YoVDO

The Little Pump Gauge That Could - Attacks Against Gas Pump Monitoring Systems

Offered By: Black Hat via YouTube

Tags

Black Hat Courses Cybersecurity Courses Critical Infrastructure Security Courses Vulnerability Analysis Courses

Course Description

Overview

Explore a comprehensive analysis of attacks on Guardian AST gas pump monitoring systems in this 54-minute Black Hat conference talk. Delve into the details of real and simulated attacks, uncovering attacker profiles, motivations, and indicators of compromise. Learn about the Gaspot script for deploying virtual monitoring systems, and gain insights into the vulnerabilities of these environments. Examine the honeypot architecture, deployment strategies, and attack scenarios. Discover the involvement of various actors, including government entities and criminals, in targeting these systems. Understand pump modifications, IDC hacking, and prevention techniques. Gain valuable knowledge on securing gas pump monitoring systems and interpreting attack statistics.

Syllabus

Introduction
Welcome
Overview
Target Attackers
Underground Forums
Incidents
Vulnerabilities Incidents
Why are these environments attacked
The Government
Criminals
Nonpatched
Guardian ST
How the system works
Demonstration
Inventory Command
Critical vs NonCritical
The Honeypot
Honeypot Architecture
Honeypot Deployment
Honeypot Code
Honeypot Randomization
Honeypot Name Change
Inmap Script
Classification
Attribution
Attack Scenarios
Attack Breakdown
Connection Attempts
Valid Commands
Attack Statistics
Eddie Murphy Slide
Syrian Electronic Army
Jordanian Honey Pots
Pump Modifications
IDC
Hacking
IDC Involvement
Release
When
Preventing Attacks
Security
Logs
Was it Targeted


Taught by

Black Hat

Related Courses

Attack on Titan M, Reloaded - Vulnerability Research on a Modern Security Chip
Black Hat via YouTube
Attacks From a New Front Door in 4G & 5G Mobile Networks
Black Hat via YouTube
AAD Joined Machines - The New Lateral Movement
Black Hat via YouTube
Better Privacy Through Offense - How to Build a Privacy Red Team
Black Hat via YouTube
Whip the Whisperer - Simulating Side Channel Leakage
Black Hat via YouTube