Título: Jurassic Pcap
Autores: Aarón Flecha y Jairo Alonso
Resumen: Presentación de entornos industriales y sus redes, centrándose en el análisis y tratamiento de capturas de tráfico con protocolos propietarios. Desarrollo de filtros y disectores.
5. Introduction
Information Technology Operation Technology
System Life Cycle Component lifetime 3-5 years Component lifetime: 10-20+ years
Security Level Maturity and knowledge on cybersecurity First steps on cybersecurity. Lack of awareness
Security Standards ISO 27002, COBIT, NIST, etc. IEC 62443, NERC CIP, IEEE 1686, etc.
Architectures Standard methodologies and architectures Isolated, all connected (new paradigm)
Patching
Straightforward upgrades and automated
changes
Infrequent to nearly impossible
Data Confidentiality Low - High Low - Moderate
Data Integrity Low - Moderate Very High
Availability Low - Moderate Very High (99.9999% uptime common)
Throughput High Modest
Time Criticality Delays tolerated Critical
Operating Systems COTS COTS, RTOS, Embedded OS (Firmware)
Communication Protocols TCP/IP primarily HART, DNP3, Mod/FieldBus, ICCP, TCP/IP, etc.
Communication Topology LAN/WAN, Telco, etc. LAN/WAN, Telco, Satellite, Serial, etc.
IT OTVs
7. Introduction
HumanMachineInterfaceRemoteTerminalUnit
ProgrammableLogicController
They show information of the state of
theprocessessothatoperatorscoordinate
andcontroltheactionstobecarriedout.
Sometimes, they allow actions to adjust
theprocessormodifyvariables.
They allow to obtain signals
from the processes and send the
information to a remote site
whereitisprocessed.
It allows to automate processes
thankstoitsprogramming. Theyhave
digitaloranalogoutputsandinputs.
8. Introduction
SupervisoryControlAnd
DataAcquisition
Performs actions of supervision,
control and management of
informationinrealtime.
Theyallowacentralizationofsignals
generatedbyone orseveral industrial
processes(alertcontrol).
It communicates with a multitude of
deviceslocatedinthecontrolnetwork
(PLC, RTU, HMI, etc.)
14. IndustrialProtocols
IEC104
Often on TCP port
2404 (can also be on
2405 if two masters
areonthesamenetwork)
Protocol of the electric sector
that is used for communications
betweenelectricalsubstationsand
controlcentres