Top Banner
SCADA Hacking for Dummies Piotr Linke Security Engineer for EE
16

SCADA Hacking for Dummies - PROIDEAdata.proidea.org.pl/confidence/9edycja/materialy/prezentacje... · SCADA Hacking for Dummies ... #1 in IPS Detection by NSS Labs (96.7% default)

May 29, 2018

Download

Documents

doanthuy
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: SCADA Hacking for Dummies - PROIDEAdata.proidea.org.pl/confidence/9edycja/materialy/prezentacje... · SCADA Hacking for Dummies ... #1 in IPS Detection by NSS Labs (96.7% default)

SCADA Hacking for Dummies

Piotr Linke

Security Engineer for EE

Page 2: SCADA Hacking for Dummies - PROIDEAdata.proidea.org.pl/confidence/9edycja/materialy/prezentacje... · SCADA Hacking for Dummies ... #1 in IPS Detection by NSS Labs (96.7% default)

2

Who doesn’t like these conferences!? my wife…

Page 3: SCADA Hacking for Dummies - PROIDEAdata.proidea.org.pl/confidence/9edycja/materialy/prezentacje... · SCADA Hacking for Dummies ... #1 in IPS Detection by NSS Labs (96.7% default)

3

Agenda

● Snort and Sourcefire

● What we should know about SCADA

● SCADA model for our demo

● Live presentation

● Two words about the NextGen IPS

Page 4: SCADA Hacking for Dummies - PROIDEAdata.proidea.org.pl/confidence/9edycja/materialy/prezentacje... · SCADA Hacking for Dummies ... #1 in IPS Detection by NSS Labs (96.7% default)

4

About Sourcefire

● Founded in 2001 by Snort Creator,

Martin Roesch, CTO

● Polska: Krzysztof Rocki, Michał Ceklarz

● FY2010 Revenue: $130.6M

● 12 offices worldwide, 380 employees

● Over 4000

commercial/enterprise/government

customers

● #1 in IPS Detection by NSS Labs

(96.7% default)

● Recognized by Forbes as Fastest-

Growing company in Security (2011)

● NASDAQ: FIRE

Page 5: SCADA Hacking for Dummies - PROIDEAdata.proidea.org.pl/confidence/9edycja/materialy/prezentacje... · SCADA Hacking for Dummies ... #1 in IPS Detection by NSS Labs (96.7% default)

5

SCADA

● Supervisory Control And Data Acquisition

▸ Evolved from analog signaling from the past into TCP/IP based signaling:

● Human maintained

● Leased telephone line

● Circuit switched lines

● Packet Switched lines

Page 6: SCADA Hacking for Dummies - PROIDEAdata.proidea.org.pl/confidence/9edycja/materialy/prezentacje... · SCADA Hacking for Dummies ... #1 in IPS Detection by NSS Labs (96.7% default)

6

SCADA’s connectivity

● Modbus TCP

IP

TCP

Function code – reading/writing coils/registers

Address - offset into register list

Length - number of bits and coils

Data – what you want to put to the device

UnitID – which unit under the same IP address

Page 7: SCADA Hacking for Dummies - PROIDEAdata.proidea.org.pl/confidence/9edycja/materialy/prezentacje... · SCADA Hacking for Dummies ... #1 in IPS Detection by NSS Labs (96.7% default)

7

SCADA

● Functions and elements

▸ Data Acquisition:

● sensors (digital ‘on’ and ‘off’ or analog ‘how much?’)

● relays

▸ Data Communication:

● Comm. Networks

▸ Data Presentation:

● Remote Terminal Unit – RTU

● Historian used for storage

▸ Control:

● Programmable Logic Controller – PLC

● Human-Machine Interface – HMI

● Supervisory Computer System - SCS

Page 8: SCADA Hacking for Dummies - PROIDEAdata.proidea.org.pl/confidence/9edycja/materialy/prezentacje... · SCADA Hacking for Dummies ... #1 in IPS Detection by NSS Labs (96.7% default)

8

SCADA model

Data Acquisition Data Comm. Data Presentation Data Control

Sensors/Relays Cables/Radio RTU/Historian PLC/HMI/SCS

Page 9: SCADA Hacking for Dummies - PROIDEAdata.proidea.org.pl/confidence/9edycja/materialy/prezentacje... · SCADA Hacking for Dummies ... #1 in IPS Detection by NSS Labs (96.7% default)

9

Our SCADA model

Alarm Interlocks

Cooling

System Dehumidifier

RTU

&

PLC

Sourcefire IPS

&

Attacker

Page 10: SCADA Hacking for Dummies - PROIDEAdata.proidea.org.pl/confidence/9edycja/materialy/prezentacje... · SCADA Hacking for Dummies ... #1 in IPS Detection by NSS Labs (96.7% default)

Demonstration Time!

Page 11: SCADA Hacking for Dummies - PROIDEAdata.proidea.org.pl/confidence/9edycja/materialy/prezentacje... · SCADA Hacking for Dummies ... #1 in IPS Detection by NSS Labs (96.7% default)

11

Real world example

Page 12: SCADA Hacking for Dummies - PROIDEAdata.proidea.org.pl/confidence/9edycja/materialy/prezentacje... · SCADA Hacking for Dummies ... #1 in IPS Detection by NSS Labs (96.7% default)

12

Open Source Snort

• Global IDS/IPS standard

• Largest community contributing to atack detection rules

• Easy to integrate

• Ran in parallel with Sourcefire

• Global Portal www.snort.org

Page 13: SCADA Hacking for Dummies - PROIDEAdata.proidea.org.pl/confidence/9edycja/materialy/prezentacje... · SCADA Hacking for Dummies ... #1 in IPS Detection by NSS Labs (96.7% default)

13

Next-Gen IPS – The Power of Awareness

Behavior

Detect anomalies in configuration, connections and data flow

Network

Know what’s there, what’s vulnerable, and what’s under attack

Application

Identify change and enforce policy on hundreds of applications

Identity

Know who is doing what, with what, and where

Page 14: SCADA Hacking for Dummies - PROIDEAdata.proidea.org.pl/confidence/9edycja/materialy/prezentacje... · SCADA Hacking for Dummies ... #1 in IPS Detection by NSS Labs (96.7% default)

14

Next-Generation IPS

Defense Center

Intrusion Prevention

SSL Inspection Virtualisation

Awareness technologies

Networks Apps Behavior Users

Page 15: SCADA Hacking for Dummies - PROIDEAdata.proidea.org.pl/confidence/9edycja/materialy/prezentacje... · SCADA Hacking for Dummies ... #1 in IPS Detection by NSS Labs (96.7% default)

15

NSS Labs report May 2011

Page 16: SCADA Hacking for Dummies - PROIDEAdata.proidea.org.pl/confidence/9edycja/materialy/prezentacje... · SCADA Hacking for Dummies ... #1 in IPS Detection by NSS Labs (96.7% default)

www.linkedin.com

Chrumkarnia – Snort PL