Eric Byres

Sons of Stuxnet Make Global Energy Infrastructure Vulnerable to Attack

June 2012


News update from Eric Byres

 

June 6, 2012

 

Stuxnet, the computer worm widely believed to have been created by western government agencies to target certain countries’ industrial software and equipment, now has some very capable offspring.

 


7 Steps to ICS and SCADA Security

February 2012


 

Cyber security threats, from sophisticated malware like Stuxnet, Night Dragon and Duqu, or from the publishing of an unprecedented number of security vulnerabilities, are causing a major disruption in the industrial automation market.

 

If you are a process control engineer, an IT professional in a company with an automation division, or a business manager responsible for safety or security, you may be wondering how your organization can get moving on more robust cyber security practices. 

 

Two industry veterans, Eric Byres and John Cusimano, combine industry standards, best practice materials, and their real-world experience to provide an easy-to-follow 7-step process for improved ICS and SCADA security.


AusCERT 2011: Ranking Australian Engineers on SCADA Security

January 2012


AusCERT 2011: Ranking Australian Engineers on SCADA Security


AusCERT 2011: Eric Byres demonstrates SCADA protection

January 2012


AusCERT 2011: Eric Byres demonstrates SCADA protection


HUG TV: Boyes and Byres Talk Cybersecurity

January 2012


HUG TV: Boyes and Byres Talk Cybersecurity


"How Stuxnet Spreads" White Paper

March 2011


News coverage following the release of the White Paper "How Stuxnet Spreads A Study of Infection Paths in Best Practice Systems" by Eric Byres, Andrew Ginter, and Joel Langill.


Industrial Control System Security Best Practices Inadequate in Blocking Advanced Malware Threats

February 2011


New "How Stuxnet Spreads" White Paper by three leading industrial security experts describes Stuxnet infection pathways and discusses how to protect SCADA systems......



Membership is requiredMember Login Required

Due to the sensitive nature of this document, you must be logged in to access it.


Login      Register to become a site member (free)     Contact Us


How Stuxnet Spreads – A Study of Infection Paths in Best Practice Systems

February 2011


 Byres Security Abterra and SCADAhacker logos

The Stuxnet worm is a sophisticated piece of computer malware designed to sabotage industrial processes controlled by Siemens SIMATIC WinCC and PCS 7 control systems.

 

This paper describes an example of a site following high security architecture best practices and then shows the ways that the worm could make its way through the defences of the site to take control of the process and cause physical damage.

 

The paper closes with a discussion of the lessons that can be learned from the analysis of Stuxnet’s propagation pathways. It explains how owners of critical systems need to respond to protect control systems from future threats of this type.



Membership is requiredMember Login Required

Due to the sensitive nature of this document, you must be logged in to access it.


Login      Register to become a site member (free)     Contact Us


Stuxnet Mitigation Matrix

October 2010


Stuxnet is a computer worm designed to take advantage of a number of previously unknown vulnerabilities present in the Windows operating system and Siemens SIMATIC WinCC, PCS7 and S7 PLS systems.

 

It takes advantage of numerous vulnerabilities in the Windows operating system and the Siemens product line.  As a result, full mitigation requires multiple actions.

 

The Stuxnet Mitigation Matrix shows mitigation measures by Windows operating system and it includes dynamic links to detailed information on each of the patches and mitigations.


2010 Belden Mission-Critical Network Design Seminar

September 2010


Orlando, Florida

September 19 - 22, 2010

 

Tofino Security speaker:

Eric Byres, CTO

 

Topic: The Good, Bad, and the Ugly Futures of Control System Security

Date: Tuesday, September 21, 2010



Syndicate content