Hacking Chemical Plants for Competition and Extortion
Hack In The Box Security Conference via YouTube
Overview
Syllabus
Intro
Industrial Control Systems aka SCADA
Cyber-physical systems
Cyber-physical hack
Control equipment vulnerabilities
ICS-CERT recommendation
TCP/IP based communication
Hear is the plant. What is the plan?
Timing of the DoS attack
Impact evaluation
Process control automation
PLC Internals
Control logic
Interlocks
PID control
Time constants
Process control vulnerability
PLC cannot do it alone
Operator is not almighty
Why to attack ICS
Attack payload
What can be done to the process
Attack considerations
Production damage attack
Plants for sale
Hacking Chemical Plant for Competition & Extortion
Stages of SCADA attack
Traditional IT hacking
Modern IT hacking
Know the equipment
Process discovery
Espionage
Max economic damage?
Understanding control structure
Control loop configuration
Understanding points and logic
Physics of process control
Process interdependencies
Understanding process response
Control loop ringing
Process control challenges
Types of attacks
Outcome of the control stage
Alarm propagation
Fingerprints of plant dynamic behavior
How to break things?
Catalyst killers
Hacker unfriendly process
Measuring the process
Technician vs. engineer
Technician answer
Quest for engineering answer
Outcome of the damage stage
Creating forensics footprint
Defeating chemical forensics
Data synchronization and processing
Taught by
Hack In The Box Security Conference