The Sum of All Fears - When ICS - SCADA Are Compromised
Hack In The Box Security Conference via YouTube
Overview
Syllabus
Intro
Outline
What is Industrial Control System, ICS?
Purdue Enterprise Reference Architecture, PERA
Common ICS Architecture
ICS Operation
Programmable Logic Controller, PLC
Human Machine Interface. HMI
2015 Ukraine Power Grid Cyber Attack
2017 Triton/Trisis Malware Attack
2018 Taiwan Semiconductor Factory Malware Attack
The ICS Vulnerabilities from NVD
Threat Hunting with PLC Honeypot
ICS Protocols in Shodan
ICS Attack Vectors(1/2)
Communication Protocol Attack
Hacking Path
Remote Stop PLC with M Protocol
Command Injection
Common Flaws in ICS Protocols
Exploit FTP Service-Upload malicious plc program file to
Fortification for OT Cyber Defense: Defense in Depth
Taught by
Hack In The Box Security Conference