1
1

00:00:00,240  -->  00:00:02,430
<v Instructor>Mitigating vulnerabilities.</v>
2

2

00:00:02,430  -->  00:00:03,600
So we've talked about a lot
3

3

00:00:03,600  -->  00:00:05,400
of specialized systems here especially
4

4

00:00:05,400  -->  00:00:07,440
in the ICS and SCADA world.
5

5

00:00:07,440  -->  00:00:08,700
And so the question is
6

6

00:00:08,700  -->  00:00:10,140
how do you start mitigating some
7

7

00:00:10,140  -->  00:00:11,640
of these vulnerabilities?
8

8

00:00:11,640  -->  00:00:13,500
Well, the go-to guide for this is going to
9

9

00:00:13,500  -->  00:00:17,130
be the "NIST Special Publication 800-82".
10

10

00:00:17,130  -->  00:00:18,900
Now, again, this is a good read if you happen
11

11

00:00:18,900  -->  00:00:20,610
to work in a manufacturing environment
12

12

00:00:20,610  -->  00:00:22,890
or someplace that uses ICS and SCADA.
13

13

00:00:22,890  -->  00:00:23,730
Now, you don't have to read
14

14

00:00:23,730  -->  00:00:24,930
this entire guide yourself
15

15

00:00:24,930  -->  00:00:27,330
because I'm going to give you the four key controls
16

16

00:00:27,330  -->  00:00:28,740
for mitigating vulnerabilities
17

17

00:00:28,740  -->  00:00:30,450
in specialized systems and this is really
18

18

00:00:30,450  -->  00:00:32,130
what you need to know for the exam.
19

19

00:00:32,130  -->  00:00:33,570
But again, if you're working in an environment
20

20

00:00:33,570  -->  00:00:35,250
that is automation and manufacturing
21

21

00:00:35,250  -->  00:00:37,050
and you have ICS SCADA systems,
22

22

00:00:37,050  -->  00:00:39,300
this entire guide is a great read for you
23

23

00:00:39,300  -->  00:00:40,380
in the real world.
24

24

00:00:40,380  -->  00:00:42,120
Now, the first thing we want to talk about is
25

25

00:00:42,120  -->  00:00:44,280
how you can establish administrative control
26

26

00:00:44,280  -->  00:00:46,620
over Operational Technology networks.
27

27

00:00:46,620  -->  00:00:48,840
The best way to do this is by recruiting staff
28

28

00:00:48,840  -->  00:00:51,270
who have expertise with these things.
29

29

00:00:51,270  -->  00:00:52,620
Because as I said,
30

30

00:00:52,620  -->  00:00:55,350
these are not your normal IT networks.
31

31

00:00:55,350  -->  00:00:56,430
I am really knowledgeable
32

32

00:00:56,430  -->  00:00:57,870
when it comes to IT networks
33

33

00:00:57,870  -->  00:00:59,820
but I am not really knowledgeable when it comes
34

34

00:00:59,820  -->  00:01:02,610
to ICS and SCADA networks in the OT realm.
35

35

00:01:02,610  -->  00:01:04,140
I've done a little bit of work with them
36

36

00:01:04,140  -->  00:01:05,820
but just enough to be dangerous.
37

37

00:01:05,820  -->  00:01:07,470
So you wouldn't want to hire me for that.
38

38

00:01:07,470  -->  00:01:09,690
Instead, you want to find people who know
39

39

00:01:09,690  -->  00:01:10,523
what they're talking about
40

40

00:01:10,523  -->  00:01:11,970
When it comes to OT.
41

41

00:01:11,970  -->  00:01:14,100
OT is a different beast and so you want to
42

42

00:01:14,100  -->  00:01:15,060
make sure you get somebody
43

43

00:01:15,060  -->  00:01:18,330
who understands SCADA and ICS and PLCs
44

44

00:01:18,330  -->  00:01:20,490
and FPGAs and all the stuff we've been talking
45

45

00:01:20,490  -->  00:01:22,020
about in the last couple lessons.
46

46

00:01:22,020  -->  00:01:24,030
These are specialists and they're worth the money
47

47

00:01:24,030  -->  00:01:25,590
to have on staff especially,
48

48

00:01:25,590  -->  00:01:27,930
if you're running a big manufacturing plant.
49

49

00:01:27,930  -->  00:01:29,880
The second big tip, you want to make
50

50

00:01:29,880  -->  00:01:32,040
sure you're implementing the minimum network links
51

51

00:01:32,040  -->  00:01:34,080
by disabling any unnecessary linkS,
52

52

00:01:34,080  -->  00:01:36,120
services and protocols.
53

53

00:01:36,120  -->  00:01:39,240
Essentially, when you have an Operational Technology network
54

