calpine Corp’s critical power plant design and system passwords (2013-15) Havex & Dragonfly information

Static &Accessible

Ephemeral &Immutable

Page 4: Measuring the Cyber-exposure on Todays Modern …(2012, 2016) Hackers steal Calpine Corp’s critical power plant design and system passwords (2013-15) Havex & Dragonfly information

Operations capability to deploy has surpassed Security’s ability to identify and assess…

Page 5: Measuring the Cyber-exposure on Todays Modern …(2012, 2016) Hackers steal Calpine Corp’s critical power plant design and system passwords (2013-15) Havex & Dragonfly information

Controlled Assets

Cyber Exposure

Connected Assets

Page 6: Measuring the Cyber-exposure on Todays Modern …(2012, 2016) Hackers steal Calpine Corp’s critical power plant design and system passwords (2013-15) Havex & Dragonfly information

The larger the Cyber Exposure Gap, the greater the odds a business impacting cyber event will occur.

Page 7: Measuring the Cyber-exposure on Todays Modern …(2012, 2016) Hackers steal Calpine Corp’s critical power plant design and system passwords (2013-15) Havex & Dragonfly information
Page 8: Measuring the Cyber-exposure on Todays Modern …(2012, 2016) Hackers steal Calpine Corp’s critical power plant design and system passwords (2013-15) Havex & Dragonfly information

Physical Process

Direct Control

Plant Supervisory

Site Operations &Production Control

Corporate LAN: ERP &Production Scheduling

Enterprise Network

SCADA Monitor

ControlCenter Inventory IT ServicesScheduling

Plant Plant0

1

2

3

4

5

µC PLC

HMI Alarm

Historian WorkstationCoordinatingcomputers

RTU

RTU

DMZ

IT Attack Vectors

OT Attack Vectors

Critical Infrastructure

at risk

Shamoon, AKA Distrack, wipes 35k workstations (2012, 2016)

Hackers steal Calpine Corp’s critical power plant design and system passwords (2013-15)

Havex & Dragonfly information theft (2014)

Australia Dept. of Resources and Energy Project files hacked (2015)

Stuxnet sabotages Iranian Nuclear facilities ( 2010)

Industroyer/ Crash Override shuts down Ukranian power grid (2015, 2016)

German Steel Mill Blast furnace disrupted causing massive damage

Page 9: Measuring the Cyber-exposure on Todays Modern …(2012, 2016) Hackers steal Calpine Corp’s critical power plant design and system passwords (2013-15) Havex & Dragonfly information

INDUSTRIAL SYSTEMS REQUIRE A“DO NO HARM” APPROACH TOGATHERING DATA

Page 10: Measuring the Cyber-exposure on Todays Modern …(2012, 2016) Hackers steal Calpine Corp’s critical power plant design and system passwords (2013-15) Havex & Dragonfly information

ANYTHING WITH AN IP STACK CAN BE VULNERABLE AND LEVERAGED FOR AN ATTACK

Page 11: Measuring the Cyber-exposure on Todays Modern …(2012, 2016) Hackers steal Calpine Corp’s critical power plant design and system passwords (2013-15) Havex & Dragonfly information

MS17-010AKA ETERNALBLUE

https://blogs.technet.microsoft.com/msrc/2017/05/12/customer-guidance-for-wannacrypt-attacks/

Released by Microsoft - March 14th 2017

Page 12: Measuring the Cyber-exposure on Todays Modern …(2012, 2016) Hackers steal Calpine Corp’s critical power plant design and system passwords (2013-15) Havex & Dragonfly information

PATCHPROTECTOR PAY

Page 13: Measuring the Cyber-exposure on Todays Modern …(2012, 2016) Hackers steal Calpine Corp’s critical power plant design and system passwords (2013-15) Havex & Dragonfly information

500,000+Dockerized apps on Hub

8 BillionContainer Downloads

Page 14: Measuring the Cyber-exposure on Todays Modern …(2012, 2016) Hackers steal Calpine Corp’s critical power plant design and system passwords (2013-15) Havex & Dragonfly information

IN ONE YEAR

DOCKER ADOPTION

UP 40%

Page 15: Measuring the Cyber-exposure on Todays Modern …(2012, 2016) Hackers steal Calpine Corp’s critical power plant design and system passwords (2013-15) Havex & Dragonfly information

AT A TIME

HOSTS RUNSEVENCONTAINERS

Page 16: Measuring the Cyber-exposure on Todays Modern …(2012, 2016) Hackers steal Calpine Corp’s critical power plant design and system passwords (2013-15) Havex & Dragonfly information
Page 17: Measuring the Cyber-exposure on Todays Modern …(2012, 2016) Hackers steal Calpine Corp’s critical power plant design and system passwords (2013-15) Havex & Dragonfly information

ACTI

VE

SCA

NN

ING

HOW VULNERABLE

ARE CONTAINERS?

Page 18: Measuring the Cyber-exposure on Todays Modern …(2012, 2016) Hackers steal Calpine Corp’s critical power plant design and system passwords (2013-15) Havex & Dragonfly information

Named VulnerabilitiesDROWN673

Containers with CVE-2016-0800

HEARTBLEED359

Containers withCVE-2014-0160

IMAGETRAGICK119

Containers withCVE-2016-3714

POODLE61

Containers withCVE-2014-3566

SHELLSHOCK59

Containers withCVE-2014-6271

GHOST53

Containers withCVE-2015-0235

Page 19: Measuring the Cyber-exposure on Todays Modern …(2012, 2016) Hackers steal Calpine Corp’s critical power plant design and system passwords (2013-15) Havex & Dragonfly information

THE EARLIER YOU DETECT A VULNERABILITY IN THE DEVELOPMENT LIFECYCLE, THE EASIER IT IS TO ADDRESS.

Page 20: Measuring the Cyber-exposure on Todays Modern …(2012, 2016) Hackers steal Calpine Corp’s critical power plant design and system passwords (2013-15) Havex & Dragonfly information

FOCUS ON THEFOUNDATIONAL

4

Page 21: Measuring the Cyber-exposure on Todays Modern …(2012, 2016) Hackers steal Calpine Corp’s critical power plant design and system passwords (2013-15) Havex & Dragonfly information

Advanced technology for complete visibility

Industrial IoT

ICS/SCADA

Enterprise IoT

Network infrastructure

Servers

Desktop

Virtual machine

Laptop

Mobile

Web app

Cloud

Container

Active

ScanningAgentScanning

Passive

MonitoringImageRegistry

Page 22: Measuring the Cyber-exposure on Todays Modern …(2012, 2016) Hackers steal Calpine Corp’s critical power plant design and system passwords (2013-15) Havex & Dragonfly information

IF YOU ARE FLYING BLIND TO A WIDENING CYBER EXPOSURE GAP ON TODAYS EPHEMERAL

AND IMMUTABLE ASSETS

THAT'S JUST UNTENABLE.TENABLE.

Page 23: Measuring the Cyber-exposure on Todays Modern …(2012, 2016) Hackers steal Calpine Corp’s critical power plant design and system passwords (2013-15) Havex & Dragonfly information

tenable.com

www

[email protected]