I'm going to switch gears a bit. As you know (or perhaps you don't know!) two of the largest hacking conferences in the U.S. are happening around this time--BlackHat USA and DefCon. It provides a place for, among other things, white hats to talk about interesting/important hacking and InfoSec concepts and for white and gray hats to brag about their latest l33t activities. Since they're highly popular, and since one can get info on the talks after the conferences, they are an important source of information about vulnerabilities and threats.
DefCon doesn't start until tomorrow, but BlackHat has its fair share of interesting talks and briefings. Sine I like to focus on Internet of Things topics, here's a brief overview of the IoT-related talks that are happening at BlackHat 2017:
DefCon doesn't start until tomorrow, but BlackHat has its fair share of interesting talks and briefings. Sine I like to focus on Internet of Things topics, here's a brief overview of the IoT-related talks that are happening at BlackHat 2017:
- Industroyer/CrashOverride: Zero Things Cool about a Threat Group Targeting the Power Grid: This talk is about malware (Industroyer/CrashOverride) related to the attacks on Ukraine's power grid in 2015 and 2016. This malware is designed to attack Industrial Control Systems (ICS) at a large scale and can be rapidly repurposed to attack a wide variety of power grids.
- When IoT Attacks: Understanding the Safety Risks Associated with Connected Devices: The topic of this presentation is how IoT could be repurposed to physically attack a person. While it sounds futuristic (and perhaps unrealistic for now), it's an interesting concept that will likely be part of threat management in the future.
- Go Nuclear: Breaking Radiation Monitoring Devices: Radiation monitoring devices are used in a wide variety of settings to preserve health and human life. What happens when their security flaws are tampered with?
- Breaking the Laws of Robotics: Attacking Industrial Robots: Robots used in manufacturing are often networked and contain numerous digital controllers to perform their work. If an attacker exploits a vulnerability in these networks or controllers, they could potentially impact the manufactured product and endanger human life. This talk discusses vulnerabilities in these robots.
- Free-fall: Hacking Tesla from Wireless to CAN Bus: Tesla is one of the foremost car manufacturers in a lot of areas, including in vulnerability hunting. This talk is from a group of people who were able to create an exploit chain that could be used to remotely hack a Tesla vehicle.
- And then the Script-Kiddie Said, "Let There be no Light." Are Cyber-Attacks on the Power Grid Limited to Nation-State Actors?: This talk discusses vulnerabilities in the power grid that can be discovered with open-source intelligence (OSINT)--e.g. stuff you can find on the Internet. It also discusses some practical attacks on networked parts of the power grid.
- Exploiting Network Printers: A good traditional topic: breaking into one of the most traditional IoT components of a business network. This has a lot of good use for security teams, since the threats are applicable to most corporate networks.
- Adventures in Attacking Wind Farm Control Networks: I discussed this vulnerability in a post a few weeks ago, but this talk provides more insight into the attack.
- Breaking Electronic Door Locks like You're on CSI: Cyber: So this technically may not be considered part of the IoT since many electronic door locks aren't networked, but it's still an interesting topic that addresses vulnerabilities in something we don't normally associate computers with.
No comments:
Post a Comment