runZero Hour: Episode 4

Episode 4 of the runZero Hour webcast discussed lookalikes on the network, which can include: human-machine interfaces found in OT environments, simulators/probes, honeypots, rogue devices, and compatible devices that happen to look alike just because they speak the same protocol. Most of these serve legitimate purposes for testing and monitoring, so their presence isn’t necessarily malicious, but they present challenges for fingerprinting. How do you differentiate a lookalike from the real thing?

The hurdle is incredibly steep if you're just doing passive discovery. It can't always differentiate between request and response with some protocols, such as Factory Interface Network Service (FINS). You really need to initiate the conversation for accurate fingerprinting.

Beyond that, you must leverage other techniques to identify the device doppelgängers. For example, with GasPot for the Automatic Tank Gauge (ATG) protocol, you can leverage line endings–carriage return line feed (\r\n) versus line feed (\n)--as a “tell”. Another fun example would be IoT/OT devices and their Windows lookalikes. You can actually use the discrepancy between ICMP and TCP syn response times as a giveaway.

Lookalikes was just one segment in this episode of runZero Hour. Watch the recording for more insights.

Meet Our Speakers

HD Moore

CEO and Co-Founder

Huxley Barbee

Former Security Evangelist

Rob King

Director of Security Research

Tom Sellers

Principal Research Engineer

Subscribe Now

Get the latest news and expert insights delivered in your inbox.

Welcome to the club! Your subscription to our newsletter is successful.


Related Resources

Webcasts
Safeguarding OT/ICS Assets: Insights from CECA
Security experts from the National Renewable Energy Lab’s (NREL) Clean Energy Cybersecurity Accelerator™ (CECA) program join runZero to discuss...
Webcasts
runZero Hour: Episode 8
The latest insights (and opinions!) on the impending US ban of Kaspersky products, the FBI's warning for threats against the renewable energy...
Webcasts
runZero Hour: Episode 9
Join the runZero research team for a special episode of runZero Hour featuring our deep dive research on the SSH protocol and SSHamble, an open...
Webcasts
Unknown Assets are the Achilles Heel of Effective Cyber Defense — And Zero Trust
Achieving complete visibility across complex environments is a core tenet of zero trust. See how to achieve your goals with tips form our experts.

See Results in Minutes

Get complete visibility into IT, OT, & IoT — without agents, credentials, or hardware.

© Copyright 2024 runZero, Inc. All Rights Reserved