Network Security Consulting Agency Since 1989 - Specialized in Unix, Windows, TCP/IP and Internet
You are here
:
Home
>
Resources
>
Lectures
> Industrial control systems security. Scadastrophe... or not.
Go to:
HSC Trainings
Search
:
Services
Skills & Expertise
Consulting
ISO 27001 services
Audit & Assessment
Penetration tests
Vunerability assessment (TSAR)
Forensics
ARJEL
Training courses
E-learning
Conferences
Agenda
Past events
Tutorials
Resources
Thematic index
Tips
Lectures
Courses
Articles
Tools (download)
Vulnerability watch
Company
Hervé Schauer
Team
Job opportunities
Credentials
History
Partnerships
Associations
Press and
communication
HSC Newsletter
Press review
Press releases
Publications
Contacts
How to reach us
Specific inquiries
Directions to our office
Hotels near our office
Industrial control systems security. Scadastrophe... or not.
Access to the content
Beginning of the presentation
PDF version
[4.2M]
Adobe Flash version
Description
Presentation about the security of industrial control systems (SCADA / ICS).
Context & Dates
Talk presented during OSSIR Paris, on 15 May 2012.
Author
Stéphane Milani (Stephane.Milani@hsc.fr)
Type
[
-
]
Abstract &
Table of content
Flyleaf
Réseaux industriels / SCADA
Attaques récentes (Mars - Avril 2012)
Composants essentiels
Vannes et automates
IHM (Interface Homme-Machine)
IHM (Interface Homme-Machine)
Configuration courante - réseau
Protocoles
Protocole Modbus/TCP
Protocole IEC 104
Protocole S7
Protocole EtherNet/IP CIP
Protocole DNP3 (IEEE Std 1815)
Sécurité ?
Architecture
Automates PLC : exemple Schneider
Automates
Automates
Failles impactant les IHM
Sans fil ?
Moteurs de recherche
Sûreté vs sécurité
Retours d’expérience Accès au réseau industriel
Tests depuis un réseau industriel
Intrusion depuis un réseau Bureautique
Intrusion depuis un réseau Bureautique
Intrusion depuis un réseau Bureautique
Usines isolées - Accès distants
Usines isolées - Accès distants
Autres exemples
Attaques ciblées / APT / Ver / Virus
Quid des petites infrastructures ?
iPhone / Android / BlackBerry
Radio / Capteurs
Etude d'un boîtier de télétransmission (RTU)
Boîtiers de télétransmission (RTU)
Étude de la sécurité d'un RTU
HTTP RTU
Serveur FTP
Firmware
Quelques Solutions
Pistes...
Pistes...
Pistes...
Quelques solutions
Quelques solutions
Docs / Standards / Normes utiles US
Docs / Recommandations ENISA Europe
Related documents
Audit
Audit & Assessment
Feedback on RGS compliance
[27 May 2011 -
]
Infiltrate 2011 report
[16 April 2011 -
]
Feedback on security audits
[1 April 2008 -
]
Technicals Security Audits for BS7799
[24 May 2005 -
]
Useful standards for network security
[20 October 2003 -
]
Audits, Assessments and Penetration Tests
[22 January 2003 -
]
Audits, Assessments and Penetration Tests
[26 June 2002 -
]
Network auditing
[12 November 1997 -
]
Tests and evaluation of Internet security solutions
[30 May 1997 -
]
Autohack
[13 June 1995 -
]
Satan
[11 April 1995 -
]
Network Partitionning
Deperimetrization or not ?
[22 November 2007 -
]
Network security stakes
[14 October 2004 -
]
Networks Security
[25 July 2000 -
]
Distributed Network Security
[12 May 2000 -
]
Distributed Network Security
[15 December 1999 -
]
Distributed Network Security - From Firewall to Network Partitioning
[30 November 1999 -
]
Distributed Network Security - From the Firewall to Network Partitionning
[November 1999 -
]
Le cloisonnement de réseaux
[18 August 1999 -
]
Network Partitioning
[August 1997 -
]
Private networks partitioning
[8 July 1997 -
]
Intranets partitioning
[June 1997 -
]
Security Architectures
Multi-layers in depth security
[19 March 2011 -
]
Évolution des attaques de type Cross Site Request Forgery
[1 June 2007 -
]
Tunnels detection at network border
[2 June 2006 -
]
Détection de tunnels aux limites du périmètre
[2 June 2006 -
]
How to make one's Internet security
[5 January 2002 -
]
Security architecture for connecting to the Internet
[18 December 2001 -
]
How to set up security systems?
[29 March 2001 -
]
How to insert VPNs in existing security architectures?
[29 September 1999 -
]
TAFIM - Technical Architecture Framework for Information Management
[May 1997 -
]
How to build a secure Internet access architecture?
[October 1995 -
]
Penetration tests
Vunerability assessment (TSAR)
Penetration tests
Advanced Penetration Testing, Exploits and Ethical Hacking - SANS SEC660
Network Penetration Testing and Ethical Hacking - SANS SEC560
Web App Penetration Testing and Ethical Hacking - SANS SEC542
Patator tool
[Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage. -
]
Dislocker tool
[This software has been designed to read BitLocker encrypted partitions under a Linux system. -
]
skyrack tool
[Tool to help ROP oriented exploitation -
]
Skyrack, rop for masses
[17 June 2011 -
]
Infiltrate 2011 report
[16 April 2011 -
]
Delphes tool
[Delphes extracts the usernames and passwords from Oracle file. -
]
Penetration tests: Exposing real world attacks
[9 February 2011 -
]
27C3 report
[8 February 2011 -
]
Webef tool
[Bruteforcer of web server files and directories -
]
BlueBerry tool
[BlueBerry is a tool that can be used to decrypt BlackBerry Administration Service passwords. -
]
Webshells, or how to open your network's doors ?
[21 October 2010 -
]
passe-partout tool
[In-memory extraction of SSL private keys -
]
Webshells, or how to open your network's doors ?
[16 March 2010 -
]
Webshells, real threat for information systems ?
[1 December 2009 -
]
Web Attacks with Smartphone
[4 June 2009 -
]
Security issue seen in enterprises web applications
[27 November 2008 -
]
Feedback on security audits
[1 April 2008 -
]
WSPP tool
[WSPP -
]
Modern techniques of IP attacks
[18 March 2003 -
]
Audits, Assessments and Penetration Tests
[22 January 2003 -
]
Audits, Assessments and Penetration Tests
[26 June 2002 -
]
Nmap's hidden option
[27 December 2000 -
]
jis & wis tool
[JBoss AS administration tools using HTTP invokers -
]
Introduction to intrusion tests
[17 March 1998 -
]
Tests and evaluation of Internet security solutions
[30 May 1997 -
]
Intrusion tests
[December 1996 -
]
Copyright
© 2012, Hervé Schauer Consultants, all rights reserved.
Last modified on 15 May 2012 at 21:21:40 CET - webmaster@hsc.fr
Information on this server
- © 1989-2010 Hervé Schauer Consultants