bsidesaugusta 2015 - how to get into ics security

29
HOW TO GET INTO ICS SECURITY @chrissistrunk

Upload: chris-sistrunk

Post on 12-Feb-2017

1.409 views

Category:

Education


0 download

TRANSCRIPT

Page 1: BSidesAugusta 2015 - How to get into ICS security

HOW TO GET INTO ICS SECURITY@chrissistrunk

Page 2: BSidesAugusta 2015 - How to get into ICS security

About meChris Sistrunk, PEElectrical EngineerSr. ICS Security Consultant

Control system security assessments ICS Village (DEF CON & RSA Conference)

Entergy (11+ years) SCADA Engineer (10 years) Project Robus (ICS Protocol Fuzzing)

30+ implementation vulnerabilities in DNP3 stacks Substation Security Team

BSidesJackson – November 7th

Page 3: BSidesAugusta 2015 - How to get into ICS security

You’re here What excites you about ICS security? Is ICS or security in your job now? Do you want it to be?

Page 4: BSidesAugusta 2015 - How to get into ICS security

Some numbers

Industrial ControlSystem Humans

MANY

Engineers, TechniciansOperators, Vendors,

etc

SecurityHumans~189,000

ICS SecurityHumans<1000

0.5% of Security

Page 5: BSidesAugusta 2015 - How to get into ICS security

Is 0.5% enough to protect CI?

Page 6: BSidesAugusta 2015 - How to get into ICS security

I’m recruiting you for ICS Security

Page 7: BSidesAugusta 2015 - How to get into ICS security

OT Side > ICSsec

Page 8: BSidesAugusta 2015 - How to get into ICS security

Operational Technology You’ve got the engineering or technical

background You know how the plant or process works You probably already work with:

ICS components like PLCs and RTUs ICS protocols like Modbus, Ethernet/IP, DNP3, etc Networking (ethernet, serial, including wireless) NERC/CIP or CFATS requirements

Page 9: BSidesAugusta 2015 - How to get into ICS security

Get familiar with security Learn

Security Conferences! (Thanks IronGeek) SecurityTube Lots and lots of material online Security Training (SANS ICS, Red Tiger,

SCADAhacker) SamuraiSTFU, Kali, Security Onion Linux Distros

Make friends with the IT Security team

Page 10: BSidesAugusta 2015 - How to get into ICS security

Red Bull

Page 11: BSidesAugusta 2015 - How to get into ICS security

Make an ICS Security Lab Many companies with control systems

have labs If not, you may have spare equipment

laying around…get creative!

Page 12: BSidesAugusta 2015 - How to get into ICS security

So…Stuxnet happened

Page 13: BSidesAugusta 2015 - How to get into ICS security

What would be your Stuxnet? Think like a bad guy…with a hard hat! …like an attacker has your prints Who knows…you might find a

vulnerability

“To make things work well, you must break them”

Page 14: BSidesAugusta 2015 - How to get into ICS security

Red Team and Blue Team Learn how to use Metasploit Learn how to watch for Modbus Fuzzing Write some Modbus Snort rules

Page 15: BSidesAugusta 2015 - How to get into ICS security

IT Side > ICSsec

Page 16: BSidesAugusta 2015 - How to get into ICS security

Google all the things Modbus.org > modbus spec Tons of code on github: opendnp3,

modbus, etc Wireshark Pcaps online > Netresec has a library,

SANS, S4

Page 17: BSidesAugusta 2015 - How to get into ICS security

Videos YouTube & Vimeo “SCADA” “Control Systems” “PLC” Conference Talks “How It’s Made” Marathon!

Page 18: BSidesAugusta 2015 - How to get into ICS security

Make an ICS network at home Raspberry Pi

opendnp3, modbus, BACnet Arduino

modbus $15 HMI from eBay

(got lucky) ~$700 for a new

Phoenix Contact PLC

Page 19: BSidesAugusta 2015 - How to get into ICS security

You know security, but not ICS…yet What I am about to tell you is the single

greatest secret to go from IT Security into ICS…

Page 20: BSidesAugusta 2015 - How to get into ICS security

Donuts

Page 21: BSidesAugusta 2015 - How to get into ICS security

Spend time with OT Learn what Engineers, Technicians, or

Operators do in their job Show that you care and that you are

eager to learn Create relationships across the

company/industry

RTFM

Page 22: BSidesAugusta 2015 - How to get into ICS security

Other ICS Security Things

Page 23: BSidesAugusta 2015 - How to get into ICS security

Connect! SCADAsec email list at Infracritical ICS Security Conferences

DigitalBond’s S4 SANS ICS Summit 4SICS EnergySec Oil & Gas Security Summit ICS Cyber Security Conference “Weisscon”

Page 24: BSidesAugusta 2015 - How to get into ICS security

Standards NIST SP800-82 Revision 2 IEC 62443 NERC/CIP CFATS …to name a few

Page 25: BSidesAugusta 2015 - How to get into ICS security

Training ICS-CERT

Free online training and resources Free 5-day Red vs Blue ICS exercise

SANS ICS410 and ICS515 Red Tiger Security, Lofty Perch,

SCADAhacker Vendor Training

Page 26: BSidesAugusta 2015 - How to get into ICS security

Certification There isn’t a Professional Engineering

license for Security...…but not everyone is an engineer.

GICSP is a new certification out to teach IT folks the basics of ICS and OT folks the basics of security.

Page 27: BSidesAugusta 2015 - How to get into ICS security

Links https://ics-cert.us-cert.gov/Standards-and-References http://dx.doi.org/10.6028/NIST.SP.800-82r2 https://scadahacker.com/library/index.html http://www.dhs.gov/dhs-daily-open-source-infrastructure-report http://news.infracritical.com/mailman/listinfo/scadasec http://scadaperspective.com/ http://pen-testing.sans.org/holiday-challenge/2013 http://www.netresec.com/?page=PcapFiles http://

www.giac.org/certification/global-industrial-cyber-security-professional-gicsp

https://www.shodan.io/explore/category/industrial-control-systems

Page 28: BSidesAugusta 2015 - How to get into ICS security

Contact Me Anytime!

[email protected]@chrissistrunk

Page 29: BSidesAugusta 2015 - How to get into ICS security

Ideas? Questions?