This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
OWASP AppSec DC 2012/Denial of Surface
From OWASP
Revision as of 20:51, 2 March 2012 by Mark.bristow (talk | contribs) (Created page with "<noinclude>{{:OWASP AppSec DC 2012 Header}}</noinclude> __NOTOC__ == The Presentation == rightAre industrial systems airgapped?<br>Some are, s...")
Registration Now OPEN! | Hotel | Schedule | Convention Center | AppSecDC.org
The Presentation
Are industrial systems airgapped?Some are, some aren't. Unfortunately, enough of them aren't...to suggest bigger questions. Shodan has provided us with over 10,000 proofs of ICS connectivty, and visualization is the key to this story. More importantly, this data was provided to ICS-CERT to help mitigate such exposure. That data was in turn shared globally with other CERTS and CSIRTS, and the lessons are still being learned.
It's time to re-examine the fantasy of the airgap, and think of ways to do vulnerability and exposure management in vendor and owner agnostic ways. More importantly, how do you do vulnerability management at a national or international scale?
This is not a story of 'I found a couple scary things in SHODAN'. This is a theory of the underlying cause for being able to find THOUSANDS of ICS devices and logins on the open internet. Complete with open source eye-candy!
The Speakers
Eireann Leverett
Gold Sponsors |
||||
Silver Sponsors |
||||
Small Business |
||||
Exhibitors |