ICSJWG – Key Takeaways

If you attended the recent ICSJWG Spring 2012 conference, you likely attended the panel that Industrial Defender organized entitled “Key Takeaways from S4 and Project Basecamp.” Moderated by Bob Lockhart from Pike Research, the members of the panel included: Markus Braendle, ABB Robert McComber, Telvent/Schnieder Graham Speake, Yokogowa Brad Hegrat, Rockwell/Allen-Bradley Jonathan Pollet, Red Tiger Security Jacob Kitchel, Industrial Defender There were a lot of good questions, strong opin << More >>

Advanced Persistent Threats

Mandiant has just released a report on Advanced Persistent Threats. This was the organization providing the keynote address at the recent Digital Bond S4 conference. The paper can be requested at: http://www.mandiant.com/products/services/m-trends The contents of the report are disturbing. Mandiant documents cases where a patient and very capable adversary has infiltrated many different organizations. In one case, only 10 systems out of 50,000 were taken over, and in one of those systems, the m << More >>

Application Whitelisting and Control Systems

I just got back from the Digital Bond SCADA Security Scientific Symposium (S4) where I presented on whitelisting. Whitelisting is the “hot new” host intrusion prevention system (HIPS) technology that some tout as the end of the anti-virus (AV) era. Anti-virus of course works by producing a “black list” of virus signatures. If data or a file matches a signature, the AV technology takes some sort of action to protect your system – anything from a popup alert to blocki << More >>