New portable hands-on industrial control system cyber security training kit and course

New course material from Cybati has been used in FBI and university training programs, and is now available commercially.

09/26/2011


Distributed control and SCADA systems provide automation for such critical infrastructure as the bulk electric grid system, natural gas and oil distribution, transportation, fresh water/waste water, manufacturing, food, and defense. Many control systems are electronically connected to networks of less trust, potentially even a slight distance away from the Internet. It is paramount to the safety of our society to understand the architecture of these systems and how to protect them.

The Cybati three-day hands-on course, Critical Infrastructure Control System Cyber Security, is a real-world training session for intermediate to advanced programmers, cyber professionals, and engineers covering control system vulnerabilities, threats, and mitigating controls. This course provides hands-on analysis of DCS and SCADA environments, allowing participants to understand the impacts of attacks like Stuxnet, and supporting mitigating controls as defined in the NERC reliability standards, Department of Homeland Security CFATs, and other industry and government based recommended controls, such as ISA, NIST, NNSA, IEC, NRC, EPA, INGAA, FDA, and CPNI.

Participants learn control system cyber architecture, ladder logic programming, cyber vulnerability assessments, and attack surface analysis, along with mitigating physical, cyber, and operational controls. Hands-on laboratories include attacking and protecting PLCs and other control system hardware. Participants perform actual man-in-the-middle injections leading to false operator displays, rogue PLC administration, and automation and safety-system ladder logic analysis to identify potential failure models and mitigating controls.

Matthew E. Luallen, Cybati co-founder and president says, “Recent events such as Stuxnet, and exploits and vulnerabilities discussed at conferences such as Blackhat and Defcon are a concern to any modern society. This hands-on training environment and course material allows participants to focus on the vulnerabilities associated with control systems, tactically understand the risks and identify security controls. The control system training kit and courseware provides real world examples of cyber security risks and controls that can help asset owners protect their investment.”

Watch a video of DePaul University students who have completed a similar course.

https://cybati.org/

Edited by Peter Welander, pwelander@cfemedia.com



No comments
The Engineers' Choice Awards highlight some of the best new control, instrumentation and automation products as chosen by...
The System Integrator Giants program lists the top 100 system integrators among companies listed in CFE Media's Global System Integrator Database.
The Engineering Leaders Under 40 program identifies and gives recognition to young engineers who...
This eGuide illustrates solutions, applications and benefits of machine vision systems.
Learn how to increase device reliability in harsh environments and decrease unplanned system downtime.
This eGuide contains a series of articles and videos that considers theoretical and practical; immediate needs and a look into the future.
Salary and career survey: Benchmarks and advice; Designing controls; Remote data collection, historians; Control valve advances; Hannover Messe; Control Engineering International
System integration: Best practices and technologies to help; Virtualization virtues; Cyber security advice; Motor system efficiency, savings; Product exclusives; Road to Hannover
Collaborative robotics: How to improve safety, return on investment; Industrial Internet of Things, Industrie 4.0: World views; High-performance HMI, Information Integration: OPC and OMG
This article collection contains several articles on the Industrial Internet of Things (IIoT) and how it is transforming manufacturing.
PLCs, robots, and the quest for a single controller; how OEE is key to automation solutions.

Find and connect with the most suitable service provider for your unique application. Start searching the Global System Integrator Database Now!

Getting to the bottom of subsea repairs: Older pipelines need more attention, and operators need a repair strategy; OTC preview; Offshore production difficult - and crucial
Digital oilfields: Integrated HMI/SCADA systems enable smarter data acquisition; Real-world impact of simulation; Electric actuator technology prospers in production fields
Special report: U.S. natural gas; LNG transport technologies evolve to meet market demand; Understanding new methane regulations; Predictive maintenance for gas pipeline compressors
click me