<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2enclosuresfull.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:rawvoice="http://www.rawvoice.com/rawvoiceRssModule/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>Digital Bond's SCADA Security Portal</title>
	
	<link>http://www.digitalbond.com</link>
	<description>SCADA Security and Operations IT</description>
	<lastBuildDate>Sat, 18 May 2013 03:49:26 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
<!-- podcast_generator="Blubrry PowerPress/4.0.5" -->
	<itunes:summary>Dale Peterson of Digital Bond interviews industry leaders and comments on the top stories in ICS security in the Unsolicited Response podcast. This is an indepth technical and policy podcast for those interested in SCADA Security, DCS Security, Control System Security, or ICS Security.</itunes:summary>
	<itunes:author>Dale Peterson</itunes:author>
	<itunes:explicit>no</itunes:explicit>
	<itunes:image href="http://digibond.wpengine.netdna-cdn.com/wp-content/plugins/powerpress/itunes_default.jpg" />
	<itunes:owner>
		<itunes:name>Dale Peterson</itunes:name>
		<itunes:email>info@digitalbond.com</itunes:email>
	</itunes:owner>
	<managingEditor>info@digitalbond.com (Dale Peterson)</managingEditor>
	<copyright>Copyright © 2011 Digital Bond, Inc. All Rights Reserved</copyright>
	<itunes:subtitle>Unsolicited Response Podcast</itunes:subtitle>
	<itunes:keywords>SCADA, SCADA Security, ICS, DCS, Control Systems, Stuxnet</itunes:keywords>
	<image>
		<title>Digital Bond's SCADA Security Portal</title>
		<url>http://www.digitalbond.com/wp-content/plugins/powerpress/rss_default.jpg</url>
		<link>http://www.digitalbond.com</link>
	</image>
	<itunes:category text="Technology" />
		<rawvoice:rating>TV-G</rawvoice:rating>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/digitalbond/oLPM" /><feedburner:info uri="digitalbond/olpm" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:emailServiceId>digitalbond/oLPM</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><item>
		<title>Friday News &amp; Notes</title>
		<link>http://feedproxy.google.com/~r/digitalbond/oLPM/~3/Gizi9quX1eQ/</link>
		<comments>http://www.digitalbond.com/blog/2013/05/17/friday-news-notes-74/#comments</comments>
		<pubDate>Sat, 18 May 2013 03:46:29 +0000</pubDate>
		<dc:creator>Dale Peterson</dc:creator>
				<category><![CDATA[Critical Intelligence]]></category>
		<category><![CDATA[Friday News & Notes]]></category>
		<category><![CDATA[SCADA Security News]]></category>

		<guid isPermaLink="false">http://www.digitalbond.com/?p=12256</guid>
		<description><![CDATA[<p><a href="http://digibond.wpengine.netdna-cdn.com/wp-content/uploads/2013/05/Jeremy-Brooks.jpg"></a>Odd and troubling week.</p> <p><a href="http://mobile.reuters.com/article/article/idUSBRE94E11B20130515?irpc=932">DHS Secretary Napolitano announced Enhanced Cybersecurity Services</a> &#8212; the US Government will share information on 0days and threats via a paid service offered by private government contractors like AT&#38;T, Raytheon and Northrup Grumman. This would even include 0days purchased from researchers. Does this make or break the 0day market? How does this compare to a bug bounty? this is so odd it&#8217;s hard to even come up with a cogent argument for or against your tax dollars at work.</p> <p>The <a href="http://csrc.nist.gov/cyberframework/nist-initial-analysis-of-rfi-responses.pdf">US NIST published a document analyzing the request for information (RFI) responses to the upcoming cybersecurity framework</a>. Respondents think it should be flexible, global, risk-based and leverage existing standards. Ok &#8230;</p> <p>NIST issued <a href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-82r1.pdf">Revision 1 of SP800-82 Guide to ICS Security</a>. More importantly they announced an effort for a major update of this document to Revision 2 in the next year.</p> <p>The <a href="http://www.nytimes.com/2013/05/13/us/cyberattacks-on-rise-against-us-corporations.html?_r=2&#38;">NY Times and most other major media vaguely reported on cyber attacks on energy sector companies</a> with the goal of sabotage or control of the ICS. The information is based on a non-public bulletin from ICS-CERT.</p> <p>Anonymous announced Operation Petrol will start on June 20th against &#8220;greedy oil companies&#8221; and governments that support them.</p> <p>The US Security and Exchanges Commission (SEC) reported that t<a href="http://mobile.bloomberg.com/news/2013-05-13/sec-chairman-reviewing-company-cybersecurity-disclosures.html">he 27 largest public companies sustained no major financial losses due to cyber attacks</a>.</p> Tweet of the Week #bbpBox_335287042772705281 a { text-decoration:none; color:#4B1630; }#bbpBox_335287042772705281 a:hover { text-decoration:underline; }the same public that says the <a href="http://twitter.com/search?q=%23nist" title="#nist">#nist</a> cyber security framework should be "risk based" says "baseball should include baseballs" <a href="http://twitter.com/search?q=%23nistcsf" title="#nistcsf">#nistcsf</a> <a href="http://twitter.com/search?q=%23eo" title="#eo">#eo</a><a title='tweeted on 17 May 2013 01:53' href='http://twitter.com/#!/sintixerr/status/335287042772705281' target='_blank'>about 21 hours ago</a> via <a href="http://www.tweetdeck.com" rel="nofollow" target="blank">TweetDeck</a><a href='https://twitter.com/intent/tweet?in_reply_to=335287042772705281' class='bbp-action bbp-reply-action' title='Reply'>Reply</a><a href='https://twitter.com/intent/retweet?tweet_id=335287042772705281' class='bbp-action bbp-retweet-action' title='Retweet'>Retweet</a><a href='https://twitter.com/intent/favorite?tweet_id=335287042772705281' class='bbp-action bbp-favorite-action' title='Favorite'>Favorite</a><a href='http://twitter.com/intent/user?screen_name=sintixerr'></a><a style='font-weight:bold' href='http://twitter.com/intent/user?screen_name=sintixerr'>@sintixerr</a>Jack Whitsitt <p>Don&#8217;t forget to <a href="http://feeds.feedburner.com/digitalbond/oLPM">subscribe to this blog RSS feed</a> and <a href="http://twitter.com/digitalbond">follow @digitalbond.com on twitter</a>.</p> Worth Reading Articles <ul> <li>CIO Magazine article <a href="http://www.forbes.com/sites/ciocentral/2013/05/15/how-to-prepare-for-when-the-sec-comes-asking-about-cybersecurity-risk/">Beware The Coming SEC Regulations on Cybersecurity </a></li> <li>Tom Aldrich post <a href="http://tomalrichblog.blogspot.com/2013/05/meanwhile-back-at-cip-v3-ranch.html?spref=tw">Meanwhile, Back at the (CIP v3) Ranch</a></li> </ul> Critical Intelligence&#8217;s <a href="http://digitalbond.com/scadapedia/ics-security-event-calendar/">ICS Security Event Calendar</a> Updates <ul> <li>ICS Security Session at <a href="https://www.google.com/calendar/render?eid=NGpkZHFkM2FlM3E4YmZoa3E4b25yZWRyMDggY2FsZW5kYXJAY3JpdGljYWwtaW50ZWxsaWdlbmNlLmNvbQ&#38;sf=true&#38;output=xml">Ventyx World</a>, June 11-15 in San Francisco, California</li> <li>UTC <a href="http://www.utc.org/event/2013-critical-infrastructure-communications-policy-summit-700-mhz-workshop">Critical Infrastructure Communications Policy Summit</a>, June 20 in Washington DC</li> <li><a href="http://www.informa.com.au/conferences/energy-utilities/water/scada-conference">Australian National SCADA Conference</a>, Aug 15-16 in Melbourne, Australia</li> </ul> <p><a href="https://www.critical-intelligence.com/">Critical Intelligence</a> provides reports and other information products on  Cyber Situational Awareness and Threat Intelligence services for Industrial Control System Owner/Operators, Vendors and Government stakeholders.</p> <p>Image by ChrisInPlymouth</p> ]]></description>
				<content:encoded><![CDATA[<p><a href="http://digibond.wpengine.netdna-cdn.com/wp-content/uploads/2013/05/Jeremy-Brooks.jpg"><img class="alignleft size-full wp-image-12257" alt="ICS Security News" src="http://digibond.wpengine.netdna-cdn.com/wp-content/uploads/2013/05/Jeremy-Brooks.jpg" width="160" height="240" /></a>Odd and troubling week.</p>
<p><a href="http://mobile.reuters.com/article/article/idUSBRE94E11B20130515?irpc=932">DHS Secretary Napolitano announced Enhanced Cybersecurity Services</a> &#8212; the US Government will share information on 0days and threats via a paid service offered by private government contractors like AT&amp;T, Raytheon and Northrup Grumman. This would even include 0days purchased from researchers. Does this make or break the 0day market? How does this compare to a bug bounty? this is so odd it&#8217;s hard to even come up with a cogent argument for or against your tax dollars at work.</p>
<p>The <a href="http://csrc.nist.gov/cyberframework/nist-initial-analysis-of-rfi-responses.pdf">US NIST published a document analyzing the request for information (RFI) responses to the upcoming cybersecurity framework</a>. Respondents think it should be flexible, global, risk-based and leverage existing standards. Ok &#8230;</p>
<p>NIST issued <a href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-82r1.pdf">Revision 1 of SP800-82 Guide to ICS Security</a>. More importantly they announced an effort for a major update of this document to Revision 2 in the next year.</p>
<p>The <a href="http://www.nytimes.com/2013/05/13/us/cyberattacks-on-rise-against-us-corporations.html?_r=2&amp;">NY Times and most other major media vaguely reported on cyber attacks on energy sector companies</a> with the goal of sabotage or control of the ICS. The information is based on a non-public bulletin from ICS-CERT.</p>
<p>Anonymous announced Operation Petrol will start on June 20th against &#8220;greedy oil companies&#8221; and governments that support them.</p>
<p>The US Security and Exchanges Commission (SEC) reported that t<a href="http://mobile.bloomberg.com/news/2013-05-13/sec-chairman-reviewing-company-cybersecurity-disclosures.html">he 27 largest public companies sustained no major financial losses due to cyber attacks</a>.</p>
<h3>Tweet of the Week</h3>
<!-- tweet id : 335287042772705281 --><style type='text/css'>#bbpBox_335287042772705281 a { text-decoration:none; color:#4B1630; }#bbpBox_335287042772705281 a:hover { text-decoration:underline; }</style><div id='bbpBox_335287042772705281' class='bbpBox' style='padding:20px; margin:5px 0; background-color:#000000; background-image:url(http://a0.twimg.com/profile_background_images/5082282/slgallery3.jpg); background-repeat:no-repeat'><div style='background:#fff; padding:10px; margin:0; min-height:48px; color:#030303; -moz-border-radius:5px; -webkit-border-radius:5px;'><span style='width:100%; font-size:18px; line-height:22px;'>the same public that says the <a href="http://twitter.com/search?q=%23nist" title="#nist">#nist</a> cyber security framework should be "risk based" says "baseball should include baseballs" <a href="http://twitter.com/search?q=%23nistcsf" title="#nistcsf">#nistcsf</a> <a href="http://twitter.com/search?q=%23eo" title="#eo">#eo</a></span><div class='bbp-actions' style='font-size:12px; width:100%; padding:5px 0; margin:0 0 10px 0; border-bottom:1px solid #e6e6e6;'><img align='middle' src='http://digibond.wpengine.netdna-cdn.com/wp-content/plugins/twitter-blackbird-pie//images/bird.png' /><a title='tweeted on 17 May 2013 01:53' href='http://twitter.com/#!/sintixerr/status/335287042772705281' target='_blank'>about 21 hours ago</a> via <a href="http://www.tweetdeck.com" rel="nofollow" target="blank">TweetDeck</a><a href='https://twitter.com/intent/tweet?in_reply_to=335287042772705281' class='bbp-action bbp-reply-action' title='Reply'><span><em style='margin-left: 1em;'></em><strong>Reply</strong></span></a><a href='https://twitter.com/intent/retweet?tweet_id=335287042772705281' class='bbp-action bbp-retweet-action' title='Retweet'><span><em style='margin-left: 1em;'></em><strong>Retweet</strong></span></a><a href='https://twitter.com/intent/favorite?tweet_id=335287042772705281' class='bbp-action bbp-favorite-action' title='Favorite'><span><em style='margin-left: 1em;'></em><strong>Favorite</strong></span></a></div><div style='float:left; padding:0; margin:0'><a href='http://twitter.com/intent/user?screen_name=sintixerr'><img style='width:48px; height:48px; padding-right:7px; border:none; background:none; margin:0' src='http://a0.twimg.com/profile_images/3163480324/18459fa2ac5e09ef6a970fae332cffda_normal.png' /></a></div><div style='float:left; padding:0; margin:0'><a style='font-weight:bold' href='http://twitter.com/intent/user?screen_name=sintixerr'>@sintixerr</a><div style='margin:0; padding-top:2px'>Jack Whitsitt</div></div><div style='clear:both'></div></div></div><!-- end of tweet -->
