+ All Categories
Home > Technology > [CLASS 2014] Palestra Técnica - Samuel Linares

[CLASS 2014] Palestra Técnica - Samuel Linares

Date post: 25-Jun-2015
Category:
Upload: ti-safe-seguranca-da-informacao
View: 95 times
Download: 0 times
Share this document with a friend
Description:
Título da Palestra: Ligando proteção da infraestrutura crítica e segurança cibernética industrial: Existe uma Cyber-Tsunami na espera?
Popular Tags:
42
1 Linking Critical Infrastructure Protection and Industrial Cybersecurity: Is there a Cyber-Tsunami in waiting? Samuel Linares Industrial Cybersecurity Center (CCI) Director
Transcript
Page 1: [CLASS 2014] Palestra Técnica - Samuel Linares

1

Linking Critical

Infrastructure Protection

and Industrial

Cybersecurity: Is there a

Cyber-Tsunami in waiting?

Samuel LinaresIndustrial Cybersecurity Center (CCI)

Director

Page 2: [CLASS 2014] Palestra Técnica - Samuel Linares
Page 3: [CLASS 2014] Palestra Técnica - Samuel Linares
Page 4: [CLASS 2014] Palestra Técnica - Samuel Linares

Earthquake Research Institute, University of Tokyo

1960 Chile Great Earthquake Mw9.5

1964 Alaska Earthquake Mw 9.2

1957 Andreanof Islands Earthquaker Mw9.1

1952 Kamchatka Earthquake Mw9.0

2011 East Japan Great Earthquake Mw 9.0

2004 Indian Ocean Earthquake Mw9.0

2010 Chile Earthquake Mw8.8

Page 5: [CLASS 2014] Palestra Técnica - Samuel Linares

Changing

Environment?

Page 6: [CLASS 2014] Palestra Técnica - Samuel Linares

Convergence

Page 7: [CLASS 2014] Palestra Técnica - Samuel Linares

Consequences: Intangible

Web Portal unavailable

No email

Consequences: Tangible, Concrete

Production Losses

Environmental Damages

Public Health

Lower Company Valuation

Physical & Cyber Worlds Convergence

Page 8: [CLASS 2014] Palestra Técnica - Samuel Linares

8

IT in the Industrial World

Convergence

Page 9: [CLASS 2014] Palestra Técnica - Samuel Linares

IT in the Industrial World

Industrial devices have inherited

all problems from IT

Industrial Control

Systems are NOT

isolated anymore.

They have moved

from using

dedicated serial

lines to Ethernet or

WiFi

Now, most of

industrial protocols

are running over

TCP/IP

Industrial Control

Systems use general

purpose operating

systems

Page 10: [CLASS 2014] Palestra Técnica - Samuel Linares

10

IT in the Industrial World

Convergence

Different Cultures

Page 11: [CLASS 2014] Palestra Técnica - Samuel Linares

Plant vs IT vs Security

Plant / IT Conflict:

– “Watertight” environments. “Don’t get

into my lot, and I won’t into yours”

– Attention is not paid to communication

interfaces between both worlds

– Connection interfaces are no man’s land,

and many times, unknown (others

WWW… Wild Wild West ☺)

Page 12: [CLASS 2014] Palestra Técnica - Samuel Linares

12

IT in the Industrial World

Convergence

Different Cultures

¿Security?

Page 13: [CLASS 2014] Palestra Técnica - Samuel Linares

¿Cyber Security?Industrial Safety

Physical Security

Environmental

Safety

SECURITY

Page 14: [CLASS 2014] Palestra Técnica - Samuel Linares

14

Stuxnet

Page 15: [CLASS 2014] Palestra Técnica - Samuel Linares

Stuxnet

Page 16: [CLASS 2014] Palestra Técnica - Samuel Linares

16

Project Basecamp

& Project Robus

Page 17: [CLASS 2014] Palestra Técnica - Samuel Linares

Project Basecamp

SCADA Security

Scientific

Symposium (S4)

Page 18: [CLASS 2014] Palestra Técnica - Samuel Linares

18

Project Robus: Master Serial Killer

• Objective: Analysis of Implementation of

Industrial Protocols (First: DNP3)

• DNP3: 15 advisories, 28 tickets reported

• Fuzzing techniques

• All devices analyzed vulnerables: only 2 ok!

• Implementaciones se limitan a garantizar

funcionalidad, pero no la seguridad

• Hundreds of thousands vulnerable devices:

much of them connected to Internet

Page 19: [CLASS 2014] Palestra Técnica - Samuel Linares

19

Smart Grid and

Internet of Things are coming…

Page 20: [CLASS 2014] Palestra Técnica - Samuel Linares

Smart Grid

Page 21: [CLASS 2014] Palestra Técnica - Samuel Linares

Internet de las CosasInternet of Things

Page 22: [CLASS 2014] Palestra Técnica - Samuel Linares

22

Cybersecurity

Strategies and Regulations

Page 23: [CLASS 2014] Palestra Técnica - Samuel Linares

European Cyber Security Strategy

CYBERSECURITY

FRAMEWORK

CIP Regulations

Page 24: [CLASS 2014] Palestra Técnica - Samuel Linares

24

Shodan

Page 25: [CLASS 2014] Palestra Técnica - Samuel Linares

Shodan (www.shodanhq.com)

• Internet search engine that indexes internet-

connected services response (FTP, SSH, Telnet,

HTTP, HTTPS, SNMP, uPNP, SMB…)

• Provide cccess to millions of Internet-

connected devices

Page 26: [CLASS 2014] Palestra Técnica - Samuel Linares

26

Page 27: [CLASS 2014] Palestra Técnica - Samuel Linares

27

Page 28: [CLASS 2014] Palestra Técnica - Samuel Linares

28

Page 29: [CLASS 2014] Palestra Técnica - Samuel Linares

Internet-facing

Industrial Systems+2.000.000Located in

United States30%ISP’s Dynamic

Addresses80%

Project SHINESHodan INtelligence Extraction

Page 30: [CLASS 2014] Palestra Técnica - Samuel Linares

30

Shodan

Demo

Page 31: [CLASS 2014] Palestra Técnica - Samuel Linares
Page 32: [CLASS 2014] Palestra Técnica - Samuel Linares
Page 33: [CLASS 2014] Palestra Técnica - Samuel Linares

33

Page 34: [CLASS 2014] Palestra Técnica - Samuel Linares

34

Page 35: [CLASS 2014] Palestra Técnica - Samuel Linares

35

Who's Really Attacking

our ICS Devices?

Page 36: [CLASS 2014] Palestra Técnica - Samuel Linares

• ONLY attacks that were targeted

• ONLY attempted modification of

pump system

• ONLY attempted modification via

Modbus/DNP3

• DoS/DDoS were considered attacks

Kyle Wilhoit

(Trendmicro)

Page 37: [CLASS 2014] Palestra Técnica - Samuel Linares

…on the look-out

Page 38: [CLASS 2014] Palestra Técnica - Samuel Linares
Page 39: [CLASS 2014] Palestra Técnica - Samuel Linares
Page 40: [CLASS 2014] Palestra Técnica - Samuel Linares

RRRR

“C3R: Collaboration, Coordination and Commitment based

Relationships”

Collaboration

CoordinationCommitment

Page 41: [CLASS 2014] Palestra Técnica - Samuel Linares
Page 42: [CLASS 2014] Palestra Técnica - Samuel Linares

Industrial Cyber Security

Tsunami is here…

Will you keep

watching?

Thank youSamuel Linares - @infosecmanblog – [email protected]


Recommended