Through the Eyes of the Attacker: Designing Embedded Systems Exploits for Industrial Control Systems

No ratings

Presented at IT-DefenseStuttgart 2019 by

Industrial Control Systems (ICS) threat landscape has changed dramatically over the past few years. New threats have emerged to challenge the shock created by Stuxnet. This talk will present the evolution of the ICS exploits and tactics to picture ongoing „race-to-the-bottom-situation” between ICS threat actors and defenders. The discussion will “descend” all the way to the physical process, showing that cyber-physical systems cannot be secured only by the means of canonical IT security approaches. Physical world can be exploited by unconventional methods and therefore needs to be taken into consideration when securing ICS. Additional attention will be given to the relationship between security and safety, and how current cyber threats may undermine traditional safety design decisions.While the process of finding security weaknesses in the embedded devices is well understood, little is known how the discovered vulnerabilities can be weaponized. The goal of this talk is to provide the audience with a “through the eyes of the attacker” experience when designing advanced embedded systems exploits & implants as part of cyber-physical attacks. Attendees will learn cyber-physical attack life cycle and will be provided with the details on strategies for implants stability and exploits reliability.The State of AI-assisted Fuzzing & Program Analysis – Clarence ChioFuzzing and program analysis are a security professional’s bread and butter. The faster we are able to find bugs in software, the more effectively we are able to secure systems. However, system and code complexity has been exponentially increasingly over time, and exhaustively analyzing programs is becoming an intractable task. In this talk, I analyze 10 of the most exciting research papers published in the last few years and try to identify trends of how this field is progressing. I will show that AI-assisted program analysis is the only way forward, and share some ideas of where the field is heading in the future.