<p><em>Don&#8217;t forget to <a href="http://feeds.feedburner.com/digitalbond/oLPM">subscribe to this blog RSS feed</a> and <a href="http://twitter.com/digitalbond">follow @digitalbond.com on twitter</a>.</em></p>
<h3>Worth Reading Articles</h3>
<ul>
<li>CIO Magazine article <a href="http://www.forbes.com/sites/ciocentral/2013/05/15/how-to-prepare-for-when-the-sec-comes-asking-about-cybersecurity-risk/">Beware The Coming SEC Regulations on Cybersecurity </a></li>
<li>Tom Aldrich post <a href="http://tomalrichblog.blogspot.com/2013/05/meanwhile-back-at-cip-v3-ranch.html?spref=tw">Meanwhile, Back at the (CIP v3) Ranch</a></li>
</ul>
<h3>Critical Intelligence&#8217;s <a href="http://digitalbond.com/scadapedia/ics-security-event-calendar/">ICS Security Event Calendar</a> Updates</h3>
<ul>
<li>ICS Security Session at <a href="https://www.google.com/calendar/render?eid=NGpkZHFkM2FlM3E4YmZoa3E4b25yZWRyMDggY2FsZW5kYXJAY3JpdGljYWwtaW50ZWxsaWdlbmNlLmNvbQ&amp;sf=true&amp;output=xml">Ventyx World</a>, June 11-15 in San Francisco, California</li>
<li>UTC <a href="http://www.utc.org/event/2013-critical-infrastructure-communications-policy-summit-700-mhz-workshop">Critical Infrastructure Communications Policy Summit</a>, June 20 in Washington DC</li>
<li><a href="http://www.informa.com.au/conferences/energy-utilities/water/scada-conference">Australian National SCADA Conference</a>, Aug 15-16 in Melbourne, Australia</li>
</ul>
<p><a href="https://www.critical-intelligence.com/">Critical Intelligence</a><em> provides reports and other information products on  Cyber Situational Awareness and Threat Intelligence services for Industrial Control System Owner/Operators, Vendors and Government stakeholders.</em></p>
<p><em>Image by ChrisInPlymouth</em></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=Gizi9quX1eQ:gzOK7DIppAc:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=Gizi9quX1eQ:gzOK7DIppAc:-BTjWOF_DHI"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?i=Gizi9quX1eQ:gzOK7DIppAc:-BTjWOF_DHI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=Gizi9quX1eQ:gzOK7DIppAc:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=Gizi9quX1eQ:gzOK7DIppAc:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?i=Gizi9quX1eQ:gzOK7DIppAc:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=Gizi9quX1eQ:gzOK7DIppAc:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?d=qj6IDK7rITs" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/digitalbond/oLPM/~4/Gizi9quX1eQ" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.digitalbond.com/blog/2013/05/17/friday-news-notes-74/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.digitalbond.com/blog/2013/05/17/friday-news-notes-74/</feedburner:origLink></item>
		<item>
		<title>Research and PR and ICSsec Frenzy</title>
		<link>http://feedproxy.google.com/~r/digitalbond/oLPM/~3/FHBklH9SKtM/</link>
		<comments>http://www.digitalbond.com/blog/2013/05/16/research-and-pr-and-icssec-frenzy/#comments</comments>
		<pubDate>Thu, 16 May 2013 15:20:11 +0000</pubDate>
		<dc:creator>Dale Peterson</dc:creator>
				<category><![CDATA[ICS Security Technologies]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[S4]]></category>
		<category><![CDATA[Anomaly Detection]]></category>
		<category><![CDATA[NSF]]></category>

		<guid isPermaLink="false">http://www.digitalbond.com/?p=12253</guid>
		<description><![CDATA[<p><a href="http://digibond.wpengine.netdna-cdn.com/wp-content/uploads/2013/05/chrissam42.jpg"></a></p> <p style="padding-top: 24px;">If you had any doubts about the thirst for ICS security news in the press, this week&#8217;s articles on some research from NC State provided a vivid demonstration. NC State puts out a press release on some early research, far away from anything that can be purchased, questionable if it would be of value in and ICS, and it turns into articles such as <a href="http://www.homelandsecuritynewswire.com/dr20130514-new-software-protects-networked-control-systems-from-cyber-attacks">New Software Protects Networked Control Systems From Cyber Attacks</a>.</p> <p>Let me be clear that is not a knock on the research itself. We have been advocating and highlighting ICS security research for almost a decade now with our S4 conference. The researchers at NC State have an interesting approach that we might consider worthy of a slot at S4x14 or some future event as it develops.</p> <p>The paper <a href="http://www4.ncsu.edu/~chow/Publication_folder/Conference_paper_folder/2013-05-30%20Convergence%20and%20Recovery%20analysis%20of%20the%20Secure%20D-NCS-Final%20%28TD-008583%29.pdf">Convergence and Recovery Analysis of the Secure Distributed Control Methodology for D-NCS is available online</a>.</p> <p>The base idea is to eliminate sensor data from a process if the sensor or device passing the sensor data has been compromised. Actually, this could be due to any fault, not just a physical or cyber compromise. The challenge is how does the system know the sensor or device has been compromised?</p> <p>The researchers rely primarily on a consensus algorithms, which I believe would severely limit it&#8217;s practical use. The example given in Section V.A is easy to understand. Eight temperature sensors take a measurement, and sensors 5 and 6 vary significantly from the converged value of the other six sensors. They are considered compromised and excluded from the process.</p> <p>The problem with using consensus algorithms to detect cyber attacks or other anomalies is it requires the deployment and maintenance of a large number of additional sensors that don&#8217;t exist today in most control systems. Many times sensors are not redundant (let alone in numbers to allow consensus calculations), but data smoothing/interpolation takes place to remove and replace flawed or missing data. In a sense the researchers suggest doing this in a brute force way rather than through intelligent use of surrounding state and data.</p> <p>There are high risk / high value sensors that implement a simple variant of the consensus algorithm suggested by the researchers. For example, you will sometimes see three sensors used in the chem sector, and one of the sensor&#8217;s data discarded if it varies more than a certain percentage from the other two sensors&#8217; data.</p> <p>If this is pushed out to the field or plant, as the researchers envision and makes sense, then the consensus algorithm would be implemented in the PLC which is much more likely to be attacked than the sensor. And there is still the data integrity issue in the PLC demonstrated by Stuxnet.</p> <p>A more promising and realistic and difficult approach is to combine the suggested removal of data from a process with process anomaly detection rather than consensus algorithms. There have been a few sessions at S4 where researchers have tried to model possible states of a process and detect when impossible or unlikely states or state chains occurred. The most detailed have involved substation processes, and it has worked. The problem is it was very time consuming to develop the model to detect anomalies.</p> <p>One minor item in  the paper particularly worried and bothered me. The researchers used the term Distributed Network Control System (D-NCS). DCS is a very common term if they wanted to focus on plant implementations, or the could have used ICS. Did they not know what terminology is commonly used by the people they hope will use the research?</p> <p>The <a href="http://news.ncsu.edu/releases/wms-chow-dncs/">NC State press release</a> was reasonable, not sensational, and sensible marketing of their research capabilities. The press are simply feeding the reading public what they want. The oddity is the interest in control system security is stronger outside the control system community than inside the community where the majority still hope the issue just goes away.</p> <p>Image by chrissam42</p> ]]></description>
				<content:encoded><![CDATA[<p><a href="http://digibond.wpengine.netdna-cdn.com/wp-content/uploads/2013/05/chrissam42.jpg"><img class="alignleft size-full wp-image-12254" title="Feeding Frenzy" alt="ICS Security News" src="http://digibond.wpengine.netdna-cdn.com/wp-content/uploads/2013/05/chrissam42.jpg" width="240" height="161" /></a></p>
<p style="padding-top: 24px;">If you had any doubts about the thirst for ICS security news in the press, this week&#8217;s articles on some research from NC State provided a vivid demonstration. NC State puts out a press release on some early research, far away from anything that can be purchased, questionable if it would be of value in and ICS, and it turns into articles such as <a href="http://www.homelandsecuritynewswire.com/dr20130514-new-software-protects-networked-control-systems-from-cyber-attacks">New Software Protects Networked Control Systems From Cyber Attacks</a>.</p>
<p>Let me be clear that is not a knock on the research itself. We have been advocating and highlighting ICS security research for almost a decade now with our S4 conference. The researchers at NC State have an interesting approach that we might consider worthy of a slot at S4x14 or some future event as it develops.</p>
<p>The paper <a href="http://www4.ncsu.edu/~chow/Publication_folder/Conference_paper_folder/2013-05-30%20Convergence%20and%20Recovery%20analysis%20of%20the%20Secure%20D-NCS-Final%20%28TD-008583%29.pdf">Convergence and Recovery Analysis of the Secure Distributed Control Methodology for D-NCS is available online</a>.</p>
<p>The base idea is to eliminate sensor data from a process if the sensor or device passing the sensor data has been compromised. Actually, this could be due to any fault, not just a physical or cyber compromise. The challenge is how does the system know the sensor or device has been compromised?</p>
<p>The researchers rely primarily on a consensus algorithms, which I believe would severely limit it&#8217;s practical use. The example given in Section V.A is easy to understand. Eight temperature sensors take a measurement, and sensors 5 and 6 vary significantly from the converged value of the other six sensors. They are considered compromised and excluded from the process.</p>
<p>The problem with using consensus algorithms to detect cyber attacks or other anomalies is it requires the deployment and maintenance of a large number of additional sensors that don&#8217;t exist today in most control systems. Many times sensors are not redundant (let alone in numbers to allow consensus calculations), but data smoothing/interpolation takes place to remove and replace flawed or missing data. In a sense the researchers suggest doing this in a brute force way rather than through intelligent use of surrounding state and data.</p>
<p>There are high risk / high value sensors that implement a simple variant of the consensus algorithm suggested by the researchers. For example, you will sometimes see three sensors used in the chem sector, and one of the sensor&#8217;s data discarded if it varies more than a certain percentage from the other two sensors&#8217; data.</p>
<p>If this is pushed out to the field or plant, as the researchers envision and makes sense, then the consensus algorithm would be implemented in the PLC which is much more likely to be attacked than the sensor. And there is still the data integrity issue in the PLC demonstrated by Stuxnet.</p>
<p>A more promising and realistic and difficult approach is to combine the suggested removal of data from a process with process anomaly detection rather than consensus algorithms. There have been a few sessions at S4 where researchers have tried to model possible states of a process and detect when impossible or unlikely states or state chains occurred. The most detailed have involved substation processes, and it has worked. The problem is it was very time consuming to develop the model to detect anomalies.</p>
