1
1

00:00:00,300  -->  00:00:02,790
<v ->Premise system vulnerabilities.</v>
2

2

00:00:02,790  -->  00:00:06,480
In this lesson, we are going to talk about premise systems.
3

3

00:00:06,480  -->  00:00:08,820
Now, what is a premise system?
4

4

00:00:08,820  -->  00:00:10,980
Well, a premise system is a system used
5

5

00:00:10,980  -->  00:00:14,310
for building automation and physical access security,
6

6

00:00:14,310  -->  00:00:16,830
and these are a different type of network as well.
7

7

00:00:16,830  -->  00:00:19,080
Oftentimes, you'll have this as a third network
8

8

00:00:19,080  -->  00:00:20,490
in your organization.
9

9

00:00:20,490  -->  00:00:21,600
When you're dealing with this and you go
10

10

00:00:21,600  -->  00:00:22,467
to your front door or your building
11

11

00:00:22,467  -->  00:00:25,020
and you try to get in and use your card and your pin,
12

12

00:00:25,020  -->  00:00:26,280
that has to go through some kind
13

13

00:00:26,280  -->  00:00:27,810
of an access control system.
14

14

00:00:27,810  -->  00:00:29,490
That is a premise system, right?
15

15

00:00:29,490  -->  00:00:31,530
That is physical access security.
16

16

00:00:31,530  -->  00:00:33,150
If I look at the security cameras,
17

17

00:00:33,150  -->  00:00:35,430
those are part of your premise system as well.
18

18

00:00:35,430  -->  00:00:37,710
Now, when we deal with a premise system,
19

19

00:00:37,710  -->  00:00:39,750
a lot of these system designs are going to allow
20

20

00:00:39,750  -->  00:00:41,370
for monitoring to be available
21

21

00:00:41,370  -->  00:00:43,050
across the corporate data network
22

22

00:00:43,050  -->  00:00:44,610
or even directly from the internet.
23

23

00:00:44,610  -->  00:00:46,740
And this is really great from a monitoring perspective,
24

24

00:00:46,740  -->  00:00:48,090
it makes it really easy for us.
25

25

00:00:48,090  -->  00:00:50,310
But this is also dangerous, right?
26

26

00:00:50,310  -->  00:00:51,660
Because when we have a connection
27

27

00:00:51,660  -->  00:00:53,490
to the corporate data network, that means
28

28

00:00:53,490  -->  00:00:55,230
that somebody can hack into your premise network,
29

29

00:00:55,230  -->  00:00:57,510
they can cross over into your data network.
30

30

00:00:57,510  -->  00:00:59,190
And if you connect directly to the internet,
31

31

00:00:59,190  -->  00:01:01,920
that might give them a way in into that premise network.
32

32

00:01:01,920  -->  00:01:03,240
So these are things you have to think about
33

33

00:01:03,240  -->  00:01:04,800
when you're dealing with security.
34

34

00:01:04,800  -->  00:01:05,700
Now, in addition to this,
35

35

00:01:05,700  -->  00:01:08,400
we also have building automation systems.
36

36

00:01:08,400  -->  00:01:10,260
Now, building automation systems,
37

37

00:01:10,260  -->  00:01:11,790
they have components and protocols
38

38

00:01:11,790  -->  00:01:14,040
that facilitate the centralized configuration
39

39

00:01:14,040  -->  00:01:16,080
and monitoring of your different mechanical
40

40

00:01:16,080  -->  00:01:19,590
and electrical systems within offices or data centers.
41

41

00:01:19,590  -->  00:01:21,630
Now, oftentimes you're not going to be controlling
42

42

00:01:21,630  -->  00:01:23,460
the actual power generation, right,
43

43

00:01:23,460  -->  00:01:25,260
that would be ICS and SCADA.
44

44

00:01:25,260  -->  00:01:28,890
But you are going to have other ways to look at the information
45

45

00:01:28,890  -->  00:01:31,710
inside your building through these automation systems.
46

