New DNP3 IDS Signatures
We added two new SCADA IDS signatures for DNP3 to our SCADA IDS release package. Like the recently released Modbus TCP signature update, these two new DNP3 signatures will identify when an attacker is performing a reconnaissance scan of a DNP3 outstation (PLC, RTU, IED, etc.) The first signature will identify someone scanning for all possible points, and the second will identify a function code scan.
These signatures leverage the Internal Indication (IIN) bits and look for a configurable number of errors in a configurable amount of time. The signature has our recommendation for limits, but they are easily modified by anyone with basic Snort knowledge.
Subscribers can download the latest package
and view the documentation pages for each signature.
Author: Dale Peterson
Posted: June 5th, 2007 under DNP3, SCADA IDS.
Comments: 1
Comments
Comment from Ron Southworth
Time: June 6, 2007, 12:51 am
Some good news Dale I look forward to being able to access your subscriber content when we have a few changes realised here hopefully in the next few months. This is some important work for protecting our systems so it is much apreciated
Write a comment