<p>One minor item in  the paper particularly worried and bothered me. The researchers used the term Distributed Network Control System (D-NCS). DCS is a very common term if they wanted to focus on plant implementations, or the could have used ICS. Did they not know what terminology is commonly used by the people they hope will use the research?</p>
<p>The <a href="http://news.ncsu.edu/releases/wms-chow-dncs/">NC State press release</a> was reasonable, not sensational, and sensible marketing of their research capabilities. The press are simply feeding the reading public what they want. The oddity is the interest in control system security is stronger outside the control system community than inside the community where the majority still hope the issue just goes away.</p>
<p><em>Image by chrissam42</em></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=FHBklH9SKtM:Gx6_Aiv4fNY:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=FHBklH9SKtM:Gx6_Aiv4fNY:-BTjWOF_DHI"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?i=FHBklH9SKtM:Gx6_Aiv4fNY:-BTjWOF_DHI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=FHBklH9SKtM:Gx6_Aiv4fNY:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=FHBklH9SKtM:Gx6_Aiv4fNY:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?i=FHBklH9SKtM:Gx6_Aiv4fNY:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=FHBklH9SKtM:Gx6_Aiv4fNY:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?d=qj6IDK7rITs" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/digitalbond/oLPM/~4/FHBklH9SKtM" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.digitalbond.com/blog/2013/05/16/research-and-pr-and-icssec-frenzy/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.digitalbond.com/blog/2013/05/16/research-and-pr-and-icssec-frenzy/</feedburner:origLink></item>
		<item>
		<title>Scanning PLC Devices – PLCScan</title>
		<link>http://feedproxy.google.com/~r/digitalbond/oLPM/~3/6Q2qLDLhfQU/</link>
		<comments>http://www.digitalbond.com/blog/2013/05/14/scanning-plc-devices-plcscan/#comments</comments>
		<pubDate>Tue, 14 May 2013 18:08:44 +0000</pubDate>
		<dc:creator>Stephen Hilt</dc:creator>
				<category><![CDATA[Control System IT]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[PLC Hacking]]></category>
		<category><![CDATA[PLC Security]]></category>
		<category><![CDATA[SCADA hacking]]></category>

		<guid isPermaLink="false">http://www.digitalbond.com/?p=12246</guid>
		<description><![CDATA[<p>PLCScan is a utility that was released by <a href="http://scadastrangelove.org/">scadastrangelove</a> to help identify PLC devices. It does so by acting as a port scanner to see if two common ports are open and then decides what to do based on the availability of the ports. Documented within <a href="http://www.digitalbond.com/tools/the-rack/plcscan">The Rack</a> is PLCScan, a set of python scripts that will help gather information from PLC Devices.</p> <p>First uses of a utility like this, could be fast scans of large subnets to identify PLCs. This could be PLCs of your own networks or PLCs of the internet, after all the blog post from scadastrangelove was titled &#8220;PLCScan the Internet&#8221;. It is only a matter of time before functionality of this sort gets added to searches like <a href="http://www.shodanhq.com/">Shodan</a>. A problem is that even this utility can cause issues on a production system if one does not know what kind of sensitivity comes along with these types of scans.</p> <p>The more we use the control system protocols within to help identify the systems the more accurate information we will be able to get from the devices, also the safer the utilities will be to run. In recent blog post about <a href="http://www.digitalbond.com/blog/2013/05/03/practice-practice-practice/#comments">practicing tools</a>, Ralph Langner said “the device should be considered fragile by default, period”. I agree with this statement, especially for utilities like PLCScan, we should assume that we will bring the device offline if we are using a tool against a production network.</p> <p>PLCScan could add great abilities to the assessment team. The utility can pull information from a PLC that then can be used as a reference point to validate information. This information could be information that the assessment team would had to manually pull from devices and configurations with screenshots. Information from the output from utilities like PLCScan are a lot easier to parse and utilize the data then reviewing screenshots.</p> <p>Even with the risk of bringing the device offline the benefits to knowing what type of information that utilities like PLCScan can provide are very important to understand. Based on the testing we have performed with PLCScan, the script is well written and does take some errors into account to be the safest with the device as possible. It should be used against hosts and not subnets to start with as the only way to truly stop the scan may leave some devices in state that might crash the device.</p> <p>Control system specific utilities like PLCScan will provide good information and a great value to the community if we keep helping projects like this get the most amount of information in the safest way possible. The more information we are able to gather about the systems on line we will be able to have accurate information about what is truly connected to the internet. If we can correctly identify the devices attached, we can remove them from the internet and protect them from malicious uses.</p> <p>Image from <a href="http://threatpost.com/files/2013/03/internetreport-680x400.jpg">Threatpost</a></p> ]]></description>
				<content:encoded><![CDATA[<p><img class="alignleft" alt="" src="http://threatpost.com/files/2013/03/internetreport-680x400.jpg" width="326" height="192" />PLCScan is a utility that was released by <a href="http://scadastrangelove.org/">scadastrangelove</a> to help identify PLC devices. It does so by acting as a port scanner to see if two common ports are open and then decides what to do based on the availability of the ports. Documented within <a href="http://www.digitalbond.com/tools/the-rack/plcscan">The Rack</a> is PLCScan, a set of python scripts that will help gather information from PLC Devices.</p>
<p>First uses of a utility like this, could be fast scans of large subnets to identify PLCs. This could be PLCs of your own networks or PLCs of the internet, after all the blog post from scadastrangelove was titled &#8220;PLCScan the Internet&#8221;. It is only a matter of time before functionality of this sort gets added to searches like <a href="http://www.shodanhq.com/">Shodan</a>. A problem is that even this utility can cause issues on a production system if one does not know what kind of sensitivity comes along with these types of scans.</p>
<p>The more we use the control system protocols within to help identify the systems the more accurate information we will be able to get from the devices, also the safer the utilities will be to run. In recent blog post about <a href="http://www.digitalbond.com/blog/2013/05/03/practice-practice-practice/#comments">practicing tools</a>, Ralph Langner said “the device should be considered fragile by default, period”. I agree with this statement, especially for utilities like PLCScan, we should assume that we will bring the device offline if we are using a tool against a production network.</p>
<p>PLCScan could add great abilities to the assessment team. The utility can pull information from a PLC that then can be used as a reference point to validate information. This information could be information that the assessment team would had to manually pull from devices and configurations with screenshots. Information from the output from utilities like PLCScan are a lot easier to parse and utilize the data then reviewing screenshots.</p>
<p>Even with the risk of bringing the device offline the benefits to knowing what type of information that utilities like PLCScan can provide are very important to understand. Based on the testing we have performed with PLCScan, the script is well written and does take some errors into account to be the safest with the device as possible. It should be used against hosts and not subnets to start with as the only way to truly stop the scan may leave some devices in state that might crash the device.</p>
<p>Control system specific utilities like PLCScan will provide good information and a great value to the community if we keep helping projects like this get the most amount of information in the safest way possible. The more information we are able to gather about the systems on line we will be able to have accurate information about what is truly connected to the internet. If we can correctly identify the devices attached, we can remove them from the internet and protect them from malicious uses.</p>
<p>Image from <a href="http://threatpost.com/files/2013/03/internetreport-680x400.jpg">Threatpost</a></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=6Q2qLDLhfQU:Vc0QbxmQAw4:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=6Q2qLDLhfQU:Vc0QbxmQAw4:-BTjWOF_DHI"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?i=6Q2qLDLhfQU:Vc0QbxmQAw4:-BTjWOF_DHI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=6Q2qLDLhfQU:Vc0QbxmQAw4:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=6Q2qLDLhfQU:Vc0QbxmQAw4:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?i=6Q2qLDLhfQU:Vc0QbxmQAw4:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=6Q2qLDLhfQU:Vc0QbxmQAw4:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?d=qj6IDK7rITs" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/digitalbond/oLPM/~4/6Q2qLDLhfQU" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.digitalbond.com/blog/2013/05/14/scanning-plc-devices-plcscan/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.digitalbond.com/blog/2013/05/14/scanning-plc-devices-plcscan/</feedburner:origLink></item>
		<item>
		<title>Friday News &amp; Notes</title>
		<link>http://feedproxy.google.com/~r/digitalbond/oLPM/~3/ScogPbxPxlc/</link>
		<comments>http://www.digitalbond.com/blog/2013/05/10/friday-news-notes-73/#comments</comments>
		<pubDate>Fri, 10 May 2013 16:23:01 +0000</pubDate>
		<dc:creator>Dale Peterson</dc:creator>
				<category><![CDATA[Critical Intelligence]]></category>
		<category><![CDATA[Friday News & Notes]]></category>
		<category><![CDATA[SCADA Security News]]></category>

		<guid isPermaLink="false">http://www.digitalbond.com/?p=12242</guid>
		<description><![CDATA[<p><a href="http://digibond.wpengine.netdna-cdn.com/wp-content/uploads/2013/05/F-now.jpg"></a>I asked <a href="http://www.c4-security.com/c4/">Eyal Udassin of C4-Security</a> in Israel to comment on the <a href="http://cryptome.org/2013/05/sea-haifa-hack.htm">ICS hack disclosed this week</a>. &#8220;The hack isn’t something for the books. It’s of small kibutz named Sa’ar in the northern part of Israel, indeed from a year ago. The operator had a remote access software with no password on it, so not surprisingly it was hacked. He found out that someone moved the screen view the same morning, so he understood immediately that something is fishy and changed the remote access method to a secure one.&#8221;</p> <p>ISA99 released another draft standard for comment this week &#8211; I<a href="http://www.isa.org/Content/Microsites988/SP99,_Manufacturing_and_Control_Systems_Security1/Home964/REVIEW_DRAFTS4/ISA-62443-4-1-DC.zip">SA-64432-4-1 Product Development Requirements</a>. I&#8217;ll write up my thoughts on it in an article next week.</p> <p><a href="http://www.wired.com/threatlevel/2013/05/googles-control-system-hacked/">Kim Zetter of Wired covered another vulnerable ICS connected to Internet story this week</a>. It normally wouldn&#8217;t warrant mentioning as loyal readers have certainly heard enough of this Shodan / Internet search story. However, it was a Google Building Energy Management System.</p> Tweet of the Week #bbpBox_331627829101989888 a { text-decoration:none; color:#00398E; }#bbpBox_331627829101989888 a:hover { text-decoration:underline; }1) Hack Google's Building Management System2) Report it to the Google Vulnerability Rewards Program3) &#8230;4) Profit?<a href="http://t.co/VvLJrjrr9N" rel="nofollow">http://t.co/VvLJrjrr9N</a><a title='tweeted on 6 May 2013 23:33' href='http://twitter.com/#!/mikko/status/331627829101989888' target='_blank'>6 May 2013 23:33</a> via <a href="http://twitterrific.com" rel="nofollow" target="blank">Twitterrific</a><a href='https://twitter.com/intent/tweet?in_reply_to=331627829101989888' class='bbp-action bbp-reply-action' title='Reply'>Reply</a><a href='https://twitter.com/intent/retweet?tweet_id=331627829101989888' class='bbp-action bbp-retweet-action' title='Retweet'>Retweet</a><a href='https://twitter.com/intent/favorite?tweet_id=331627829101989888' class='bbp-action bbp-favorite-action' title='Favorite'>Favorite</a><a href='http://twitter.com/intent/user?screen_name=mikko'></a><a style='font-weight:bold' href='http://twitter.com/intent/user?screen_name=mikko'>@mikko</a>Mikko Hypponen &#10008; <p>Don&#8217;t forget to <a href="http://feeds.feedburner.com/digitalbond/oLPM">subscribe to this blog RSS feed</a> and <a href="http://twitter.com/digitalbond">follow @digitalbond.com on twitter</a>.</p> Worth Reading Articles <ul> <li>Dan Goodin&#8217;s article on the use of <a href="http://arstechnica.com/security/2013/05/amid-a-barrage-of-password-breaches-honeywords-to-the-rescue/">Honeywords</a>.</li> </ul> Critical Intelligence&#8217;s <a href="http://digitalbond.com/scadapedia/ics-security-event-calendar/">ICS Security Event Calendar</a> Updates <p>Nothing this week.</p> <p><a href="https://www.critical-intelligence.com/">Critical Intelligence</a> provides reports and other information products on  Cyber Situational Awareness and Threat Intelligence services for Industrial Control System Owner/Operators, Vendors and Government stakeholders.</p> <p>Image by ChrisInPlymouth</p> ]]></description>
				<content:encoded><![CDATA[<p><a href="http://digibond.wpengine.netdna-cdn.com/wp-content/uploads/2013/05/F-now.jpg"><img class="alignleft size-full wp-image-12244" alt="ICS Security News" src="http://digibond.wpengine.netdna-cdn.com/wp-content/uploads/2013/05/F-now.jpg" width="204" height="240" /></a>I asked <a href="http://www.c4-security.com/c4/">Eyal Udassin of C4-Security</a> in Israel to comment on the <a href="http://cryptome.org/2013/05/sea-haifa-hack.htm">ICS hack disclosed this week</a>. &#8220;The hack isn’t something for the books. It’s of small kibutz named Sa’ar in the northern part of Israel, indeed from a year ago. The operator had a remote access software with no password on it, so not surprisingly it was hacked. He found out that someone moved the screen view the same morning, so he understood immediately that something is fishy and changed the remote access method to a secure one.&#8221;</p>
<p>ISA99 released another draft standard for comment this week &#8211; I<a href="http://www.isa.org/Content/Microsites988/SP99,_Manufacturing_and_Control_Systems_Security1/Home964/REVIEW_DRAFTS4/ISA-62443-4-1-DC.zip">SA-64432-4-1 Product Development Requirements</a>. I&#8217;ll write up my thoughts on it in an article next week.</p>
<p><a href="http://www.wired.com/threatlevel/2013/05/googles-control-system-hacked/">Kim Zetter of Wired covered another vulnerable ICS connected to Internet story this week</a>. It normally wouldn&#8217;t warrant mentioning as loyal readers have certainly heard enough of this Shodan / Internet search story. However, it was a Google Building Energy Management System.</p>
<h3>Tweet of the Week</h3>
<!-- tweet id : 331627829101989888 --><style type='text/css'>#bbpBox_331627829101989888 a { text-decoration:none; color:#00398E; }#bbpBox_331627829101989888 a:hover { text-decoration:underline; }</style><div id='bbpBox_331627829101989888' class='bbpBox' style='padding:20px; margin:5px 0; background-color:#7B97D0; background-image:url(http://a0.twimg.com/profile_background_images/725340442/99a2ff2361437c31a17f5b4fde454e7b.png);'><div style='background:#fff; padding:10px; margin:0; min-height:48px; color:#000000; -moz-border-radius:5px; -webkit-border-radius:5px;'><span style='width:100%; font-size:18px; line-height:22px;'>1) Hack Google's Building Management System2) Report it to the Google Vulnerability Rewards Program3) &#8230;4) Profit?<a href="http://t.co/VvLJrjrr9N" rel="nofollow">http://t.co/VvLJrjrr9N</a></span><div class='bbp-actions' style='font-size:12px; width:100%; padding:5px 0; margin:0 0 10px 0; border-bottom:1px solid #e6e6e6;'><img align='middle' src='http://digibond.wpengine.netdna-cdn.com/wp-content/plugins/twitter-blackbird-pie//images/bird.png' /><a title='tweeted on 6 May 2013 23:33' href='http://twitter.com/#!/mikko/status/331627829101989888' target='_blank'>6 May 2013 23:33</a> via <a href="http://twitterrific.com" rel="nofollow" target="blank">Twitterrific</a><a href='https://twitter.com/intent/tweet?in_reply_to=331627829101989888' class='bbp-action bbp-reply-action' title='Reply'><span><em style='margin-left: 1em;'></em><strong>Reply</strong></span></a><a href='https://twitter.com/intent/retweet?tweet_id=331627829101989888' class='bbp-action bbp-retweet-action' title='Retweet'><span><em style='margin-left: 1em;'></em><strong>Retweet</strong></span></a><a href='https://twitter.com/intent/favorite?tweet_id=331627829101989888' class='bbp-action bbp-favorite-action' title='Favorite'><span><em style='margin-left: 1em;'></em><strong>Favorite</strong></span></a></div><div style='float:left; padding:0; margin:0'><a href='http://twitter.com/intent/user?screen_name=mikko'><img style='width:48px; height:48px; padding-right:7px; border:none; background:none; margin:0' src='http://a0.twimg.com/profile_images/3428497729/8a03810d1c84ab31c512fb6660e85477_normal.jpeg' /></a></div><div style='float:left; padding:0; margin:0'><a style='font-weight:bold' href='http://twitter.com/intent/user?screen_name=mikko'>@mikko</a><div style='margin:0; padding-top:2px'>Mikko Hypponen &#10008;</div></div><div style='clear:both'></div></div></div><!-- end of tweet -->
<p><em><img title="More..." alt="" src="https://www.digitalbond.com/wp-includes/js/tinymce/plugins/wordpress/img/trans.gif" />Don&#8217;t forget to <a href="http://feeds.feedburner.com/digitalbond/oLPM">subscribe to this blog RSS feed</a> and <a href="http://twitter.com/digitalbond">follow @digitalbond.com on twitter</a>.</em></p>
<h3><img title="More..." alt="" src="https://www.digitalbond.com/wp-includes/js/tinymce/plugins/wordpress/img/trans.gif" /><br />
Worth Reading Articles<img title="More..." alt="" src="https://www.digitalbond.com/wp-includes/js/tinymce/plugins/wordpress/img/trans.gif" /></h3>
<ul>
<li>Dan Goodin&#8217;s article on the use of <a href="http://arstechnica.com/security/2013/05/amid-a-barrage-of-password-breaches-honeywords-to-the-rescue/">Honeywords</a>.</li>
</ul>
<h3>Critical Intelligence&#8217;s <a href="http://digitalbond.com/scadapedia/ics-security-event-calendar/">ICS Security Event Calendar</a> Updates</h3>
<p>Nothing this week.</p>
<p><a href="https://www.critical-intelligence.com/">Critical Intelligence</a><em> provides reports and other information products on  Cyber Situational Awareness and Threat Intelligence services for Industrial Control System Owner/Operators, Vendors and Government stakeholders.</em></p>
<p><em>Image by ChrisInPlymouth</em></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=ScogPbxPxlc:m2xmi4P3uO4:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=ScogPbxPxlc:m2xmi4P3uO4:-BTjWOF_DHI"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?i=ScogPbxPxlc:m2xmi4P3uO4:-BTjWOF_DHI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=ScogPbxPxlc:m2xmi4P3uO4:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=ScogPbxPxlc:m2xmi4P3uO4:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?i=ScogPbxPxlc:m2xmi4P3uO4:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=ScogPbxPxlc:m2xmi4P3uO4:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?d=qj6IDK7rITs" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/digitalbond/oLPM/~4/ScogPbxPxlc" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.digitalbond.com/blog/2013/05/10/friday-news-notes-73/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.digitalbond.com/blog/2013/05/10/friday-news-notes-73/</feedburner:origLink></item>
		<item>
		<title>John The Ripper – S7 Password Cracking</title>
		<link>http://feedproxy.google.com/~r/digitalbond/oLPM/~3/YpFANR9x0B0/</link>
		<comments>http://www.digitalbond.com/blog/2013/05/10/john-the-ripper-s7-password-cracking/#comments</comments>
		<pubDate>Fri, 10 May 2013 15:07:13 +0000</pubDate>
		<dc:creator>Stephen Hilt</dc:creator>
				<category><![CDATA[PLC Security]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Siemens]]></category>
		<category><![CDATA[John The Ripper]]></category>
		<category><![CDATA[Password Cracking]]></category>
		<category><![CDATA[S7]]></category>
		<category><![CDATA[SCADA]]></category>

		<guid isPermaLink="false">http://www.digitalbond.com/?p=12237</guid>
		<description><![CDATA[<p>At S4x13, Scadastrangelove (<a href="https://twitter.com/scadasl">@scadasl</a>) released a offline brute force password cracking script (<a href="http://pastebin.com/0G9Q2k6y">http://pastebin.com/0G9Q2k6y</a>). Shortly after the script was released the functionality from that script was added into John The Ripper. Documented in <a href="http://www.digitalbond.com/tools/the-rack/jtr-s7-password-cracking/">The Rack</a> is how John The Ripper is capable of cracking S7 password hashes using the Scadastrangelove technique of offline password cracking from a packet capture.</p> <p>John The Ripper has been around for many years, and is one of the most common password cracking utilities out there. With an add-on plugin and a script that is easy to run, the password hashes are extracted out of  packet captures, and cracked using John The Ripper.</p> <p>The use of John The Ripper outside of the normal workstations and servers inside of ICS environments is very limited, as most devices you can&#8217;t get the information required to run the software against the password hashes.</p> <p>With the rise of password complexity requirements inside of ICS environments, auditing the password complexity of PLC and like devices can be difficult and rely a lot of how much you trust the engineer. As an example there is nothing to say that the PLC configuration that you are looking at on the engineer workstation is the one that is truly pushed out to the PLC. With the ability to gather information from a packet capture and then verify the password complexity adds that much assurance to an assessment.</p> <p>However, this utility can be used for nefarious purposes, take an example where on a support portal for a vendor some one uploads a packet capture to try to get help, now this packet capture is downloaded by an attacker. This utility makes it easier for an attacker to crack the passwords of S7 devices. This gives an upper hand on the ability to write custom malware to alter configurations and the likes. Thats not to be said this couldn&#8217;t and wasn&#8217;t a capability before, this just took their ability and made it easier for them.</p> <p>Password cracking is dependent on the hardware in which you are running the password cracking software on. The only testing I was able to perform was on some packet captures that were given to me from Sergey Gordeychik of Positive Technologies, and the passwords were very simple passwords that cracked within a second or two. The more complex the password the more time it takes to crack via brute force techniques, with more and more password breaches happening the word lists are getting bigger which helps the dictionary attacks get that much more powerful. I expect to see more ICS devices fall to this type of attack in the future.</p> <p>Photo from <a href="http://awaitingdawn.deviantart.com/">awaitingdawn</a></p> ]]></description>