46

00:01:31,710  -->  00:01:33,480
For instance, at our offices,
47

47

00:01:33,480  -->  00:01:35,430
we have a battery backup system.
48

48

00:01:35,430  -->  00:01:38,010
This is a whole building system so that if we lose power,
49

49

00:01:38,010  -->  00:01:39,660
we have that battery that can kick in
50

50

00:01:39,660  -->  00:01:42,270
and support us for about 24 hours.
51

51

00:01:42,270  -->  00:01:43,890
Now we have the ability to log into
52

52

00:01:43,890  -->  00:01:45,690
that battery remotely over the internet
53

53

00:01:45,690  -->  00:01:48,030
so we can see exactly how much battery is left,
54

54

00:01:48,030  -->  00:01:50,670
how quickly our burn rate is, and things of that nature.
55

55

00:01:50,670  -->  00:01:52,770
If you're in a bigger building, you might have elevators
56

56

00:01:52,770  -->  00:01:53,603
and you want to be able to figure out
57

57

00:01:53,603  -->  00:01:55,620
where the elevator is at any given time.
58

58

00:01:55,620  -->  00:01:57,060
If you've watched any spy movie,
59

59

00:01:57,060  -->  00:01:58,050
I'm sure you've seen the idea
60

60

00:01:58,050  -->  00:01:59,460
of building automation systems
61

61

00:01:59,460  -->  00:02:00,900
where they turn on and off the ACs,
62

62

00:02:00,900  -->  00:02:02,370
or they turn on and off the elevators,
63

63

00:02:02,370  -->  00:02:04,710
or turn on and off the lights to a particular floor.
64

64

00:02:04,710  -->  00:02:07,050
That's what a building automation system really is.
65

65

00:02:07,050  -->  00:02:08,040
Now, when you start dealing
66

66

00:02:08,040  -->  00:02:09,570
with all these building automation systems,
67

67

00:02:09,570  -->  00:02:10,830
they have lots of different parts
68

68

00:02:10,830  -->  00:02:13,020
that could bring up vulnerabilities to your network.
69

69

00:02:13,020  -->  00:02:14,580
So again, I like to keep these
70

70

00:02:14,580  -->  00:02:16,620
as their own segment and network.
71

71

00:02:16,620  -->  00:02:18,240
But when we start talking about these vulnerabilities,
72

72

00:02:18,240  -->  00:02:19,770
we have things like the process
73

73

00:02:19,770  -->  00:02:22,680
and memory vulnerabilities inside the PLCs,
74

74

00:02:22,680  -->  00:02:25,560
because these building automations are going to use PLCs.
75

75

00:02:25,560  -->  00:02:27,750
If you're going to control elevators and lighting
76

76

00:02:27,750  -->  00:02:30,360
and water and fire mains and power,
77

77

00:02:30,360  -->  00:02:32,460
all of those things do have PLCs
78

78

00:02:32,460  -->  00:02:34,890
that you can control within your building.
79

79

00:02:34,890  -->  00:02:36,120
Then we have to think about
80

80

00:02:36,120  -->  00:02:38,580
how we're going to keep our credentials safe,
81

81

00:02:38,580  -->  00:02:40,410
because oftentimes these things
82

82

00:02:40,410  -->  00:02:42,300
have poor security management.
83

83

00:02:42,300  -->  00:02:44,010
A lot of times people write their code
84

84

00:02:44,010  -->  00:02:45,930
with plain text credentials or keys
85

85

00:02:45,930  -->  00:02:47,850
inside the application code.
86

86

00:02:47,850  -->  00:02:50,400
That way they'll say, my password is password,
87

87

00:02:50,400  -->  00:02:51,840
and they'll put it right in the code,
88

88

00:02:51,840  -->  00:02:53,820
and that could be exploited by an attacker.
89

89

00:02:53,820  -->  00:02:56,340
Another thing I often see occur is code injections
90

