modern malware demands modern defense · blackenergy 2 (various ics modules) ny dam intrusion tion...

11
Modern Malware Demands Modern Defense Robert M. Lee & Tim Conway ICS.SANS.ORG

Upload: others

Post on 28-May-2020

4 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Modern Malware Demands Modern Defense · BlackEnergy 2 (various ICS modules) NY Dam Intrusion TION BE3 (Loss of Safety, Reliability, Assets) Dec 2016 Ukraine Power Outage Dec 2015

Modern Malware Demands Modern Defense

Robert M. Lee & Tim Conway

ICS.SANS.ORG

Page 2: Modern Malware Demands Modern Defense · BlackEnergy 2 (various ICS modules) NY Dam Intrusion TION BE3 (Loss of Safety, Reliability, Assets) Dec 2016 Ukraine Power Outage Dec 2015
Page 3: Modern Malware Demands Modern Defense · BlackEnergy 2 (various ICS modules) NY Dam Intrusion TION BE3 (Loss of Safety, Reliability, Assets) Dec 2016 Ukraine Power Outage Dec 2015

Learning LeadingDefending

Page 4: Modern Malware Demands Modern Defense · BlackEnergy 2 (various ICS modules) NY Dam Intrusion TION BE3 (Loss of Safety, Reliability, Assets) Dec 2016 Ukraine Power Outage Dec 2015

Learning

Page 5: Modern Malware Demands Modern Defense · BlackEnergy 2 (various ICS modules) NY Dam Intrusion TION BE3 (Loss of Safety, Reliability, Assets) Dec 2016 Ukraine Power Outage Dec 2015

Defending

Page 6: Modern Malware Demands Modern Defense · BlackEnergy 2 (various ICS modules) NY Dam Intrusion TION BE3 (Loss of Safety, Reliability, Assets) Dec 2016 Ukraine Power Outage Dec 2015

Defending

Page 7: Modern Malware Demands Modern Defense · BlackEnergy 2 (various ICS modules) NY Dam Intrusion TION BE3 (Loss of Safety, Reliability, Assets) Dec 2016 Ukraine Power Outage Dec 2015

ics-community.sans.org

Major Public ICS Incidents & Access Campaigns

Low HighICS IMPACTS

High

ICS Recon

Stuxnet (all versions)

(Nuisance) (Lost Productivity/Data) (Lost Value)

ICS Targeting

ICS Delivery

ICS Exploits

ICS Payload

Low

UnspecifiedGerman Facility

Havex(OPC module)

Critical InfrastructureData Exfiltration

BlackEnergy 2(various ICS modules)

NY Dam Intrusion

BE3

ICS

CU

STO

MIZ

ATI

ON

(Loss of Safety, Reliability, Assets)

Dec 2016Ukraine Power Outage

Dec 2015Ukraine Power Outage

Stage One

Stage Two

TRISIS

Defending

Page 8: Modern Malware Demands Modern Defense · BlackEnergy 2 (various ICS modules) NY Dam Intrusion TION BE3 (Loss of Safety, Reliability, Assets) Dec 2016 Ukraine Power Outage Dec 2015

ics-community.sans.org

ICS

Atta

cks

225kUkraine 2015

Three electric utilities attacked through a cyber means resulting in 225k customers out of power

200 MW

Ukraine 2016Electric transmission substation attacked

through a cyber means

SISMiddle East Facility 2017

Safety Instrumented System, targeted and

impacted

?Combination

Safety or protection system manipulation

followed by intentional control system misuse to cause equipment damage

and human health and safety impact

Defending

Page 9: Modern Malware Demands Modern Defense · BlackEnergy 2 (various ICS modules) NY Dam Intrusion TION BE3 (Loss of Safety, Reliability, Assets) Dec 2016 Ukraine Power Outage Dec 2015

ics-community.sans.org

Leading

Vendors

EducatorsICS

Community OEM

Government

Asset Owners

Integrators

Page 10: Modern Malware Demands Modern Defense · BlackEnergy 2 (various ICS modules) NY Dam Intrusion TION BE3 (Loss of Safety, Reliability, Assets) Dec 2016 Ukraine Power Outage Dec 2015

ics-community.sans.org

Vendors

EducatorsOEM

Government

Asset Owners

IntegratorsLearning LeadingDefending

Page 11: Modern Malware Demands Modern Defense · BlackEnergy 2 (various ICS modules) NY Dam Intrusion TION BE3 (Loss of Safety, Reliability, Assets) Dec 2016 Ukraine Power Outage Dec 2015

Join the Community that is defending our Critical Infrastructure