HITB-Invoice-Logo

thank you for joining us!

ICEFALL – Revisiting a Decade of OT Insecure-by-Design Practices

Date

August 25, 2022

Time

16:30

Track

CommSec Track

More than a decade ago, Project Basecamp highlighted how many OT devices and protocols deployed in a wide variety of industries and critical infrastructure applications were insecure-by-design. Ever since, it’s been common knowledge that one of the biggest issues facing OT security is not so much the presence of unintentional vulnerabilities but the persistent absence of basic security controls. While the past decade has seen the advent of standards-driven hardening efforts at the component and system level it has also seen impactful real-world OT incidents like Industroyer and TRITON abusing insecure-by-design functionality, which has left many defenders wondering just how much has changed.

In this talk, we will present dozens of previously undisclosed issues in products from almost 20 vendors deployed in industry verticals ranging from oil & gas, chemical and power generation to water management, mining and manufacturing. We will provide a quantitative overview of these issues, which range from persistent insecure-by-design practices in security-certified products to failed attempts to move away from them, in order to illustrate how the opaque and proprietary nature of these systems, the suboptimal vulnerability management surrounding them and the often false sense of security offered by certifications significantly complicate OT risk management efforts.

In addition, we will take a technical deep-dive into several of the issues to demonstrate the ability of attackers to achieve remote code execution on critical Level 1 devices using nothing but intended functionality and discuss its defensive implications. Finally, we will present quantitative insights into our research process in order to provide the audience with some hard numbers on the resources required to develop basic offensive capabilities for the issues discussed and its potential implications for the relevant threat landscape.

Speakers

Researcher

National University Singapore

Dr. Wang Kailong is currently a research fellow at National University of Singapore (NUS). He received his PhD degree from School of Computing NUS in 2022. He has worked as a Research Assistant in NUS while pursuing his PhD degree from 2016 to 2021. His research interests include mobile and web security and privacy, and protocol verification. His works have appeared in the top conferences such as WWW and MobiCom.

Co-Founder & CTO

Authomize

Mr. Gal Diskin is a cybersecurity and AI researcher. He was previously the VP & head of Palo Alto Networks’ Israeli site, and is a serial entrepreneur. Mr. Diskin’s research has been featured in HITB, Defcon, Black Hat, CCC, and other conferences, spanning fields from low level security research such as hardware vulnerabilities, binary instrumentation, and car hacking to high level research on AI detection methods, Enterprise security, and Identity security. Mr. Diskin was also the technical lead and co-founder of Intel’s software security organization, as well as the CTO of Cyvera and HeXponent (co-founder) before their acquisition.

Senior Security Researcher

Huajiang โ€œKevin2600โ€ Chen (Twitter: @kevin2600) is a senior security researcher. He mainly focuses on vulnerability research in wireless and Vehicle security. He is a winner of GeekPwn 2020 and also made to the Tesla hall of fame 2021. Kevin2600 has spoken at various conferences including KCON; DEFCON and CANSECWEST.

Security Researcher

Li Siwei is a security researcher. He specializes in Big data analysis and AI Security.

Founder, CEO

CloudSEK

Rahul Sasi is an Indian entrepreneur, Founder of CloudSEK, and a security expert. He was voted as the top influential Cyber Security person in 2015, he has made a significant open source contribution to the security landscape and is an invited speaker to over 20+ countries. He is part of the working committees of RBI and MeitY.
CloudSEK : https://cloudsek.com/
LinkedIn: https://www.linkedin.com/in/fb1h2s/

Senior Security Engineer

CloudSEK

Vishal Singh is working as a Senior Security Engineer at CloudSEK. His main responsibility includes handling the Research & Development of CloudSEK ASM. He loves automating manual effort tasks, and also likes net surfing & exploring new places in his free time.

Other Talks in This Track

LOCATION

CommSec Track

DATE

August 26

TIME

16:30

LOCATION

CommSec Track

DATE

August 26

TIME

17:30

LOCATION

CommSec Track

DATE

August 26

TIME

12:00