				<content:encoded><![CDATA[<p><img class="alignleft" alt="" src="http://fc05.deviantart.net/fs37/i/2008/257/c/9/keys_by_awaitingdawn.jpg" width="269" height="210" />At S4x13, Scadastrangelove (<a href="https://twitter.com/scadasl">@scadasl</a>) released a offline brute force password cracking script (<a href="http://pastebin.com/0G9Q2k6y">http://pastebin.com/0G9Q2k6y</a>). Shortly after the script was released the functionality from that script was added into John The Ripper. Documented in <a href="http://www.digitalbond.com/tools/the-rack/jtr-s7-password-cracking/">The Rack</a> is how John The Ripper is capable of cracking S7 password hashes using the Scadastrangelove technique of offline password cracking from a packet capture.</p>
<p>John The Ripper has been around for many years, and is one of the most common password cracking utilities out there. With an add-on plugin and a script that is easy to run, the password hashes are extracted out of  packet captures, and cracked using John The Ripper.</p>
<p>The use of John The Ripper outside of the normal workstations and servers inside of ICS environments is very limited, as most devices you can&#8217;t get the information required to run the software against the password hashes.</p>
<p>With the rise of password complexity requirements inside of ICS environments, auditing the password complexity of PLC and like devices can be difficult and rely a lot of how much you trust the engineer. As an example there is nothing to say that the PLC configuration that you are looking at on the engineer workstation is the one that is truly pushed out to the PLC. With the ability to gather information from a packet capture and then verify the password complexity adds that much assurance to an assessment.</p>
<p>However, this utility can be used for nefarious purposes, take an example where on a support portal for a vendor some one uploads a packet capture to try to get help, now this packet capture is downloaded by an attacker. This utility makes it easier for an attacker to crack the passwords of S7 devices. This gives an upper hand on the ability to write custom malware to alter configurations and the likes. Thats not to be said this couldn&#8217;t and wasn&#8217;t a capability before, this just took their ability and made it easier for them.</p>
<p>Password cracking is dependent on the hardware in which you are running the password cracking software on. The only testing I was able to perform was on some packet captures that were given to me from Sergey Gordeychik of Positive Technologies, and the passwords were very simple passwords that cracked within a second or two. The more complex the password the more time it takes to crack via brute force techniques, with more and more password breaches happening the word lists are getting bigger which helps the dictionary attacks get that much more powerful. I expect to see more ICS devices fall to this type of attack in the future.</p>
<p>Photo from <a href="http://awaitingdawn.deviantart.com/">awaitingdawn</a></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=YpFANR9x0B0:bLPBjLcUSiM:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=YpFANR9x0B0:bLPBjLcUSiM:-BTjWOF_DHI"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?i=YpFANR9x0B0:bLPBjLcUSiM:-BTjWOF_DHI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=YpFANR9x0B0:bLPBjLcUSiM:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=YpFANR9x0B0:bLPBjLcUSiM:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?i=YpFANR9x0B0:bLPBjLcUSiM:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=YpFANR9x0B0:bLPBjLcUSiM:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?d=qj6IDK7rITs" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/digitalbond/oLPM/~4/YpFANR9x0B0" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.digitalbond.com/blog/2013/05/10/john-the-ripper-s7-password-cracking/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.digitalbond.com/blog/2013/05/10/john-the-ripper-s7-password-cracking/</feedburner:origLink></item>
		<item>
		<title>Last Call: Cyber Security Training in Chicago</title>
		<link>http://feedproxy.google.com/~r/digitalbond/oLPM/~3/ouaODnjmS0w/</link>
		<comments>http://www.digitalbond.com/blog/2013/05/09/last-call-cyber-security-training-in-chicago/#comments</comments>
		<pubDate>Thu, 09 May 2013 18:15:34 +0000</pubDate>
		<dc:creator>Michael Toecker</dc:creator>
				<category><![CDATA[Training]]></category>

		<guid isPermaLink="false">http://www.digitalbond.com/?p=12240</guid>
		<description><![CDATA[<p><a href="http://digibond.wpengine.netdna-cdn.com/wp-content/uploads/2013/03/Screen-Shot-2013-03-13-at-6.13.45-PM.png"></a>There are several seats still available for the upcoming Cyber Security for Power Generation training outside of Chicago.  The one-day course is specifically designed for those engineers and IT professionals responsible for securing a power plant DCS and balance of plant cyber systems. The entire course is taught in the context of model power plant.</p> <p>I&#8217;m looking forward to conducting this training, as I&#8217;ve spent the past 8 or so years engaged in power generation work. There are nuances and concerns associated with Cyber Security for Power Generation, and I&#8217;m looking forward to sharing with attendees.  Cost is $495, which is a bargain for an 8 hour professional training.</p> <p>For more details, please check out the <a href="http://www.cvent.com/events/cyber-security-for-power-generation/event-summary-ac7cc13cc07a4912bea31f6c203d02de.aspx">event site</a>.</p> ]]></description>
				<content:encoded><![CDATA[<p><a href="http://digibond.wpengine.netdna-cdn.com/wp-content/uploads/2013/03/Screen-Shot-2013-03-13-at-6.13.45-PM.png"><img class="alignleft size-thumbnail wp-image-12053" alt="Michael Toecker" src="http://digibond.wpengine.netdna-cdn.com/wp-content/uploads/2013/03/Screen-Shot-2013-03-13-at-6.13.45-PM-150x150.png" width="150" height="150" /></a>There are several seats still available for the upcoming Cyber Security for Power Generation training outside of Chicago.  The one-day course is specifically designed for those engineers and IT professionals responsible for securing a power plant DCS and balance of plant cyber systems. The entire course is taught in the context of model power plant.</p>
<p>I&#8217;m looking forward to conducting this training, as I&#8217;ve spent the past 8 or so years engaged in power generation work. There are nuances and concerns associated with Cyber Security for Power Generation, and I&#8217;m looking forward to sharing with attendees.  Cost is $495, which is a bargain for an 8 hour professional training.</p>
<p>For more details, please check out the <a href="http://www.cvent.com/events/cyber-security-for-power-generation/event-summary-ac7cc13cc07a4912bea31f6c203d02de.aspx">event site</a>.</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=ouaODnjmS0w:fnOccFNp43k:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=ouaODnjmS0w:fnOccFNp43k:-BTjWOF_DHI"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?i=ouaODnjmS0w:fnOccFNp43k:-BTjWOF_DHI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=ouaODnjmS0w:fnOccFNp43k:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=ouaODnjmS0w:fnOccFNp43k:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?i=ouaODnjmS0w:fnOccFNp43k:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=ouaODnjmS0w:fnOccFNp43k:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?d=qj6IDK7rITs" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/digitalbond/oLPM/~4/ouaODnjmS0w" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.digitalbond.com/blog/2013/05/09/last-call-cyber-security-training-in-chicago/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.digitalbond.com/blog/2013/05/09/last-call-cyber-security-training-in-chicago/</feedburner:origLink></item>
		<item>
		<title>S4x13 Video: Detecting 0-Day Attacks with Non-Signature IDS</title>
		<link>http://feedproxy.google.com/~r/digitalbond/oLPM/~3/0gFPXciASbE/</link>
		<comments>http://www.digitalbond.com/blog/2013/05/09/s4x13-video-detecting-0-day-attacks-with-non-signature-ids/#comments</comments>
		<pubDate>Thu, 09 May 2013 14:13:20 +0000</pubDate>
		<dc:creator>Dale Peterson</dc:creator>
				<category><![CDATA[Network IDS/IPS]]></category>
		<category><![CDATA[S4]]></category>
		<category><![CDATA[Damiano Bolzoni]]></category>
		<category><![CDATA[S4x13]]></category>
		<category><![CDATA[SCADA IDS]]></category>

		<guid isPermaLink="false">http://www.digitalbond.com/?p=12238</guid>
		<description><![CDATA[<p>Damiano Bolzoni&#8217;s of <a href="http://www.secmatters.com/">Security Matters</a> presented Detecting 0-Day and Targeted Attacks on ICS with Non-Signature Based IDS. While the quantitative mode of anomaly detection, looking at the quantity of packets, has had some success, qualitative approach has had a lot of research with minimal practical results.</p> <p>The session explains n-gram analysis and shows the results of four different n-gram approaches on finding anomalies in 30-days of Modbus/TCP traffic on a water ICS and 7-days of SMB traffic on a gas SCADA. This was great to see because using real world data in ICS research is actually still rare.</p> <p></p> <p>The results of the n-gram models were better for the Modbus/TCP, but even the best model had 10 false positives a day even with the highly repetitive Modbus traffic.</p> <p>Damiano then proposes a new method that is an extension of what is done in Tenable&#8217;s Passive Security Scanner, INL&#8217;s Sofia and other products. Those products will identify &#8220;normal&#8221; communication on the network by source IP, destination IP and destination TCP/UDP port. The example demonstrated in the presentation includes other ICS protocol parameters.</p> <p>For example, it will identify what function codes are used and alert on new function codes. It will identify data lengths and alert on new data lengths. Obviously the similar the protocol the easier it is to do this. An application layer protocol like Modbus/TCP is relatively simple. A protocol that includes its own data and transport layer, like DNP3, could cause more false positives unless packet fragmentation is dealt with. A complex protocol like EtherNet/IP would be much more difficult. It is similar to the issues that require a preprocessor in signature based network IDS.</p> <p>In fact, some of our early Quickdraw IDS signatures detect similar anomalous behavior. However, the signature based approach requires selecting and modifying the signatures manually. Damiano&#8217;s approach generates these rules automatically.</p> ]]></description>
				<content:encoded><![CDATA[<p>Damiano Bolzoni&#8217;s of <a href="http://www.secmatters.com/">Security Matters</a> presented Detecting 0-Day and Targeted Attacks on ICS with Non-Signature Based IDS. While the quantitative mode of anomaly detection, looking at the quantity of packets, has had some success, qualitative approach has had a lot of research with minimal practical results.</p>
<p>The session explains n-gram analysis and shows the results of four different n-gram approaches on finding anomalies in 30-days of Modbus/TCP traffic on a water ICS and 7-days of SMB traffic on a gas SCADA. This was great to see because using real world data in ICS research is actually still rare.</p>
<p><iframe src="http://player.vimeo.com/video/65793786" width="640" height="480" frameborder="0" webkitAllowFullScreen mozallowfullscreen allowFullScreen></iframe></p>
<p>The results of the n-gram models were better for the Modbus/TCP, but even the best model had 10 false positives a day even with the highly repetitive Modbus traffic.</p>
<p>Damiano then proposes a new method that is an extension of what is done in Tenable&#8217;s Passive Security Scanner, INL&#8217;s Sofia and other products. Those products will identify &#8220;normal&#8221; communication on the network by source IP, destination IP and destination TCP/UDP port. The example demonstrated in the presentation includes other ICS protocol parameters.</p>
<p>For example, it will identify what function codes are used and alert on new function codes. It will identify data lengths and alert on new data lengths. Obviously the similar the protocol the easier it is to do this. An application layer protocol like Modbus/TCP is relatively simple. A protocol that includes its own data and transport layer, like DNP3, could cause more false positives unless packet fragmentation is dealt with. A complex protocol like EtherNet/IP would be much more difficult. It is similar to the issues that require a preprocessor in signature based network IDS.</p>
<p>In fact, some of our early Quickdraw IDS signatures detect similar anomalous behavior. However, the signature based approach requires selecting and modifying the signatures manually. Damiano&#8217;s approach generates these rules automatically.</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=0gFPXciASbE:srPPmVTl1HU:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=0gFPXciASbE:srPPmVTl1HU:-BTjWOF_DHI"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?i=0gFPXciASbE:srPPmVTl1HU:-BTjWOF_DHI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=0gFPXciASbE:srPPmVTl1HU:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=0gFPXciASbE:srPPmVTl1HU:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?i=0gFPXciASbE:srPPmVTl1HU:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=0gFPXciASbE:srPPmVTl1HU:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?d=qj6IDK7rITs" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/digitalbond/oLPM/~4/0gFPXciASbE" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.digitalbond.com/blog/2013/05/09/s4x13-video-detecting-0-day-attacks-with-non-signature-ids/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		<feedburner:origLink>http://www.digitalbond.com/blog/2013/05/09/s4x13-video-detecting-0-day-attacks-with-non-signature-ids/</feedburner:origLink></item>
		<item>
		<title>Response Fuzzing</title>
		<link>http://feedproxy.google.com/~r/digitalbond/oLPM/~3/Xxh7aAcUNLQ/</link>
		<comments>http://www.digitalbond.com/blog/2013/05/08/response-fuzzing/#comments</comments>
		<pubDate>Wed, 08 May 2013 19:56:13 +0000</pubDate>
		<dc:creator>Michael Toecker</dc:creator>
				<category><![CDATA[Research]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Fuzzing]]></category>
		<category><![CDATA[SCADA]]></category>

		<guid isPermaLink="false">http://www.digitalbond.com/?p=12221</guid>
		<description><![CDATA[<p><a href="http://digibond.wpengine.netdna-cdn.com/wp-content/uploads/2013/05/fuzzy.jpg"></a>Fuzzing, as a practice, has been around for a while. Throw garbage at an input to a program and see what falls apart. Analyze the crashes and dumps, and see if any involve commonly exploitable issues, such as buffer overflows, off by one errors, etc.</p> <p>I&#8217;ve seen SCADA protocols brought low by a simple repetition of &#8216;AAA&#8230;&#8217;; and I&#8217;ve seen much more complex fuzzing efforts (such as those brought up by Terry McCorkle and Billy Rios in some of their advanced training). In normal IT, fuzzing often focuses effort on the &#8216;server&#8217; or &#8216;input&#8217; part of the communication, where the user can influence input sent to the server. This is because the user is determined to be the larger threat, and the server is considered the system to defend. There are exceptions to this, one of the notable ones are browser based bugs designed to infect users based on input received from a web server.</p> <p>But most ICS deployments have the exact opposite use case. Yes, we use client-server type architectures, but the systems that require the most protection are often not the server ones (the PLCs), they are the client systems (the controlling HMIs, etc). For example, take a Modbus communication: The client requests point data directly from a PLC, which then responds back to the client with the point data requested.  Simple right?</p> <p>However, when the client is requesting data it is also vulnerable to a malicious response. In most research I&#8217;ve read, this malicious response has usually been &#8216;bad data&#8217;, data designed to provide upstream operators with false readouts and influence decisions. Easy to do when your protocols lack integrity. But, what if there were buffer overflow conditions in code that processes a response? An attacker might be able to use these conditions to crash the upstream process, and potentially insert their own code.</p> <p>This request-response type architecture is present everywhere in automation, and runs over both TCP/IP and bare serial protocols. The more interesting condition is that a control center (the client) communicates to potentially hundreds of end devices (the servers), and only a small portion of those end devices may have physical and cyber protections. I use this example because I see it in NERC CIP implementations everywhere, where you have a Control Center with a dozen critical substations and 4 dozen that are non-critical.</p> <p>I had an opportunity to do some very basic fuzzing for clients in the past, and recently looked at this condition. While I lacked time (this was limited to about 4 hours of  hacking, including recording the requests and responses) to put together something truly magnificent, I did write-up some basic Python code to send back malformed data when a SCADA system requested it. I didn&#8217;t find anything with this, maybe you will. Use your best judgement in implementing this code, as it is intentionally designed to provide data intended to crash systems and process.</p> <p>This code was written to pretend to be a Modbus device in a few very simple cases, allowing the Control Center to request data from it. The responses from the program were intended to be scripted, but you could build more intelligence in if necessary with the PyModbus project. Specifically, this code pretended to be a serial Modbus device, accessible through a Ethernet to serial converter. This made interception and monitoring of the communication much simpler than going through a bare serial interface.</p> <p>The intent of the code was simple:</p> <li>Listen for a specific requests from the control center</li> <li>Queue up a valid response to that request</li> <li>Randomly alter some of the parameters from a valid response</li> <li>Respond to the control center</li> <li>Log all information regarding the communications to flat file for analysis</li> <p>The major limitation in this code is lack of CRC generation, which would ensure that the malicious data is accepted by the subsystem as valid, and then processed. I&#8217;ve also removed the payloads I worked with, you&#8217;ll need to generate your own valid requests and responses.</p> <p><a href="http://pastebin.com/C3wCjMzJ">Link to code</a></p> <p>title image by <a href="http://www.flickr.com/photos/oskay/">oskay</a></p> ]]></description>
				<content:encoded><![CDATA[<p><a href="http://digibond.wpengine.netdna-cdn.com/wp-content/uploads/2013/05/fuzzy.jpg"><img class="alignleft size-thumbnail wp-image-12222" alt="fuzzy" src="http://digibond.wpengine.netdna-cdn.com/wp-content/uploads/2013/05/fuzzy-150x150.jpg" width="150" height="150" /></a>Fuzzing, as a practice, has been around for a while. Throw garbage at an input to a program and see what falls apart. Analyze the crashes and dumps, and see if any involve commonly exploitable issues, such as buffer overflows, off by one errors, etc.</p>
<p>I&#8217;ve seen SCADA protocols brought low by a simple repetition of &#8216;AAA&#8230;&#8217;; and I&#8217;ve seen much more complex fuzzing efforts (such as those brought up by Terry McCorkle and Billy Rios in some of their advanced training). In normal IT, fuzzing often focuses effort on the &#8216;server&#8217; or &#8216;input&#8217; part of the communication, where the user can influence input sent to the server. This is because the user is determined to be the larger threat, and the server is considered the system to defend. There are exceptions to this, one of the notable ones are browser based bugs designed to infect users based on input received from a web server.</p>
<p>But most ICS deployments have the exact opposite use case. Yes, we use client-server type architectures, but the systems that require the most protection are often not the server ones (the PLCs), they are the client systems (the controlling HMIs, etc). For example, take a Modbus communication: The client requests point data directly from a PLC, which then responds back to the client with the point data requested.  Simple right?<span id="more-12221"></span></p>
<p>However, when the client is requesting data it is also vulnerable to a malicious response. In most research I&#8217;ve read, this malicious response has usually been &#8216;bad data&#8217;, data designed to provide upstream operators with false readouts and influence decisions. Easy to do when your protocols lack integrity. But, what if there were buffer overflow conditions in code that processes a response? An attacker might be able to use these conditions to crash the upstream process, and potentially insert their own code.</p>
<p>This request-response type architecture is present everywhere in automation, and runs over both TCP/IP and bare serial protocols. The more interesting condition is that a control center (the client) communicates to potentially hundreds of end devices (the servers), and only a small portion of those end devices may have physical and cyber protections. I use this example because I see it in NERC CIP implementations everywhere, where you have a Control Center with a dozen critical substations and 4 dozen that are non-critical.</p>
<p>I had an opportunity to do some very basic fuzzing for clients in the past, and recently looked at this condition. While I lacked time (this was limited to about 4 hours of  hacking, including recording the requests and responses) to put together something truly magnificent, I did write-up some basic Python code to send back malformed data when a SCADA system requested it. I didn&#8217;t find anything with this, maybe you will. Use your best judgement in implementing this code, as it is intentionally designed to provide data intended to crash systems and process.</p>
<p>This code was written to pretend to be a Modbus device in a few very simple cases, allowing the Control Center to request data from it. The responses from the program were intended to be scripted, but you could build more intelligence in if necessary with the PyModbus project. Specifically, this code pretended to be a serial Modbus device, accessible through a Ethernet to serial converter. This made interception and monitoring of the communication much simpler than going through a bare serial interface.</p>
<p>The intent of the code was simple:</p>
<ol>
<li>Listen for a specific requests from the control center</li>
<li>Queue up a valid response to that request</li>
<li>Randomly alter some of the parameters from a valid response</li>
<li>Respond to the control center</li>
<li>Log all information regarding the communications to flat file for analysis</li>
</ol>
<p>The major limitation in this code is lack of CRC generation, which would ensure that the malicious data is accepted by the subsystem as valid, and then processed. I&#8217;ve also removed the payloads I worked with, you&#8217;ll need to generate your own valid requests and responses.</p>
<p><a href="http://pastebin.com/C3wCjMzJ">Link to code</a></p>
<p><em>title image by <a href="http://www.flickr.com/photos/oskay/">oskay</a></em></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=Xxh7aAcUNLQ:tBgKY77IDJA:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=Xxh7aAcUNLQ:tBgKY77IDJA:-BTjWOF_DHI"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?i=Xxh7aAcUNLQ:tBgKY77IDJA:-BTjWOF_DHI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=Xxh7aAcUNLQ:tBgKY77IDJA:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=Xxh7aAcUNLQ:tBgKY77IDJA:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?i=Xxh7aAcUNLQ:tBgKY77IDJA:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=Xxh7aAcUNLQ:tBgKY77IDJA:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?d=qj6IDK7rITs" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/digitalbond/oLPM/~4/Xxh7aAcUNLQ" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.digitalbond.com/blog/2013/05/08/response-fuzzing/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		<feedburner:origLink>http://www.digitalbond.com/blog/2013/05/08/response-fuzzing/</feedburner:origLink></item>