90

00:02:56,340  -->  00:02:58,290
against the web user interface.
91

91

00:02:58,290  -->  00:03:00,060
A lot of these building automation systems,
92

92

00:03:00,060  -->  00:03:02,400
the way that they are monitored is through a web interface,
93

93

00:03:02,400  -->  00:03:04,260
whether locally or over the internet.
94

94

00:03:04,260  -->  00:03:06,060
So if there is a web interface presented
95

95

00:03:06,060  -->  00:03:07,980
that means an attacker could access that
96

96

00:03:07,980  -->  00:03:09,720
and then do a code injection doing something
97

97

00:03:09,720  -->  00:03:12,300
like an XML injection, an SQL injection,
98

98

00:03:12,300  -->  00:03:15,330
a cross-site scripting injection, something like that.
99

99

00:03:15,330  -->  00:03:16,530
And so you got to keep that in mind.
100

100

00:03:16,530  -->  00:03:18,780
This is an area that could allow for somebody
101

101

00:03:18,780  -->  00:03:21,480
to get into that network and then control your building.
102

102

00:03:21,480  -->  00:03:23,250
Now, one of the things that we really have to worry about
103

103

00:03:23,250  -->  00:03:26,130
with these premise systems and building automation systems,
104

104

00:03:26,130  -->  00:03:27,060
is that they can be used
105

105

00:03:27,060  -->  00:03:29,910
to create a denial of service condition in the real world.
106

106

00:03:29,910  -->  00:03:31,320
Now, what do I mean by that?
107

107

00:03:31,320  -->  00:03:32,580
Well, let's say I got a hold
108

108

00:03:32,580  -->  00:03:34,170
of your building automation system
109

109

00:03:34,170  -->  00:03:35,490
and I was able to do a code injection
110

110

00:03:35,490  -->  00:03:37,080
and take access over it.
111

111

00:03:37,080  -->  00:03:39,030
I could create a denial of service condition for you
112

112

00:03:39,030  -->  00:03:40,680
that could affect your entire building
113

113

00:03:40,680  -->  00:03:43,560
by turning off your HVAC, which is your air conditioner.
114

114

00:03:43,560  -->  00:03:44,760
And if you have a server farm
115

115

00:03:44,760  -->  00:03:46,320
and I take away your air conditioner,
116

116

00:03:46,320  -->  00:03:49,050
that can overheat the systems and cause them to shut down.
117

117

00:03:49,050  -->  00:03:52,260
Now, I have caused an electronic attack against your servers
118

118

00:03:52,260  -->  00:03:55,380
by doing a physical attack by taking away your cooling.
119

119

00:03:55,380  -->  00:03:57,330
These are the things you have to think about.
120

120

00:03:57,330  -->  00:03:58,980
Another reason to worry about these systems
121

121

00:03:58,980  -->  00:04:01,140
is often they're not well secured.
122

122

00:04:01,140  -->  00:04:02,790
If you think back to 2015,
123

123

00:04:02,790  -->  00:04:05,280
there was a big case of this in the news with Target.
124

124

00:04:05,280  -->  00:04:08,040
Target is a big retail chain in the United States
125

125

00:04:08,040  -->  00:04:10,200
and they actually had one of their contractors
126

126

00:04:10,200  -->  00:04:12,150
who ran their HVAC systems,
127

127

00:04:12,150  -->  00:04:13,950
their systems had gotten hacked
128

128

00:04:13,950  -->  00:04:15,900
and somebody went through their systems
129

129

00:04:15,900  -->  00:04:18,000
through the HVAC at the Target stores,
130

130

00:04:18,000  -->  00:04:20,370
and then down into the point of sale systems,
131

131

00:04:20,370  -->  00:04:23,160
the cash registers, and started collecting credit card data.
132

132

00:04:23,160  -->  00:04:25,800
This was a huge breach and it was a huge black eye
133

133

00:04:25,800  -->  00:04:27,210
for the corporation.
134

134

00:04:27,210  -->  00:04:29,340
So remember, these building automation systems
135

