Exfiltrating Reconnaissance Data from Air-Gapped ICS/SCADA Networks

In this talk, we cover the following scenario: An attacker compromises the air-gapped network with autonomous, self-directed malware that performs reconnaissance to discover the network topology, the specific types of industrial devices connected to it (as with the CrashOverride malware used in the 2016 Ukrainian grid attack), and perhaps sensitive IP such as secret formulas and nuclear blueprints.

By David Atch & George Lashenko

Full Abstract & Presentation Materials: https://www.blackhat.com/eu-17/briefings.html#exfiltrating-reconnaissance-data-from-air-gapped-ics-scada-networks