		<item>
		<title>Review of ISA-62443-3-2 Security Risk Assessment and System Design</title>
		<link>http://feedproxy.google.com/~r/digitalbond/oLPM/~3/sdyI4hJL1lg/</link>
		<comments>http://www.digitalbond.com/blog/2013/05/06/review-of-isa-62443-3-2-security-risk-assessment-and-system-design/#comments</comments>
		<pubDate>Mon, 06 May 2013 14:06:25 +0000</pubDate>
		<dc:creator>Dale Peterson</dc:creator>
				<category><![CDATA[ISA 99]]></category>
		<category><![CDATA[Risk Management]]></category>

		<guid isPermaLink="false">http://www.digitalbond.com/?p=12212</guid>
		<description><![CDATA[<p><a href="http://digibond.wpengine.netdna-cdn.com/wp-content/uploads/2013/05/sludgegulper.jpg"></a>A draft of <a href="http://www.isa.org/Content/Microsites988/SP99,_Manufacturing_and_Control_Systems_Security1/Home964/REVIEW_DRAFTS4/ISA-62443-3-2-Comments_due_May_22.zip">ISA-62443-3-2 is out for comment now</a>. Previously it was called Zones and Conduits, but the latest draft recommends a title change to Security Risk Assessment and System Design. The recommended new title is more accurate for the content.</p> <p>Readers looking for some detailed guidance or requirements on performing a security risk assessment or designing a security architecture will be disappointed. This standard is primarily a process document that tells an owner/operator the tasks that must be done in a risk assessment, but doesn&#8217;t provide much information on how to do the tasks.</p> <p>The positive spin on this document is it provides a consistent process and terminology for performing an ICS risk assessment. For example there is a specific list of information that must be documented for each zone and conduit in Section 4.4.3.1.</p> <p>The negative spin is it has requirements, &#8220;shalls&#8221;, without helping an owner/operator determine how to do this. A few examples:</p> <ul> <li>4.5.1.1 &#8220;A list of the threats that could affect the assets contained within the zone or conduit shall be developed.&#8221;</li> <li>4.5.2.1 &#8220;The zone or conduit shall be analyzed in order to identify and document the known vulnerabilities in the zone or conduit access points and in the assets contained within the zone or conduit.&#8221;</li> <li>And then the list of earlier required shalls are combined in a calculation such as 4.6.1.1 &#8220;The residual risk calculated for each threat 4.5.5 shall be compared to the organization’s tolerable risk (specified in 4.3). Additional security countermeasures must be applied if the residual risk exceeds the tolerable risk.&#8221;</li> </ul> <p>This document is high level Risk Management 101. It&#8217;s actually a very short document and quick read with about 5 pages after you strip out the formatting and definition sections and an example annex.</p> <p>It may be unfair to look at this document in isolation. ISA99 has a large set of standards and technical reports in process that interlock to hopefully form a complete picture. In addition, future annexes (appendices) are hinted at that could provide guidance on how to achieve these mandatory requirements. This is started with a partially completed annex on a chemical truck loading example, and another annex to be written with &#8220;several possible methodologies that can be used to assess the frequency of the threat hazard&#8221;.</p> <p>There is guidance on security zones as the standard recommends (shoulds) that control, safety, corporate, wireless, and mobile devices all be in their own zones. All guidance is very broad such as &#8220;The organization’s tolerable risk for the SuC should be included in the security requirements specification.&#8221;</p> <p>It&#8217;s a draft so there is still work to be done. Consider even the limited examples in this article. Specifying the organization&#8217;s tolerable risk is optional, but it is then required in Section 4.6.1.1. ISA99 has a comment form and is very welcoming of any suggested improvements.</p> <p>In summary, ISA-62443-3-2 isn&#8217;t going to be of much assistance to an owner/operator doing a risk assessment or a security design unless there is substantial work on the annex. It likely will be a key component of the overall ISA99 standards framework.</p> <p>Image by SludgeGulper</p> ]]></description>
				<content:encoded><![CDATA[<p><a href="http://digibond.wpengine.netdna-cdn.com/wp-content/uploads/2013/05/sludgegulper.jpg"><img class="alignleft size-full wp-image-12217" alt="Zones and Conduits" src="http://digibond.wpengine.netdna-cdn.com/wp-content/uploads/2013/05/sludgegulper.jpg" width="114" height="240" /></a>A draft of <a href="http://www.isa.org/Content/Microsites988/SP99,_Manufacturing_and_Control_Systems_Security1/Home964/REVIEW_DRAFTS4/ISA-62443-3-2-Comments_due_May_22.zip">ISA-62443-3-2 is out for comment now</a>. Previously it was called Zones and Conduits, but the latest draft recommends a title change to Security Risk Assessment and System Design. The recommended new title is more accurate for the content.</p>
<p>Readers looking for some detailed guidance or requirements on performing a security risk assessment or designing a security architecture will be disappointed. This standard is primarily a process document that tells an owner/operator the tasks that must be done in a risk assessment, but doesn&#8217;t provide much information on how to do the tasks.</p>
<p>The positive spin on this document is it provides a consistent process and terminology for performing an ICS risk assessment. For example there is a specific list of information that must be documented for each zone and conduit in Section 4.4.3.1.</p>
<p>The negative spin is it has requirements, &#8220;shalls&#8221;, without helping an owner/operator determine how to do this. A few examples:</p>
<ul>
<li><span style="line-height: 13px;"><span style="line-height: 13px;">4.5.1.1 &#8220;</span></span>A list of the threats that could affect the assets contained within the zone or conduit shall be developed.&#8221;</li>
<li>4.5.2.1 &#8220;The zone or conduit shall be analyzed in order to identify and document the known vulnerabilities in the zone or conduit access points and in the assets contained within the zone or conduit.&#8221;</li>
<li>And then the list of earlier required shalls are combined in a calculation such as 4.6.1.1 &#8220;The residual risk calculated for each threat 4.5.5 shall be compared to the organization’s tolerable risk (specified in 4.3). Additional security countermeasures must be applied if the residual risk exceeds the tolerable risk.&#8221;</li>
</ul>
<p>This document is high level Risk Management 101. It&#8217;s actually a very short document and quick read with about 5 pages after you strip out the formatting and definition sections and an example annex.</p>
<p>It may be unfair to look at this document in isolation. ISA99 has a large set of standards and technical reports in process that interlock to hopefully form a complete picture. In addition, future annexes (appendices) are hinted at that could provide guidance on how to achieve these mandatory requirements. This is started with a partially completed annex on a chemical truck loading example, and another annex to be written with &#8220;several possible methodologies that can be used to assess the frequency of the threat hazard&#8221;.</p>
<p>There is guidance on security zones as the standard recommends (shoulds) that control, safety, corporate, wireless, and mobile devices all be in their own zones. All guidance is very broad such as &#8220;The organization’s tolerable risk for the SuC should be included in the security requirements specification.&#8221;</p>
<p>It&#8217;s a draft so there is still work to be done. Consider even the limited examples in this article. Specifying the organization&#8217;s tolerable risk is optional, but it is then required in Section 4.6.1.1. ISA99 has a comment form and is very welcoming of any suggested improvements.</p>
<p>In summary, ISA-62443-3-2 isn&#8217;t going to be of much assistance to an owner/operator doing a risk assessment or a security design unless there is substantial work on the annex. It likely will be a key component of the overall ISA99 standards framework.</p>
<p><em>Image by SludgeGulper</em></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=sdyI4hJL1lg:W4aY1_sIymQ:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=sdyI4hJL1lg:W4aY1_sIymQ:-BTjWOF_DHI"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?i=sdyI4hJL1lg:W4aY1_sIymQ:-BTjWOF_DHI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=sdyI4hJL1lg:W4aY1_sIymQ:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=sdyI4hJL1lg:W4aY1_sIymQ:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?i=sdyI4hJL1lg:W4aY1_sIymQ:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=sdyI4hJL1lg:W4aY1_sIymQ:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?d=qj6IDK7rITs" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/digitalbond/oLPM/~4/sdyI4hJL1lg" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.digitalbond.com/blog/2013/05/06/review-of-isa-62443-3-2-security-risk-assessment-and-system-design/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.digitalbond.com/blog/2013/05/06/review-of-isa-62443-3-2-security-risk-assessment-and-system-design/</feedburner:origLink></item>
		<item>
		<title>Friday News &amp; Notes</title>
		<link>http://feedproxy.google.com/~r/digitalbond/oLPM/~3/U2_SbNWah5E/</link>
		<comments>http://www.digitalbond.com/blog/2013/05/04/friday-news-notes-72/#comments</comments>
		<pubDate>Sat, 04 May 2013 17:52:09 +0000</pubDate>
		<dc:creator>Dale Peterson</dc:creator>
				<category><![CDATA[Critical Intelligence]]></category>
		<category><![CDATA[Friday News & Notes]]></category>

		<guid isPermaLink="false">http://www.digitalbond.com/?p=12208</guid>
		<description><![CDATA[<p><a href="http://digibond.wpengine.netdna-cdn.com/wp-content/uploads/2013/05/duncan.jpg"></a>Apologies for being late with the Friday News &#38; Notes this week. I spent the end of last week getting some inspiration from people that achieve amazing things through passion and incredibly high standards in unrelated fields.</p> <p>Heise, a major German publisher, <a href="http://www.heise.de/newsticker/meldung/Kritische-Schwachstelle-in-hunderten-Industrieanlagen-1854385.html">introduced the German market to the Internet connected ICS</a>. Nothing new here, but some good screen shots of what they found.</p> <p><a href="http://ics-cert.us-cert.gov/jsar/JSAR-12-241-01A">ICS-CERT strangely published 30+ mitigations for Shamoon</a>. Why now? And what to these mitigations have to do with Shamoon? They are basic SCADASEC and INFOSEC 101. Backup, incident response, anti-virus, segment, &#8230; To be charitable this is a worthwhile message to put out over and over again, but if they wanted to take advantage of the Shamoon buzz to get this info out they are quite late. If they wanted to make a more compelling document, they could have tied the recommended controls into the attack and demonstrated how they would have helped prevent, detect or respond to Shamoon. ICS-CERT continues to be weak.</p> <p><a href="http://www.hstoday.us/industry-news/general/single-article/rand-beers-selected-as-acting-dhs-deputy-secretary/210ce43fd2f765e5e801a85672eb273f.html#.UYRXjiJKav4.twitter">Rand Beers has been named the Acting Deputy Secretary of DHS</a>. This may help ICSsec get a bit more attention since Mr. Beers was the Under Secretary for the National Protection and Programs Directorate (NPPD).</p> <p><a href="http://chemical-facility-security-news.blogspot.com/2013/04/nist-announces-meeting-of-ispa-board-6.html">Patrick Coyle reports on a scheduled public meeting of the US Information Security and Privacy Advisory Board</a>. The meeting will address issues related to President Obama&#8217;s Cybersecurity Executive Order.</p> Tweet of the Week #bbpBox_329974483203002370 a { text-decoration:none; color:#203DB0; }#bbpBox_329974483203002370 a:hover { text-decoration:underline; }.