135

00:04:29,340  -->  00:04:31,380
could be used as an intrusion vector
136

136

00:04:31,380  -->  00:04:32,910
as somebody who wants to pivot from that
137

137

00:04:32,910  -->  00:04:35,700
into a more dangerous attack against your corporate network.
138

138

00:04:35,700  -->  00:04:38,040
So you have to make sure the right protection's in place.
139

139

00:04:38,040  -->  00:04:39,570
Now, the final thing I want to talk about
140

140

00:04:39,570  -->  00:04:41,610
in this lesson is the idea of PACS,
141

141

00:04:41,610  -->  00:04:44,460
which is the physical access control system.
142

142

00:04:44,460  -->  00:04:47,010
Now, the physical access control system is all
143

143

00:04:47,010  -->  00:04:48,450
of the components and protocols
144

144

00:04:48,450  -->  00:04:50,940
that facilitate the centralized configuration monitoring
145

145

00:04:50,940  -->  00:04:54,660
of security mechanisms within offices and data centers.
146

146

00:04:54,660  -->  00:04:57,090
So when we start talking about all those security cameras
147

147

00:04:57,090  -->  00:04:59,310
and the access control to badge in and badge out
148

148

00:04:59,310  -->  00:05:00,210
of your building,
149

149

00:05:00,210  -->  00:05:03,540
that is all part of your physical access control systems.
150

150

00:05:03,540  -->  00:05:05,430
Now, PACS can either be implemented
151

151

00:05:05,430  -->  00:05:07,590
as part of your building automation system
152

152

00:05:07,590  -->  00:05:09,780
or as part of a separate system.
153

153

00:05:09,780  -->  00:05:10,890
Either way will work.
154

154

00:05:10,890  -->  00:05:13,140
It just depends on how your contractor sets it up
155

155

00:05:13,140  -->  00:05:15,360
or how your organization sets it up.
156

156

00:05:15,360  -->  00:05:18,690
Now, one word of warning here, PACS are often installed
157

157

00:05:18,690  -->  00:05:21,570
and maintained by a third party external supplier.
158

158

00:05:21,570  -->  00:05:24,930
And because of that, a lot of times people will omit that
159

159

00:05:24,930  -->  00:05:28,260
from their risk analysis or their vulnerability assessments.
160

160

00:05:28,260  -->  00:05:30,150
So as you're starting to think about your networks
161

161

00:05:30,150  -->  00:05:32,520
and you think, okay, I've got this Windows Network here,
162

162

00:05:32,520  -->  00:05:33,960
I've got this server farm here,
163

163

00:05:33,960  -->  00:05:35,970
I might have this OT over here.
164

164

00:05:35,970  -->  00:05:37,770
They don't think about the building network itself
165

165

00:05:37,770  -->  00:05:40,290
because it's some third party contract.
166

166

00:05:40,290  -->  00:05:43,470
So that's okay if you're going to exclude it from your scope
167

167

00:05:43,470  -->  00:05:44,880
if you have that in writing that
168

168

00:05:44,880  -->  00:05:47,100
that is part of their responsibilities.
169

169

00:05:47,100  -->  00:05:49,230
And they would probably have some kind of requirement
170

170

00:05:49,230  -->  00:05:52,500
to give you every quarter, every six months, every year,
171

171

00:05:52,500  -->  00:05:54,330
some kind of a vulnerability statement
172

172

00:05:54,330  -->  00:05:55,560
of what the network looks like.
173

173

00:05:55,560  -->  00:05:58,230
Because again, you can outsource the task
174

174

00:05:58,230  -->  00:06:00,450
but you can't outsource the responsibility.
175

175

00:06:00,450  -->  00:06:03,480
If their network is tied to your network in any way
176

176

00:06:03,480  -->  00:06:05,160
and there's a vulnerability on their network,
177

177

00:06:05,160  -->  00:06:06,360
that means the attacker could get
178

178

00:06:06,360  -->  00:06:09,000
from them to you just like they did with Target.
179

179

00:06:09,000  -->  00:06:10,143
So keep that in mind.
