Day 4 Cyber Analysis Course Slides
Total Page:16
File Type:pdf, Size:1020Kb
Introduction to Cyber Analysis Course April 1‐4, 2019 DAY 4 – APRIL 4, 2019 DAY 3 RECAP . Writing Exercise . Tools and Activities –IQF – Virtualization – Kali Linux –NMAP CYBER ANALYSIS – Metasploit TRAINING COURSE –Nikto –SQLMap –Burp Suite –OWASP ZAP – CAIN and Abel – OpenVAS 2 DAY 4: AGENDA 4.1 Cyber Physical Systems - Industrial Control Systems - Shodan 4.1 CYBER PHYSICAL SYSTEMS - Internet of Things – Industrial Control Systems – Shodan – Internet of Things 4.2 Writing Exercise 4.3 Darknets, P2P, and Onion Routing 4.4 Wrap-Up 4 3 INDUSTRIAL CONTROL SYSTEMS (ICS) ICS - SCADA . An Industrial Control System (ICS) is a term that describes . SCADA systems are commonly used in the following critical several types of control systems used in industrial protection, infrastructure sectors: such as: – Public and private sector (buildings, airports, ships, space stations) – Supervisory Data and Acquisition Systems (SCADA) • Water treatment and distribution plants – Distributed Control Systems (DCS) • Wastewater treatment and collection plants – Programmable Logic Controllers (PLC) • Oil and gas pipelines • Electrical power (transmission and distribution) • Wind farms • Communication systems 5 Argonne National Laboratory 1 Introduction to Cyber Analysis Course April 1‐4, 2019 INDUSTRIAL CONTROL SYSTEMS (ICS) INDUSTRIAL CONTROL SYSTEMS (ICS) . ICS systems are commonly found in the CI sectors as well as ICS electrical, water, wastewater, oil, gas, and data industries. Human Machine Remote diagnostics/ Corporate . An ICS will receive data from remote stations, and (automated or Interface (HMI) maintenance Data operator-driven) supervisory commands can be pushed to Network remote station control devices (field devices). Data Controller . Field devices are responsible for controlling local operations, Historian such as: Actuator Sensors Internet – Opening and closing valves and breakers – Collecting data from sensory systems Actuators: composed of valves, switches, motors Industrial Sensors: detect status of variables associated with the – Monitoring for alarm conditions Process industrial process (temperature, pressure, flow rates) Controller: Manages the actuators based on sensor readings and operator input HMI: Allows operators to monitor the controlled process and influence it Data Historian: Logs all process control activity to allow reporting at multiple levels Remote Diagnostics: Maintenance that provide ICS staff/vendors to access, diagnose, and correct problems 7 8 ICS – SCADA ICS – PLC . Supervisory Control and Data Acquisition (SCADA) systems . Programmable Logic Controllers (PLC) are digital computers that operate with coded signals that provide control of remote automate industrial (electromechanical) processes, such as: equipment – Controlling machinery on assembly lines – Sequential relay control . Control systems can be combined with data acquisition by – Motion control adding coded signals to acquire status information of remote – Process control equipment for display/recording –Networking . SCADA systems refer to centralized systems that monitor and – Distributed Control Systems (DCS) control entire sites, or complexes of systems over large areas. • PLCs are frequently used by the following industries: . Most control actions are performed automatically by Remote – Power and mining industries Terminal Units (RTUs) or by PLCs – Military – Water and wastewater industries • PLCs will be present anywhere a logical sequence of processes must be followed by machines 9 10 ICS – PLC ICS – HMI . PLCs can have digital or analog I/Os, and can handle extreme . Human–machine interface (HMI) is the user interface that temperature ranges. handles the human to machine interaction. – Resistant to vibration, impact, and electrical noise. It is the I/O device through which the human operator controls . Some modern PLCs are equivalent to desktop computers in the the process. ability to handle data, storage, processing power, and . Types of user interfaces include: communication – Interactive aspects of an OS . Programs that control PLCs are usually stored in non-volatile – Hand tools memory, or with a battery backup. – Heavy machinery operator controls – Process controls . A Human-machine Interface (HMI) is employed to help with configuration, alarm reporting and every control interactions. 