@<a href="http://twitter.com/intent/user?screen_name=andrewsmhay" class="twitter-action">andrewsmhay</a> One should aim higher than the target; also&#8230; if target is moving, one must lead the target<a title='tweeted on 2 May 2013 10:03' href='http://twitter.com/#!/joshcorman/status/329974483203002370' target='_blank'>2 May 2013 10:03</a> via <a href="http://www.tweetdeck.com" rel="nofollow" target="blank">TweetDeck</a><a href='https://twitter.com/intent/tweet?in_reply_to=329974483203002370' class='bbp-action bbp-reply-action' title='Reply'>Reply</a><a href='https://twitter.com/intent/retweet?tweet_id=329974483203002370' class='bbp-action bbp-retweet-action' title='Retweet'>Retweet</a><a href='https://twitter.com/intent/favorite?tweet_id=329974483203002370' class='bbp-action bbp-favorite-action' title='Favorite'>Favorite</a><a href='http://twitter.com/intent/user?screen_name=joshcorman'></a><a style='font-weight:bold' href='http://twitter.com/intent/user?screen_name=joshcorman'>@joshcorman</a>Joshua Corman <p>Don&#8217;t forget to <a href="http://feeds.feedburner.com/digitalbond/oLPM">subscribe to this blog RSS feed</a> and <a href="http://twitter.com/digitalbond">follow @digitalbond.com on twitter</a>.</p> Worth Reading Articles <ul> <li>SC Magazine <a href="http://www.scmagazine.com/me-and-my-job-marty-edwards-ics-cert/article/288855/">Brief Interview with Marty Edwards</a> &#60; DP Note: Marty is that sincere, good guy you read in the interview. The last answer is a sad reality though.</li> </ul> Critical Intelligence&#8217;s <a href="http://digitalbond.com/scadapedia/ics-security-event-calendar/">ICS Security Event Calendar</a> Updates <ul> <li><a href="https://www.google.com/calendar/render?eid=ajZtMTZqOHFzdW4wODA5dTh0a2U4NmttaDAgY2FsZW5kYXJAY3JpdGljYWwtaW50ZWxsaWdlbmNlLmNvbQ&#38;sf=true&#38;output=xml">ICSsec presentations at AusCERT</a>, May 23-24 in Gold Coast, Australia</li> <li>APTA <a href="http://www.exida.com/index.php/Training/Register/exida_courses_at_apta_june_5_2013">Securing Control and Communications Systems in Rail Transit Environments</a>, June 5 in Philadelphia, Pennsylvania</li> <li>Rios/McCorkle Black Hat Training <a href="https://www.blackhat.com/us-13/training/ics-for-pentesters%E2%80%93finding-and-exploiting-industrial-control-systems-on-enterprise-networks.html">ICS for Pentesters</a>, July 27-28 and July 29-30 in Las Vegas, Nevada</li> <li><a href="http://www.critis2013.nl/index.html">Conference on Critical Information Infrastructures Security</a>, Sept 16-18 in Amsterdam, The Netherlands</li> <li>ISA <a href="http://www.isa.org/Template.cfm?Section=Event_Calendar1&#38;template=/conference/ShortDescription.cfm&#38;ConferenceID=5685">Advanced Industrial Cybersecurity</a>, Sept 16-20 in Houston, Texas</li> <li><a href="http://www.cybersecurity-chemicals.com/">Cyber Security in the 21st Century for the Chemical and Petrochem Industrie</a>s, Sept 24-25 in Houston, Texas</li> <li><a href="http://www.isa.org/Template.cfm?Section=Event_Calendar1&#38;template=/conference/ShortDescription.cfm&#38;ConferenceID=5687">Using ANSI/ISA99 (IEC 62443) Standards To Secure Your ICS</a>, Oct 17-18 in Houston, Texas</li> </ul> <p><a href="https://www.critical-intelligence.com/">Critical Intelligence</a> provides reports and other information products on  Cyber Situational Awareness and Threat Intelligence services for Industrial Control System Owner/Operators, Vendors and Government stakeholders.</p> <p>Image by duncan</p> ]]></description>
				<content:encoded><![CDATA[<p><a href="http://digibond.wpengine.netdna-cdn.com/wp-content/uploads/2013/05/duncan.jpg"><img class="alignleft size-full wp-image-12210" alt="ICS Security" src="http://digibond.wpengine.netdna-cdn.com/wp-content/uploads/2013/05/duncan.jpg" width="240" height="240" /></a>Apologies for being late with the Friday News &amp; Notes this week. I spent the end of last week getting some inspiration from people that achieve amazing things through passion and incredibly high standards in unrelated fields.</p>
<p>Heise, a major German publisher, <a href="http://www.heise.de/newsticker/meldung/Kritische-Schwachstelle-in-hunderten-Industrieanlagen-1854385.html">introduced the German market to the Internet connected ICS</a>. Nothing new here, but some good screen shots of what they found.</p>
<p><a href="http://ics-cert.us-cert.gov/jsar/JSAR-12-241-01A">ICS-CERT strangely published 30+ mitigations for Shamoon</a>. Why now? And what to these mitigations have to do with Shamoon? They are basic SCADASEC and INFOSEC 101. Backup, incident response, anti-virus, segment, &#8230; To be charitable this is a worthwhile message to put out over and over again, but if they wanted to take advantage of the Shamoon buzz to get this info out they are quite late. If they wanted to make a more compelling document, they could have tied the recommended controls into the attack and demonstrated how they would have helped prevent, detect or respond to Shamoon. ICS-CERT continues to be weak.</p>
<p><a href="http://www.hstoday.us/industry-news/general/single-article/rand-beers-selected-as-acting-dhs-deputy-secretary/210ce43fd2f765e5e801a85672eb273f.html#.UYRXjiJKav4.twitter">Rand Beers has been named the Acting Deputy Secretary of DHS</a>. This may help ICSsec get a bit more attention since Mr. Beers was the Under Secretary for the National Protection and Programs Directorate (NPPD).</p>
<p><a href="http://chemical-facility-security-news.blogspot.com/2013/04/nist-announces-meeting-of-ispa-board-6.html">Patrick Coyle reports on a scheduled public meeting of the US Information Security and Privacy Advisory Board</a>. The meeting will address issues related to President Obama&#8217;s Cybersecurity Executive Order.</p>
<h3>Tweet of the Week</h3>
<!-- tweet id : 329974483203002370 --><style type='text/css'>#bbpBox_329974483203002370 a { text-decoration:none; color:#203DB0; }#bbpBox_329974483203002370 a:hover { text-decoration:underline; }</style><div id='bbpBox_329974483203002370' class='bbpBox' style='padding:20px; margin:5px 0; background-color:#642D8B; background-image:url(http://a0.twimg.com/profile_background_images/647029274/f7ni9h90g0175zjs2ub3.jpeg);'><div style='background:#fff; padding:10px; margin:0; min-height:48px; color:#3D1957; -moz-border-radius:5px; -webkit-border-radius:5px;'><span style='width:100%; font-size:18px; line-height:22px;'>.@<a href="http://twitter.com/intent/user?screen_name=andrewsmhay" class="twitter-action">andrewsmhay</a> One should aim higher than the target; also&#8230; if target is moving, one must lead the target</span><div class='bbp-actions' style='font-size:12px; width:100%; padding:5px 0; margin:0 0 10px 0; border-bottom:1px solid #e6e6e6;'><img align='middle' src='http://digibond.wpengine.netdna-cdn.com/wp-content/plugins/twitter-blackbird-pie//images/bird.png' /><a title='tweeted on 2 May 2013 10:03' href='http://twitter.com/#!/joshcorman/status/329974483203002370' target='_blank'>2 May 2013 10:03</a> via <a href="http://www.tweetdeck.com" rel="nofollow" target="blank">TweetDeck</a><a href='https://twitter.com/intent/tweet?in_reply_to=329974483203002370' class='bbp-action bbp-reply-action' title='Reply'><span><em style='margin-left: 1em;'></em><strong>Reply</strong></span></a><a href='https://twitter.com/intent/retweet?tweet_id=329974483203002370' class='bbp-action bbp-retweet-action' title='Retweet'><span><em style='margin-left: 1em;'></em><strong>Retweet</strong></span></a><a href='https://twitter.com/intent/favorite?tweet_id=329974483203002370' class='bbp-action bbp-favorite-action' title='Favorite'><span><em style='margin-left: 1em;'></em><strong>Favorite</strong></span></a></div><div style='float:left; padding:0; margin:0'><a href='http://twitter.com/intent/user?screen_name=joshcorman'><img style='width:48px; height:48px; padding-right:7px; border:none; background:none; margin:0' src='http://a0.twimg.com/profile_images/2045128971/Corman_VF_Square_normal.jpg' /></a></div><div style='float:left; padding:0; margin:0'><a style='font-weight:bold' href='http://twitter.com/intent/user?screen_name=joshcorman'>@joshcorman</a><div style='margin:0; padding-top:2px'>Joshua Corman</div></div><div style='clear:both'></div></div></div><!-- end of tweet -->
<p><em><img title="More..." alt="" src="https://www.digitalbond.com/wp-includes/js/tinymce/plugins/wordpress/img/trans.gif" />Don&#8217;t forget to <a href="http://feeds.feedburner.com/digitalbond/oLPM">subscribe to this blog RSS feed</a> and <a href="http://twitter.com/digitalbond">follow @digitalbond.com on twitter</a>.</em></p>
<h3><img title="More..." alt="" src="https://www.digitalbond.com/wp-includes/js/tinymce/plugins/wordpress/img/trans.gif" /><br />
Worth Reading Articles<img title="More..." alt="" src="https://www.digitalbond.com/wp-includes/js/tinymce/plugins/wordpress/img/trans.gif" /></h3>
<ul>
<li>SC Magazine <a href="http://www.scmagazine.com/me-and-my-job-marty-edwards-ics-cert/article/288855/">Brief Interview with Marty Edwards</a> &lt; DP Note: Marty is that sincere, good guy you read in the interview. The last answer is a sad reality though.</li>
</ul>
<h3>Critical Intelligence&#8217;s <a href="http://digitalbond.com/scadapedia/ics-security-event-calendar/">ICS Security Event Calendar</a> Updates</h3>
<ul>
<li><a href="https://www.google.com/calendar/render?eid=ajZtMTZqOHFzdW4wODA5dTh0a2U4NmttaDAgY2FsZW5kYXJAY3JpdGljYWwtaW50ZWxsaWdlbmNlLmNvbQ&amp;sf=true&amp;output=xml">ICSsec presentations at AusCERT</a>, May 23-24 in Gold Coast, Australia</li>
<li>APTA <a href="http://www.exida.com/index.php/Training/Register/exida_courses_at_apta_june_5_2013">Securing Control and Communications Systems in Rail Transit Environments</a>, June 5 in Philadelphia, Pennsylvania</li>
<li>Rios/McCorkle Black Hat Training <a href="https://www.blackhat.com/us-13/training/ics-for-pentesters%E2%80%93finding-and-exploiting-industrial-control-systems-on-enterprise-networks.html">ICS for Pentesters</a>, July 27-28 and July 29-30 in Las Vegas, Nevada</li>
<li><a href="http://www.critis2013.nl/index.html">Conference on Critical Information Infrastructures Security</a>, Sept 16-18 in Amsterdam, The Netherlands</li>
<li>ISA <a href="http://www.isa.org/Template.cfm?Section=Event_Calendar1&amp;template=/conference/ShortDescription.cfm&amp;ConferenceID=5685">Advanced Industrial Cybersecurity</a>, Sept 16-20 in Houston, Texas</li>
<li><a href="http://www.cybersecurity-chemicals.com/">Cyber Security in the 21st Century for the Chemical and Petrochem Industrie</a>s, Sept 24-25 in Houston, Texas</li>
<li><a href="http://www.isa.org/Template.cfm?Section=Event_Calendar1&amp;template=/conference/ShortDescription.cfm&amp;ConferenceID=5687">Using ANSI/ISA99 (IEC 62443) Standards To Secure Your ICS</a>, Oct 17-18 in Houston, Texas</li>
</ul>
<p><a href="https://www.critical-intelligence.com/">Critical Intelligence</a><em> provides reports and other information products on  Cyber Situational Awareness and Threat Intelligence services for Industrial Control System Owner/Operators, Vendors and Government stakeholders.</em></p>
<p><em>Image by duncan</em></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=U2_SbNWah5E:HJgOJisKZ7A:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=U2_SbNWah5E:HJgOJisKZ7A:-BTjWOF_DHI"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?i=U2_SbNWah5E:HJgOJisKZ7A:-BTjWOF_DHI" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=U2_SbNWah5E:HJgOJisKZ7A:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?d=7Q72WNTAKBA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=U2_SbNWah5E:HJgOJisKZ7A:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?i=U2_SbNWah5E:HJgOJisKZ7A:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/digitalbond/oLPM?a=U2_SbNWah5E:HJgOJisKZ7A:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/digitalbond/oLPM?d=qj6IDK7rITs" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/digitalbond/oLPM/~4/U2_SbNWah5E" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.digitalbond.com/blog/2013/05/04/friday-news-notes-72/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.digitalbond.com/blog/2013/05/04/friday-news-notes-72/</feedburner:origLink></item>
	</channel>
</rss>
