DEF CON 32 - The Risk and Reward of Distributed Industrial Control - Joe Slowik

DEF CON 32 - The Risk and Reward of Distributed Industrial Control - Joe Slowik

Source: YouTube · DEFCONConference · published Oct 16, 2024 · 26:35

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The main message is that distributed industrial control systems, enabled by wireless and remote connectivity, have dramatically expanded the attack surface for critical infrastructure, requiring new security and resilience strategies. 2:00

Key Takeaways:
• Distributed operations now rely on wireless, remote connectivity, increasing exposure to adversaries 4:30.
• The acid rain malware incident disrupted wind turbines via a satellite network, demonstrating real-world risks of unsecured wireless control systems 10:21.
• Colonial Pipeline’s incident highlights that even small, distributed systems can face severe disruption if control links are compromised 13:01.
• Critical infrastructure must ensure command integrity and have fail-safe fallbacks to prevent cascading failures during network outages 19:45.
• Security must prioritize communication integrity over encryption due to latency and bandwidth constraints in remote systems 21:47.

Remote operations are now a necessity, not a luxury, but without robust security and redundancy, they introduce significant risks to operational safety and continuity. 25:32

Sources:

  • 2:00 Introduction to distributed operations and expanded attack surfaces
  • 4:30 Shift from wired to wireless connectivity in industrial systems
  • 10:21 Acid rain malware attack on wind turbines via satellite network
  • 13:01 Colonial Pipeline in

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

so should we get started okay I guess we're getting started so hello everyone welcome to Defcon at the lovely Las Vegas Convention Center fabulous new venue that we're all learning to deal with uh first off can folks who are sitting in the back hear me because I know it's a pretty difficult room so there's plenty of space up here feel free to move forward or whatever the screens are also a little tiny if you're sitting in the back trust me I don't bite and I don't think anyone else here does either but what we'll talk about today is getting into the risk and reward of distributed Industrial Control Systems uh first who am I my name is Joe slowick I currently do a bunch of things over at the miter corporation like leading up some of the functions within attack and doing critical infrastruct…