Infosecurity.US

Information Security & Occasional Forays Into Adjacent Realms

  • Web Log

Radvanovsky's RuggedTrax →

December 02, 2015 by Marc Handelman in All is Information, Control Systems, ICS/SCADA, ICS, Information Sharing, Internetwork Security, Information Security

Bob Radvanovsky, of Infracritical SCADASEC fame and Critical Infrastructure Protection and Cyber Security Researcher, has completed the RuggedTrax project, and published the findings thereto. Outstanding work Mr. Radvanovsky.

December 02, 2015 /Marc Handelman
All is Information, Control Systems, ICS/SCADA, ICS, Information Sharing, Internetwork Security, Information Security

Chuvakin, Tanks versus Tractors →

August 13, 2015 by Marc Handelman in ICS/SCADA, Information Security, ICS, All is Information, IoT, Alternate Attack Analysis

Via Gartner Research Vice President Anton Chuvakin, Ph.D., comes a superb screed prompted by JeepGate. Today's Must Read.

August 13, 2015 /Marc Handelman
ICS/SCADA, Information Security, ICS, All is Information, IoT, Alternate Attack Analysis

ICS Cyber-Incidents Not Identified, Reported →

July 14, 2015 by Marc Handelman in All is Information, ICS/SCADA, ICS, Information Security

In a tour de force post on the Unfettered blog, highly respected Industrial Control Systems Information Security Professional Joe Weiss targets systemic problems in the ICS arena. One of those problems is apparently the correct identification and reporting of security incidents in the ICS realm. If you read anything today on ICS / SCADA information and Network Security, read Joes' blog post - it's simply that important.

July 14, 2015 /Marc Handelman
All is Information, ICS/SCADA, ICS, Information Security

Infographica, SANS ICS

July 08, 2015 by Marc Handelman in All is Information, ICS/SCADA, ICS, Information Security
July 08, 2015 /Marc Handelman
All is Information, ICS/SCADA, ICS, Information Security

NIST Releases Revision 2, Guide to Industrial Control Systems (ICS) Security

June 09, 2015 by Marc Handelman in All is Information, Governance, Hardware Security, ICS, ICS/SCADA, Information Security

The National Institute of Standards and Technology (NIST) has announced the release of Special Publication 800-82, Revision 2, Guide to Industrial Control Systems (ICS) Security. Outstanding.

June 09, 2015 /Marc Handelman
All is Information, Governance, Hardware Security, ICS, ICS/SCADA, Information Security

IOActive Industrial Security, Switches Get Stitches →

April 29, 2015 by Marc Handelman in All is Information, ICS, ICS/SCADA, Information Security, Smart Grids
April 29, 2015 /Marc Handelman
All is Information, ICS, ICS/SCADA, Information Security, Smart Grids

SANS ICS Rebuttal of Norse Iran Report v1.1

SANS ICS Defense Use Case: The Norse / AEI Rebuttal →

April 29, 2015 by Marc Handelman in All is Information, Alternate Attack Analysis, Information Security, ICS, ICS/SCADA

Superb rebuttal co-authored by Robert M. Lee, CAPT USAF (see Captain Lee's personal rebuttal of the NORSE and AEI document here), Michael J. Assante Co-Founder and Chief Security Strategist, NexDefense, Inc., and Tim Conway, ICS and SCADA Technical Training Director at SANS targeting the report entitled "The Growing Cyberthreat from Iran: The Initial Report of Project Pistaschio Harvest" produced by Norse and the American Enterprise Institute. Read it and Weep.

April 29, 2015 /Marc Handelman
All is Information, Alternate Attack Analysis, Information Security, ICS, ICS/SCADA

Alexanders' Warning: Catastrophic Attacks on Energy Sector in the Offing

April 28, 2015 by Marc Handelman in All is Information, Common Sense, Cyberwar, Electronic Warfare, Government, ICS, ICS/SCADA, Information Security, Intelligence, USNSA

via David Bisson, writing at Tripwire's State of Security blog, comes a particularly dire warning from Keith Alexander, GEN (RET) USA (RET), holder of a Bronze Star and the 16th Director of the United States National Security Agency, focusing on the security bulwarks of the embattled Energy Sector.

April 28, 2015 /Marc Handelman
All is Information, Common Sense, Cyberwar, Electronic Warfare, Government, ICS, ICS/SCADA, Information Security, Intelligence, USNSA

IOActive Industrial Security, Stages of a SCADA Attack →

April 21, 2015 by Marc Handelman in ICS, ICS/SCADA, Network Security, Information Security
April 21, 2015 /Marc Handelman
ICS, ICS/SCADA, Network Security, Information Security

NIST Announces New Internal Report Targeting Smart Metering →

March 13, 2015 by Marc Handelman in All is Information, Communications, Compute Infrastructure, Data Security, Electrical Engineering, Hardware Security, ICS/SCADA, Infrastructure, Information Security

The National Institute of Standards and Technology (NIST) has announced a new internal report detailing a framework targeting Smart Meter Upgradability (NIST Internal Report NISTIR 7823), Advanced Metering Infrastructure Smart Meter Upgradeability Test Framework). Authored by Michaela Iorga (a member of the Computer Security Division, in the Information Technology Laboratory (ITL) at NIST) and Scott Shorter (of Electrosoft Services, Inc. in Reston, Virgina), the document is also available at the International DOI System under NIST.IR.7823.

I reckon the document's abstract sums it up quite nicely:

"As electric utilities turn to Advanced Metering Infrastructures (AMIs) to promote the development and deployment of the Smart Grid, one aspect that can benefit from standardization is the upgradeability of Smart Meters. The National Electrical Manufacturers Association (NEMA) standard SG-AMI 1-2009, “Requirements for Smart Meter Upgradeability,” describes functional and security requirements for the secure upgrade—both local and remote—of Smart Meters. This report describes conformance test requirements that may be used voluntarily by testers and/or test laboratories to determine whether Smart Meters and Upgrade Management Systems conform to the requirements of NEMA SG-AMI 1-2009. For each relevant requirement in NEMA SG-AMI 1-2009, the document identifies the information to be provided by the vendor to facilitate testing, and the high-level test procedures to be conducted by the tester/laboratory to determine conformance." - via NIST IR 7823

Meanwhile, you can also track, examine and attempt to contain your surprise at the latest, recognized industiral control systems & supervisory control and data acquisition systems vulnerabilities from our colleagues st US-CERT, here.

March 13, 2015 /Marc Handelman
All is Information, Communications, Compute Infrastructure, Data Security, Electrical Engineering, Hardware Security, ICS/SCADA, Infrastructure, Information Security

Internets of Energy →

March 02, 2015 by Marc Handelman in All is Information, Commerce, Electrical Engineering, ICS/SCADA, Information Security, Internet Antiquities, National Security, Infrastructure, Smart Grids, Utilities

In which, the National Science Foundation NSF regales us with the Horrible Revelation that our power grid's baseline technological underpinnings are firmly ensconced within Industrial Age capabilities. Bad says you, Huzzah!

March 02, 2015 /Marc Handelman
All is Information, Commerce, Electrical Engineering, ICS/SCADA, Information Security, Internet Antiquities, National Security, Infrastructure, Smart Grids, Utilities

IOActive, Switches Get Stitches

January 18, 2015 by Marc Handelman in All is Information, Information Security, ICS/SCADA
January 18, 2015 /Marc Handelman
All is Information, Information Security, ICS/SCADA
  • Newer
  • Older