CypherCon 2023: How to Safely Scan OT Devices in Critical Environments

Active scanning is often considered a no-go on industrial control systems and other OT and IoT devices because of bad experiences they’ve had. However, the reasons that led to devices freezing up are entirely avoidable. Alternatives, such as passive monitoring, are expensive and don’t yield great results.

In this talk, you’ll learn about the most common reasons why embedded devices become unstable and how to make active scanning perfectly safe. The talk is based on lab research. Its recommendations have been proven to work in manufacturing plants, hospitals, and utility companies.

Importance: Because passive discovery via SPAN or TAP is difficult and expensive to deploy and active scanning is considered a no-go, security teams responsible for OT environments lack good asset inventory. Without proper inventory and an understanding of the true network structure, security teams can’t be proactive about their security posture and leave their networks open to attacks. All of this is because of misconceptions about active scanning that can be easily resolved.

CypherCon is an annual Wisconsin hacker conference attracting over 1,500 attendees held in Milwaukee, Wisconsin each spring: https://cyphercon.com

Meet Our Speakers

Chris Kirsch

Contributor

Subscribe Now

Get the latest news and expert insights delivered in your inbox.

Welcome to the club! Your subscription to our newsletter is successful.


Related Resources

Talks
LASCON 2024 Keynote: HD Moore - Hacker Numerology
In this keynote HD Moore explores the numbers that define our lives and how to use limited observations of identifiers to reason about the security...
Talks
DEF CON 32: SSHamble: Unexpected Exposures in SSH (Video)
This talk digs deep into SSH, the lesser-known implementations, many of the surprising security issues found along the way, and how to exploit them.
Talks
CypherCon 7.0 Keynote: 25 Years of Vulnerability Mismanagement
HD Moore, Founder and CEO of runZero, gives the keynote address at CypherCon 7.0.
Talks
DEF CON 32: SSHamble: Unexpected Exposures in SSH (PDF)
This presentation digs deep into SSH, the lesser-known implementations, many of the surprising security issues found along the way, and how to...

See Results in Minutes

Get complete visibility into IT, OT, & IoT — without agents, credentials, or hardware.

© Copyright 2024 runZero, Inc. All Rights Reserved