SCADA Fear, Uncertainty, and the Digital Armageddon Presented By Morgan MarquisBoire © 2007 SecurityAssessment.com Whois Hi, My Name is Morgan © 2007 SecurityAssessment.com Whois Hi, My Name is Morgan I’m a security guy © 2007 SecurityAssessment.com Whois Hi, My Name is Morgan I’m a security guy SecurityAssessment.com © 2007 SecurityAssessment.com Whois Hi, My Name is Morgan I’m a security guy SecurityAssessment.com Kiwicon © 2007 SecurityAssessment.com Introduction Today we will be covering SCADA What is it? Why is it so hip right now? How do we bust it? When good SCADA goes bad Are there cyberterrorists lurking in the bushes outside my SCADA installation? SCADA security and Securing your SCADA networks Questions © 2007 SecurityAssessment.com What the hell is SCADA? SCADA is… Industrial Control Systems (ICS), commonly referred to as SCADA underlie much of the infrastructure that makes every day life possible in the modern world. © 2007 SecurityAssessment.com What the hell is SCADA? SCADA is… Industrial Control Systems (ICS), commonly referred to as SCADA underlie much of the infrastructure that makes every day life possible in the first world. Supervisory Control and Data Acquisition SCADA systems support processes that manage water supply and treatment plants; Control pipes line distribution systems and power grids; Operate chemical and in other countries, nuclear power plants; HVAC systems – Heating, Ventilation, Air Conditioning Lift / Elevator Systems Traffic Signals Mass transit systems © 2007 SecurityAssessment.com What the hell is SCADA? SCADA Networks – Past and Present These could be described as “primitive” when compared to most modern networks Proprietary Hardware & Software (Past) Manuals and procedures not widely available Closed systems considered to be immune to outside threats Interconnected Networks (Present) Utility Networks, Corporate Networks, Internet DNP3 over TCP/IP Modern stuff is susceptible to modern (or perhaps not so modern) attacks (SYN Flood, Ping of death) © 2007 SecurityAssessment.com What the hell is SCADA? So what is it actually? A SCADA system usually includes signal hardware (input and output), controllers, networks, user interface (HMI), communications equipment and software. All together, the term SCADA refers to the entire central system. The central system usually monitors data from various sensors that are either in close proximity or off site (sometimes miles away). © 2007 SecurityAssessment.com
Description: