1
00:00:06,591 --> 00:00:09,600
- In 10.6, we're gonna take a close look

2
00:00:09,600 --> 00:00:11,253
at embedded systems.

3
00:00:12,450 --> 00:00:15,360
Now, an embedded system
is an electronic product

4
00:00:15,360 --> 00:00:17,070
that contains a microprocessor

5
00:00:17,070 --> 00:00:20,763
and software designed to
perform a specific task.

6
00:00:21,660 --> 00:00:22,650
Now, an embedded system

7
00:00:22,650 --> 00:00:24,870
can either be fixed or
it can be programmable

8
00:00:24,870 --> 00:00:28,740
and embedded system
applications have a wide range

9
00:00:28,740 --> 00:00:30,780
from digital watches and microwaves

10
00:00:30,780 --> 00:00:33,690
to hybrid vehicles and avionics.

11
00:00:33,690 --> 00:00:36,450
And I think this is a
fascinating statistic.

12
00:00:36,450 --> 00:00:39,840
It's estimated that 98%
of all microprocessors

13
00:00:39,840 --> 00:00:43,383
manufactured are actually
used in embedded systems.

14
00:00:43,383 --> 00:00:44,730
So we think about the fact

15
00:00:44,730 --> 00:00:47,010
that our PCs, our laptops,
our desktops, you know,

16
00:00:47,010 --> 00:00:49,920
proliferate all over the
world, but in fact, right,

17
00:00:49,920 --> 00:00:54,213
they're way, way outnumbered
by embedded systems.

18
00:00:55,680 --> 00:00:57,840
So let's look at some examples

19
00:00:57,840 --> 00:00:59,790
of commercial embedded systems

20
00:00:59,790 --> 00:01:02,460
in the medical field
of vehicles, aircraft,

21
00:01:02,460 --> 00:01:04,110
and smart meters.

22
00:01:04,110 --> 00:01:05,280
In the medical field,

23
00:01:05,280 --> 00:01:08,430
medical devices such as
our digital flow sensors.

24
00:01:08,430 --> 00:01:11,400
MRI, and CT scanners,
sonography, wearables,

25
00:01:11,400 --> 00:01:15,330
as well as biomedical
applications to monitor patients

26
00:01:15,330 --> 00:01:17,070
and to support telemedicine.

27
00:01:17,070 --> 00:01:19,293
All use embedded systems.

28
00:01:20,340 --> 00:01:22,680
Vehicles, things like
adaptive cruise control,

29
00:01:22,680 --> 00:01:26,070
airbags, telematics traction control,

30
00:01:26,070 --> 00:01:28,410
emission control systems, parking systems,

31
00:01:28,410 --> 00:01:31,680
navigation, collision
sensors, climate control,

32
00:01:31,680 --> 00:01:34,432
even our antilock braking systems.

33
00:01:34,432 --> 00:01:35,490
In our aircraft,

34
00:01:35,490 --> 00:01:37,710
temperature control,
speed control sensors,

35
00:01:37,710 --> 00:01:40,500
flight management systems,
flight data recorders

36
00:01:40,500 --> 00:01:41,823
and engine controls.

37
00:01:42,660 --> 00:01:43,980
And smart meters, you know,

38
00:01:43,980 --> 00:01:47,730
the energy use, consumption,
integration and billing.

39
00:01:47,730 --> 00:01:50,496
We are just surrounded by microprocessors

40
00:01:50,496 --> 00:01:52,383
and embedded systems.

41
00:01:54,360 --> 00:01:55,920
So we're gonna look
through different types

42
00:01:55,920 --> 00:01:57,240
of embedded systems, starting

43
00:01:57,240 --> 00:02:00,570
with industrial embedded
systems, and specifically looking

44
00:02:00,570 --> 00:02:04,410
at industrial control systems
and supervisory control

45
00:02:04,410 --> 00:02:07,230
and data acquisition
systems known as SCADA.

46
00:02:07,230 --> 00:02:10,560
Now, I did introduce you
to this type of system

47
00:02:10,560 --> 00:02:12,429
earlier on when we
talked about architecture

48
00:02:12,429 --> 00:02:15,240
but now we're gonna dive
in a little bit deeper.

49
00:02:15,240 --> 00:02:18,090
So our industrial control systems or ICSs

50
00:02:18,090 --> 00:02:20,730
are gonna be embedded systems that monitor

51
00:02:20,730 --> 00:02:23,190
and control industrial
processes that exist

52
00:02:23,190 --> 00:02:24,840
in the physical world.

53
00:02:24,840 --> 00:02:27,090
Now, ICSs can either be data-driven

54
00:02:27,090 --> 00:02:28,953
or they can be operated remotely.

55
00:02:30,330 --> 00:02:34,080
Our SCADA systems, supervisory
control and data acquisition.

56
00:02:34,080 --> 00:02:37,530
SCADA usually refers to a centralized ICS

57
00:02:37,530 --> 00:02:40,500
or industrial control
system, which monitor

58
00:02:40,500 --> 00:02:44,010
very complex systems that are
spread out over large areas.

59
00:02:44,010 --> 00:02:47,250
So electricity, natural gas, gasoline,

60
00:02:47,250 --> 00:02:49,623
water, waste treatment, transportation.

61
00:02:50,580 --> 00:02:55,170
Top threats to our SCADA systems
really include cyber attack

62
00:02:55,170 --> 00:02:59,250
by politically motivated
adversaries on one hand,

63
00:02:59,250 --> 00:03:01,443
and then human error on the other.

64
00:03:02,550 --> 00:03:04,860
And our big concern in
terms of vulnerabilities

65
00:03:04,860 --> 00:03:08,147
with the SCADA system is how
long their life has to be,

66
00:03:08,147 --> 00:03:10,110
which I mentioned to you before.

67
00:03:10,110 --> 00:03:12,690
So we end up with serious
vulnerabilities included

68
00:03:12,690 --> 00:03:14,910
in outdated operating systems,

69
00:03:14,910 --> 00:03:18,030
lack of or weak authentication mechanisms,

70
00:03:18,030 --> 00:03:20,490
minimal visibility for monitoring.

71
00:03:20,490 --> 00:03:22,890
And because they always
have to be operating,

72
00:03:22,890 --> 00:03:24,963
very limited maintenance windows.

73
00:03:26,580 --> 00:03:27,510
An embedded system

74
00:03:27,510 --> 00:03:30,570
generally has three
closed loop components.

75
00:03:30,570 --> 00:03:32,430
The first is an SoC that stands

76
00:03:32,430 --> 00:03:34,924
for System-on-a-Chip,
which is a microprocessor

77
00:03:34,924 --> 00:03:39,840
or microcontroller with advanced
peripherals, such as WiFi.

78
00:03:39,840 --> 00:03:42,570
Second is a realtime operating system

79
00:03:42,570 --> 00:03:46,290
or RTOS that defines the
way the system works.

80
00:03:46,290 --> 00:03:49,800
And third is the application
software that is specific

81
00:03:49,800 --> 00:03:51,120
to the device.

82
00:03:51,120 --> 00:03:54,030
So three components, SoC, System-on-a-Chip

83
00:03:54,030 --> 00:03:56,580
RTOS, the real-time operating system

84
00:03:56,580 --> 00:03:59,583
and then the specific
application software.

85
00:04:01,350 --> 00:04:04,380
Now we do have some issues
or some vulnerabilities

86
00:04:04,380 --> 00:04:07,800
with specifically components
of the embedded system,

87
00:04:07,800 --> 00:04:11,580
the System-on-a-Chip, and the
real-time operating system.

88
00:04:11,580 --> 00:04:14,490
Generally, the chips
are really inexpensive

89
00:04:14,490 --> 00:04:17,460
and the profit margins are slim.

90
00:04:17,460 --> 00:04:19,560
So what we find on those chips

91
00:04:19,560 --> 00:04:21,180
is that there's little incentive

92
00:04:21,180 --> 00:04:25,140
to maintain them or to
update the chip firmware,

93
00:04:25,140 --> 00:04:27,660
which means they can easily
go out of date, right?

94
00:04:27,660 --> 00:04:32,070
Vulnerabilities will be
identified but not fixed.

95
00:04:32,070 --> 00:04:35,039
And then there are a
number of vulnerabilities

96
00:04:35,039 --> 00:04:37,410
in the RTOS, the real-time
operating system.

97
00:04:37,410 --> 00:04:39,480
First, there's this very strong incentive

98
00:04:39,480 --> 00:04:42,150
to use open source operating systems.

99
00:04:42,150 --> 00:04:44,700
Now the RTOS may become outdated

100
00:04:44,700 --> 00:04:47,250
and often patches are not available.

101
00:04:47,250 --> 00:04:49,020
And even if they are available,

102
00:04:49,020 --> 00:04:52,260
the expertise to install them is rare.

103
00:04:52,260 --> 00:04:54,570
So we really wanna keep
our eye on, you know,

104
00:04:54,570 --> 00:04:56,280
what kind of chips are being used

105
00:04:56,280 --> 00:04:58,323
and what is the operating system.

106
00:05:00,840 --> 00:05:03,600
Now there are a whole host
of embedded system attacks.

107
00:05:03,600 --> 00:05:06,330
Network attack, active side channel,

108
00:05:06,330 --> 00:05:08,790
memory and bus attacks,
weak authentication,

109
00:05:08,790 --> 00:05:10,459
and a steppingstone.

110
00:05:10,459 --> 00:05:13,350
A network attack just
exploits the protocol

111
00:05:13,350 --> 00:05:16,620
or the implementation
of the embedded system.

112
00:05:16,620 --> 00:05:19,980
An active side channel
attack uses a voltage glitch

113
00:05:19,980 --> 00:05:23,493
on the power supply to
cause a program malfunction.

114
00:05:24,600 --> 00:05:26,340
Memory and bus attacks

115
00:05:26,340 --> 00:05:28,260
are really when we're
physically connecting

116
00:05:28,260 --> 00:05:32,009
to the hardware and reading
the contents of the memory.

117
00:05:32,009 --> 00:05:34,713
When I say "we," I really
mean the adversary.

118
00:05:35,550 --> 00:05:38,880
Weak authentication, well
that's using the known default

119
00:05:38,880 --> 00:05:41,040
administrative password to gain access

120
00:05:41,040 --> 00:05:43,470
because they come with a default password.

121
00:05:43,470 --> 00:05:45,240
And what do we know
about default passwords?

122
00:05:45,240 --> 00:05:48,030
We know we can easily find
them out on the internet

123
00:05:48,030 --> 00:05:50,550
so we never wanna be using
those default passwords.

124
00:05:50,550 --> 00:05:52,410
However, there may be some situations

125
00:05:52,410 --> 00:05:54,810
where that default password is hard coded

126
00:05:54,810 --> 00:05:57,990
and you don't even have the
opportunity to change it.

127
00:05:57,990 --> 00:06:00,690
And very often, authentication

128
00:06:00,690 --> 00:06:03,030
will have just single password.

129
00:06:03,030 --> 00:06:06,870
And so the system might be
subject to a brute force attack.

130
00:06:06,870 --> 00:06:09,240
And then lastly, steppingstone.

131
00:06:09,240 --> 00:06:12,630
Embedded devices such as
HVAC systems, printers

132
00:06:12,630 --> 00:06:16,830
multifunction devices and camera
systems are often connected

133
00:06:16,830 --> 00:06:19,980
to the network kind of
in an unmanaged way.

134
00:06:19,980 --> 00:06:22,440
We just put these devices on our network

135
00:06:22,440 --> 00:06:25,590
but we're not really thinking
about the security of them.

136
00:06:25,590 --> 00:06:30,240
And so our adversaries
can exploit those devices,

137
00:06:30,240 --> 00:06:33,390
those embedded systems that
aren't really being managed

138
00:06:33,390 --> 00:06:35,550
and use them as a stepping stone

139
00:06:35,550 --> 00:06:38,553
or a way to pivot to more secure systems.

140
00:06:41,310 --> 00:06:44,340
So what's the best way to
secure our embedded devices?

141
00:06:44,340 --> 00:06:46,320
Well, we've got some best practices.

142
00:06:46,320 --> 00:06:50,010
The best practices include
researching our supply chain

143
00:06:50,010 --> 00:06:53,640
including our chip manufacturer
and operating system

144
00:06:53,640 --> 00:06:55,950
researching available security controls

145
00:06:55,950 --> 00:06:57,600
for the embedded system,

146
00:06:57,600 --> 00:06:59,970
immediately change the default credentials

147
00:06:59,970 --> 00:07:01,830
if that's a possibility.

148
00:07:01,830 --> 00:07:04,140
Implement strong authentication controls.

149
00:07:04,140 --> 00:07:07,560
Let's try to move away from
just a single password.

150
00:07:07,560 --> 00:07:10,410
Disable unneeded features and services,

151
00:07:10,410 --> 00:07:13,500
that's our principle
of least functionality.

152
00:07:13,500 --> 00:07:17,010
We wanna disable clear text Telnet login.

153
00:07:17,010 --> 00:07:20,730
Telnet is often used for
managing devices remotely

154
00:07:20,730 --> 00:07:22,890
but we don't wanna use Telnet.

155
00:07:22,890 --> 00:07:24,360
Its login is clear text

156
00:07:24,360 --> 00:07:26,400
and actually, it's full
transmission of clear text.

157
00:07:26,400 --> 00:07:29,553
And instead, we wanna
use Secure Shell or SSH.

158
00:07:30,720 --> 00:07:33,060
We wanna restrict remote access to devices

159
00:07:33,060 --> 00:07:34,410
as much as possible,

160
00:07:34,410 --> 00:07:36,510
so they can't be used as a stepping stone.

161
00:07:36,510 --> 00:07:39,090
And of course, we definitely,
definitely want to keep

162
00:07:39,090 --> 00:07:42,630
our devices in our vulnerability
management programs.

163
00:07:42,630 --> 00:07:43,860
We wanna include them

164
00:07:43,860 --> 00:07:45,910
in that vulnerability management program.

165
00:07:48,630 --> 00:07:51,000
Now, if you're interested
in exploring more

166
00:07:51,000 --> 00:07:55,170
about embedded systems,
I've got a option for you.

167
00:07:55,170 --> 00:07:57,270
The Raspberry Pi is a series

168
00:07:57,270 --> 00:08:00,450
of small single-board
Linux embedded systems

169
00:08:00,450 --> 00:08:02,940
that were developed by the
Raspberry Pi Foundation.

170
00:08:02,940 --> 00:08:04,890
And you can learn more
about the foundation

171
00:08:04,890 --> 00:08:09,890
at www.raspberrypi. that's
P-I, not P-I-E, dot org.

172
00:08:10,200 --> 00:08:14,040
To promote the teaching
of basic computer science.

173
00:08:14,040 --> 00:08:15,540
So you can go out there

174
00:08:15,540 --> 00:08:18,360
and you can see all of the
different options they have.

175
00:08:18,360 --> 00:08:21,612
You can buy these small
single-board Linux embedded systems.

176
00:08:21,612 --> 00:08:24,687
They do all kinds of really
cool things with them

177
00:08:24,687 --> 00:08:27,060
and they're inexpensive
and they're just a lot

178
00:08:27,060 --> 00:08:27,893
of fun to play with.

179
00:08:27,893 --> 00:08:29,700
So if you're thinking,
I'd love to get my hands

180
00:08:29,700 --> 00:08:32,130
on an embedded system and
see how they really work,

181
00:08:32,130 --> 00:08:35,760
go out to the Raspberry Pi
site and just explore it,

182
00:08:35,760 --> 00:08:37,980
you know and maybe purchase
a couple of devices

183
00:08:37,980 --> 00:08:39,660
and play with them.

184
00:08:39,660 --> 00:08:40,950
All right, that my friends,

185
00:08:40,950 --> 00:08:43,090
brings us to a three-second challenge

186
00:08:44,700 --> 00:08:46,470
Five challenge questions,
three seconds each.

187
00:08:46,470 --> 00:08:47,760
You know how to do this.

188
00:08:47,760 --> 00:08:49,680
The first one, contains a microprocessor

189
00:08:49,680 --> 00:08:53,703
and software designed to
perform a specific task.

190
00:08:54,750 --> 00:08:56,970
One, two, three.

191
00:08:56,970 --> 00:08:58,720
That's gonna be an embedded system.

192
00:09:00,540 --> 00:09:04,443
Number two, a microprocessor
with advanced peripherals.

193
00:09:05,610 --> 00:09:07,203
One, two, three.

194
00:09:08,130 --> 00:09:11,043
That's gonna be an SoC,
a System-on-a-Chip.

195
00:09:12,540 --> 00:09:15,180
Number three, an embedded
system that monitors

196
00:09:15,180 --> 00:09:17,703
and controls industrial processes.

197
00:09:18,570 --> 00:09:20,103
One, two, three.

198
00:09:21,480 --> 00:09:24,243
That's an industrial
control system, or ICS.

199
00:09:25,410 --> 00:09:28,230
Number four, a centralized ICS system

200
00:09:28,230 --> 00:09:32,553
which monitors complex systems,
spread out over large areas.

201
00:09:33,600 --> 00:09:35,430
One, two, three.

202
00:09:35,430 --> 00:09:37,590
That's gonna be our SCADA systems.

203
00:09:37,590 --> 00:09:39,960
And lastly, number five,

204
00:09:39,960 --> 00:09:42,450
a cryptographic telnet replacement.

205
00:09:42,450 --> 00:09:44,160
I went over this really quickly.

206
00:09:44,160 --> 00:09:46,140
So we don't wanna use
Telnet, it's clear text.

207
00:09:46,140 --> 00:09:48,030
It's very basic authentication.

208
00:09:48,030 --> 00:09:49,399
What should you be using instead?

209
00:09:49,399 --> 00:09:51,090
Hopefully you caught it.

210
00:09:51,090 --> 00:09:52,950
One, two, three.

211
00:09:52,950 --> 00:09:54,660
SSH or Secure Shell

212
00:09:54,660 --> 00:09:56,610
which we'll be talking a lot more about

213
00:09:56,610 --> 00:09:57,710
a little bit later on.

214
00:09:59,130 --> 00:10:01,131
All right, that brings us
to a security-in-action

215
00:10:01,131 --> 00:10:02,850
so we can apply our knowledge,

216
00:10:02,850 --> 00:10:05,520
and this one's about a SCADA system.

217
00:10:05,520 --> 00:10:08,820
You work for a small gas and oil company.

218
00:10:08,820 --> 00:10:12,390
The current SCADA system is 20 years old

219
00:10:12,390 --> 00:10:14,550
and has never been upgraded.

220
00:10:14,550 --> 00:10:15,835
You've been asked to brief
the board of directors

221
00:10:15,835 --> 00:10:18,420
on potential vulnerabilities

222
00:10:18,420 --> 00:10:22,710
and why an investment in
upgrading the system is critical.

223
00:10:22,710 --> 00:10:24,390
So what are you gonna tell them?

224
00:10:24,390 --> 00:10:26,130
Okay, so quick recap.

225
00:10:26,130 --> 00:10:29,040
You're working for this
small oil and gas company,

226
00:10:29,040 --> 00:10:32,640
you've got a SCADA
system, it's 20 years old,

227
00:10:32,640 --> 00:10:36,360
it's never ever been upgraded.

228
00:10:36,360 --> 00:10:37,410
That make you nervous?

229
00:10:37,410 --> 00:10:38,910
Hmm, I think it should.

230
00:10:38,910 --> 00:10:41,100
Okay, go ahead and put me on pause.

231
00:10:41,100 --> 00:10:41,940
Write down some notes

232
00:10:41,940 --> 00:10:43,830
about what are you gonna
tell the board of directors

233
00:10:43,830 --> 00:10:47,070
about potential vulnerabilities
and why investment

234
00:10:47,070 --> 00:10:50,013
in upgrading the system
is so very critical.

235
00:10:51,510 --> 00:10:53,873
All right, well here's
what you might tell them.

236
00:10:54,879 --> 00:10:57,313
A 20-year-old operating system is way past

237
00:10:57,313 --> 00:11:00,630
both end of life for features
and functionality, right?

238
00:11:00,630 --> 00:11:03,810
So it's considered obsolete
and end of support.

239
00:11:03,810 --> 00:11:06,093
So no more support, no more patches.

240
00:11:07,410 --> 00:11:10,410
The known and published
vulnerabilities and exploits

241
00:11:10,410 --> 00:11:13,440
with no new patches are
being developed, right?

242
00:11:13,440 --> 00:11:15,900
We know our adversaries
are still looking closely

243
00:11:15,900 --> 00:11:18,660
at those older systems,
especially SCADA systems

244
00:11:18,660 --> 00:11:21,450
which are such a high value target.

245
00:11:21,450 --> 00:11:24,420
So they're going out there
and they're finding, right,

246
00:11:24,420 --> 00:11:26,040
these new vulnerabilities,
they're publishing

247
00:11:26,040 --> 00:11:28,320
they're sharing them,
they're developing exploits.

248
00:11:28,320 --> 00:11:29,970
But on the other side,
we have no protection

249
00:11:29,970 --> 00:11:32,643
because no new patches
are being developed.

250
00:11:33,510 --> 00:11:35,310
There's no new functionality, right?

251
00:11:35,310 --> 00:11:36,990
So we're working with functionality

252
00:11:36,990 --> 00:11:38,883
from 20 years ago.

253
00:11:40,200 --> 00:11:41,910
And there's minimal, if any,

254
00:11:41,910 --> 00:11:45,210
probably support for the current controls.

255
00:11:45,210 --> 00:11:47,970
So we can't do multi-factor authentication

256
00:11:47,970 --> 00:11:50,520
we're stuck with maybe
single factor authentication.

257
00:11:50,520 --> 00:11:52,890
Probably can't do any
automated monitoring.

258
00:11:52,890 --> 00:11:56,073
And we probably have very
minimal options on reporting.

259
00:11:58,290 --> 00:12:01,830
And then we wanna remind the
board that the SCADA systems

260
00:12:01,830 --> 00:12:05,670
have been increasingly
become cyber targets

261
00:12:05,670 --> 00:12:08,070
by politically motivated adversaries

262
00:12:08,070 --> 00:12:09,600
and by cyber terrorists.

263
00:12:09,600 --> 00:12:10,897
And there's a tendency to think,

264
00:12:10,897 --> 00:12:12,480
"Well, I'm just a small company,

265
00:12:12,480 --> 00:12:14,190
they're not gonna come after me."

266
00:12:14,190 --> 00:12:16,050
But that's really a fallacy.

267
00:12:16,050 --> 00:12:18,000
You know, they're gonna
come after small companies

268
00:12:18,000 --> 00:12:19,500
just like large companies.

269
00:12:19,500 --> 00:12:22,950
They wanna cause fear, they
wanna cause disruption, right?

270
00:12:22,950 --> 00:12:26,070
They wanna, you know, introduce
mayhem into the system

271
00:12:26,070 --> 00:12:29,190
and you can do that regardless
of the size of the company.

272
00:12:29,190 --> 00:12:32,010
So having this conversation,
having them understand

273
00:12:32,010 --> 00:12:34,680
why a 20-year-old system
really is vulnerable

274
00:12:34,680 --> 00:12:38,760
and how the organization
could easily be a target

275
00:12:38,760 --> 00:12:40,620
of a cyber adversary,

276
00:12:40,620 --> 00:12:42,870
that's a such an important
conversation to have

277
00:12:42,870 --> 00:12:44,880
and to be able to do it confidently.

278
00:12:44,880 --> 00:12:46,628
That's what I want you to do.

279
00:12:46,628 --> 00:12:48,600
And well, you know it is, right?

280
00:12:48,600 --> 00:12:50,553
It's definitely security in action.

281
00:12:51,930 --> 00:12:52,763
There you go.

282
00:12:52,763 --> 00:12:53,596
There's your word cloud.

283
00:12:53,596 --> 00:12:55,380
Not particularly big,
but I wanna make sure

284
00:12:55,380 --> 00:12:57,030
that you know everything
on that word cloud

285
00:12:57,030 --> 00:12:59,520
before you move on to our next lesson.

286
00:12:59,520 --> 00:13:01,463
And when you're ready, I'll see you there.