54

00:01:39,240  -->  00:01:41,250
you want to eliminate it from all of the rest
55

55

00:01:41,250  -->  00:01:42,990
of the networks as much as possible.
56

56

00:01:42,990  -->  00:01:44,070
We want to cut those links,
57

57

00:01:44,070  -->  00:01:45,690
we want to disable services.
58

58

00:01:45,690  -->  00:01:48,030
So if I have a manufacturing plant,
59

59

00:01:48,030  -->  00:01:49,590
I should have two networks.
60

60

00:01:49,590  -->  00:01:52,080
My corporate network, the IT network,
61

61

00:01:52,080  -->  00:01:54,690
and the plant network, the OT network.
62

62

00:01:54,690  -->  00:01:56,730
If there's any connection between those two,
63

63

00:01:56,730  -->  00:01:57,930
it should be very minimal
64

64

00:01:57,930  -->  00:02:00,030
and it should be heavily monitored.
65

65

00:02:00,030  -->  00:02:01,740
The third thing we want to talk about is
66

66

00:02:01,740  -->  00:02:02,730
how we can develop
67

67

00:02:02,730  -->  00:02:04,680
and test a patch management program
68

68

00:02:04,680  -->  00:02:06,870
for Operational Technology networks.
69

69

00:02:06,870  -->  00:02:09,600
Again, these OT networks are different
70

70

00:02:09,600  -->  00:02:11,730
than our information technology networks.
71

71

00:02:11,730  -->  00:02:12,690
You can't just go ahead
72

72

00:02:12,690  -->  00:02:15,300
and use your Microsoft SCCM servers.
73

73

00:02:15,300  -->  00:02:16,980
That's not going to work for you.
74

74

00:02:16,980  -->  00:02:18,600
So you want to make sure you understand
75

75

00:02:18,600  -->  00:02:20,520
what options you have and how you're going to
76

76

00:02:20,520  -->  00:02:22,440
do a patch management program.
77

77

00:02:22,440  -->  00:02:24,990
Remember, these are things unlike PLCs,
78

78

00:02:24,990  -->  00:02:26,310
they have firmware that needs
79

79

00:02:26,310  -->  00:02:27,630
to be upgraded sometimes.
80

80

00:02:27,630  -->  00:02:28,980
That's going to require maintenance windows,
81

81

00:02:28,980  -->  00:02:30,570
that's going to require downtime.
82

82

00:02:30,570  -->  00:02:31,590
You need to have a process
83

83

00:02:31,590  -->  00:02:32,670
of how you're going to do this
84

84

00:02:32,670  -->  00:02:34,470
and that's why it's important to develop
85

85

00:02:34,470  -->  00:02:36,450
and test your patch management program.
86

86

00:02:36,450  -->  00:02:37,650
And then the fourth thing we need to think
87

87

00:02:37,650  -->  00:02:39,750
about is how we're going to perform regular audits
88

88

00:02:39,750  -->  00:02:41,760
of logical and physical access
89

89

00:02:41,760  -->  00:02:43,920
to these different systems so that we can detect
90

90

00:02:43,920  -->  00:02:45,960
possible vulnerabilities and intrusions.
91

91

00:02:45,960  -->  00:02:47,580
Now, this isn't going to be as easy
92

92

00:02:47,580  -->  00:02:49,020
as hooking up Nessus to the network
93

93

00:02:49,020  -->  00:02:50,370
and doing a scan.
94

94

00:02:50,370  -->  00:02:51,780
You're going to have to have specialists
95

95

00:02:51,780  -->  00:02:52,980
who know what they're looking for
96

96

00:02:52,980  -->  00:02:54,870
when they're scanning these areas.
97

97

00:02:54,870  -->  00:02:57,210
Also, big word of warning here,
98

98

00:02:57,210  -->  00:02:58,320
your enumeration tools
99

99

00:02:58,320  -->  00:02:59,820
and vulnerabilities scanners,
100

100

00:02:59,820  -->  00:03:01,560
they can cause a lot of problems
101

101

00:03:01,560  -->  00:03:03,720
on Operational Technology networks.
102

102

00:03:03,720  -->  00:03:05,730
Generally, if you're trying to do scanning
103

103

00:03:05,730  -->  00:03:07,650
of an Operational Technology network,
104

104

00:03:07,650  -->  00:03:09,900
you are not going to be doing active scanning.
105

105

00:03:09,900  -->  00:03:11,940
Instead, you're going to hook up something
106

106

00:03:11,940  -->  00:03:14,820
like Wire Shark, you're going to do packet capture
107

107

00:03:14,820  -->  00:03:16,740
and then using that passive analysis
108

108

00:03:16,740  -->  00:03:18,570
of that network traffic, you'll be able
109

109

00:03:18,570  -->  00:03:21,090
to identify those devices to do your enumeration
110

110

00:03:21,090  -->  00:03:23,550
or you'll be able to use that passive analysis
111

111

00:03:23,550  -->  00:03:24,383
to start figuring out
112

112

00:03:24,383  -->  00:03:25,560
what vulnerabilities you may have
113

113

00:03:25,560  -->  00:03:26,560
inside your network.
