Archive for 'SCADA IDS'
Beta Release: SCADA IDS Preprocessors
We are pleased to announce the beta release of some Quickdraw software components today. Quickdraw is a Digital Bond research project funded by the US Department of Homeland Security (DHS). This beta release is the first three SCADA IDS preprocessors that were the crux of the Quickdraw project. They are:
DNP3
Ethernet Industrial Protocol (EtherNet/IP and [...]
Author: Daniel Peck
Posted: June 25th, 2009 under DNP3, EtherNet/IP, IDS / IPS, Modbus TCP, Quickdraw, SCADA IDS.
Comments: none
Quickdraw Update: Preprocessors and Detection Plugins
It’s been a little while since we’ve had a Quickdraw update, and I wanted to fill everyone in on how we’re doing and the approach we’re using.
As we’ve described before we’re basing the project on the snort 2.8.x tree, and we could do much of the processing and alerting using only the snort rule language [...]
Author: Daniel Peck
Posted: April 27th, 2009 under Quickdraw, SCADA IDS, SCADA Protocols.
Comments: none
IDS Signature Release 3.3
With the advent of exploits of control system component and application vulnerabilities in the wild, we have added a fourth category to Digital Bond’s IDS signature package – – Vulnerability Exploit IDS Signatures. There are currently three of vulnerability exploit signatures.
All can see the list of IDS signatures in the SCADApedia:
DNP3 Signature List
ICCP Signature List
Modbus [...]
Author: Dale Peterson
Posted: October 20th, 2008 under SCADA IDS.
Comments: none
IDS Signature for DATAC RealWin SCADA Sever Exploit
This vulnerability was made public a few days ago now, and we’ve put together a signature to detect it. This is another very simple stack based overflow, seeing far too many of these in SCADA software; I hope vendors have already started doing some internal code audits to find these with the increased exposure the [...]
Author: Daniel Peck
Posted: October 12th, 2008 under SCADA IDS.
Comments: 1
Another SCADA Honeynet Update
This honeywall update includes our four latest IDS signatures which aid in detecting points list and function code scans on DNP3 and Modbus TCP. These signatures play an important role in identifying a reconnaissance scan on PLC’s, RTU’s, and IED’s in a control system environment. In regards to the honeywall, roo-1.2 has been released for [...]
Author: Landon Lewis
Posted: July 27th, 2007 under SCADA Honeynet, SCADA IDS.
Comments: 2
New DNP3 IDS Signatures
We added two new SCADA IDS signatures for DNP3 to our SCADA IDS release package. Like the recently released Modbus TCP signature update, these two new DNP3 signatures will identify when an attacker is performing a reconnaissance scan of a DNP3 outstation (PLC, RTU, IED, etc.) The first signature will identify someone scanning for [...]
Author: Dale Peterson
Posted: June 5th, 2007 under DNP3, SCADA IDS.
Comments: 1
New IDS Signatures for Modbus TCP
We released two new Modbus TCP IDS signatures and some improvements and updates today. The download of the entire new SCADA IDS package and links to the documentation are available on our IDS research page.
The new signatures identify Modbus scanners in two different ways.
SID 1111013, Modbus TCP – Function Code Scan, identifies a scanner attempting [...]
Author: Dale Peterson
Posted: April 27th, 2007 under Modbus TCP, SCADA IDS.
Comments: none
SCADA Honeynet Updates
This update includes the current version (roo 1.1) of the honeywall and a patched target which had a vulnerability in one of the service components. After a large number of bug fixes and IDS signature interface changes, the honeywall is stable and reports all SCADA alerts correctly in Walleye (as shown below).
Thanks to Neutralbit for [...]
Author: Landon Lewis
Posted: April 2nd, 2007 under SCADA Honeynet, SCADA IDS, Site Info.
Comments: none
Displaying Custom IDS Signature Alerts in Walleye
For those of you who have downloaded our latest release of the SCADA Honeynet, you have probably noticed that the SCADA IDS signatures display ‘unknown signature’ in the Walleye interface. I’m sure this is true for anyone who has put a custom IDS snort signature on their honeywall as well. The steps below outline what [...]
Author: Landon Lewis
Posted: February 6th, 2007 under SCADA Honeynet, SCADA IDS.
Comments: none
Latest Honeywall Test Version
So I decided to load the latest test version (1.1) of the roo Honeywall from the Honeynet Project. The image was made public on 11/30/06 and there are numerous improvements. One example being the package respositories are now setup correctly, previously when you would update the honeywall it would get packages from other repos causing [...]
Author: Landon Lewis
Posted: January 31st, 2007 under SCADA Honeynet, SCADA IDS.
Comments: none