11 12 Argonne National Laboratory 2 Introduction to Cyber Analysis Course April 1‐4, 2019 ICS – SCADA SCADA DIAGRAM . SCADA systems can be found in a variety of industries, including but not limited to: – Manufacturing – Production – Power generation – Fabrication – Refining 13 ICS – SCADA: THREAT VECTORS ICS – SCADA: VENDORS . Unauthorized access to the control software, whether it be . Some examples of SCADA vendors: human access or changes induced intentionally or accidentally by virus infections and other software threats residing on the – Siemens. control host machine. – Honeywell. – Schneider Electric (Wonderware, Televent Citect) . Packet access to the network segments hosting SCADA devices. – Survalent Technology Company (STC) – Control protocols usually lack any form of cryptographic security, allowing an attacker to control a SCADA device remotely by sending – Rockwell Automation commands over a network. – Emerson Process Management – In many cases SCADA users have assumed that having a VPN offered sufficient protection, unaware that security can be trivially bypassed with physical access to SCADA-related network jacks and switches. Industrial control vendors suggest approaching SCADA security like Information Security with a defense in depth strategy that leverages common IT practices 15 16 SHODAN – DEVICE SEARCH ENGINE HOW DOES SHODAN WORK? . Shodan is a search engine that lets you find specific types of . How does this work devices(routers, servers, etc.) on the internet using a variety of 1. Crawl all IP addresses in the IPv4 space queries and filters. Some have also described it as a search 2. Try to initiate connections with known ports engine of service banners, which are meta-data the server sends 3. Record the responses/banners that are received back to the client 4. Append to any records that exist for that IP . In May 2013, CNN Money released an article detailing how . You can also create reports or find security exploits for specific SHODAN can be used to find dangerous systems on the ports/services Internet, including traffic light controls and other control systems, including ICS. In December 2013, the website SCADA Strangelove posted over 500 banner search terms to find connected SCADA devices via SHODAN and/or Google 17 18 Argonne National Laboratory 3 Introduction to Cyber Analysis Course April 1‐4, 2019 SHODAN – WHY IS THIS INTERESTING? SHODAN . Some banners can give information to the state of the device . We didn’t try to log into . What type of device (make/model) any of these devices, . Default passwords for obvious legal . Misconfigured systems reasons, but Shodan . Unchanged administrator passwords knows where a lot of . No authentication! them are: . Combined with domain knowledge (or Google) we can find useful things! 19 20 PEOPLE LIKE TVS. ALSO, PEOPLE LIKE THE INTERNET!! HOTELS LIKE THE INTERNET!!! Life IS good! UNIVERSITIES LIKE THE INTERNET!! NETWORK . If you can check your network health, I can check your network health Argonne National Laboratory 4 Introduction to Cyber Analysis Course April 1‐4, 2019 CONTROLLING ENTERTAINMENT NETWORKS COMPANIES LIKE THE INTERNET TOO!!! INTERNET BILLBOARDS ARE ON THE INTERNET! THIS WOULD NEVER, EVER BE A BAD IDEA LOCKS & LOCKERS Argonne National Laboratory 5 Introduction to Cyber Analysis Course April 1‐4, 2019 VARIOUS ELECTRICAL SUPPLIES MY TIMECARD IS OFF… MORE EXAMPLES 60,000 gallon tank (close enough) LET’S LOOK AT AN EXAMPLE OF A FILTER: DEMO OF SHODAN pdu country:"US" city:"Atlanta" net:216.247.251.0/24 1. Navigate to Shodan's website (http://www.shodan.io) 2. Search for the term "default password" . 15 total PDUs 3. Inspect the results and see what information you may be able . We can make an educated guess as to what/where this is to obtain 4. Select a result that contains a Cisco networking device 5. What kind of information is there regarding that device? 6. If there a privilege level specified what kind of access does that grant you? 7. What steps would you need to take to ensure this kind of tool cannot be used against a system you are creating? 36 Argonne National Laboratory 6 Introduction to Cyber Analysis Course April 1‐4, 2019 ICS & SCADA UNPROTECTED WHAT DOES IT ALL MEAN? . Industrial Control Systems (ICS) and Supervisory Control and . These systems were not built to be externally facing Data Acquisitions (SCADA) devices are also unprotected on the . Most are not secure for anything other than local access Internet . Security through obscurity would prevent people from accessing . Several sites are devoted to this these devices previously . So these shouldn’t be on the Internet, right? TO REITERATE… . I only accessed these sites through HTTP using a basic web browser (Chrome) . No login information was ever entered . I only followed links once I got to the page – AKA no directory traversal or spidering . All devices were found directly through Shodan . I did not test if default credentials worked (but some other researchers did, and they usually work) Argonne National Laboratory 7 Introduction to Cyber Analysis Course April 1‐4, 2019 SHODAN REPORTS . September 10, 2014 Shodan Developer John Metherly releases reporting functionality . Keep track of search results