trabajando con gráficos en la computadora portátil

Análisis y resolución de problemas de SCADA y sistemas de control industrial

Categoría: Security / Forensics
Formato Aula abierta / Virtual / Presencial
This course is for Networking, Engineering, and Security personnel who need to develop a set of packet investigation techniques through study of the Industrial Control Systems and SCADA networking Protocols (IEC 60870, IEC 60870-5, IEC 60870-6 standard protocols: BACNET, CODESYS,.. leer más abajo
Ámsterdam / Interno / Virtual
duración: 5 días
5-12 class size
English

No hay datos disponibles todavía.

¿Estás interesado en este curso? Solicita más información. 

This course is for Networking, Engineering, and Security personnel who need to develop a set of packet investigation techniques through study of the Industrial Control Systems and SCADA networking Protocols (IEC 60870, IEC 60870-5, IEC 60870-6 standard protocols: BACNET, CODESYS, DNP3, EIP, Ethercat, Modbus, Point Protocol, S7, HART IP, and ISO Protocol) using Wireshark and other Open-Source Analysis tools. 

The technologies of Industrial Control Systems and SCADA architecture comprise many of the critical components of the worldwide critical infrastructure. Effective analysis and troubleshooting such advanced technologies encompasses the skills of not only capturing data, but also the ability to discern unusual patterns hidden within seemingly normal network traffic. This course will provide the student with a set of investigate and analysis techniques focusing on the use of vendor-neutral, Open-Source Tools such as Wireshark to provide insight into the following areas:

– Specialized configuration and advanced traffic capture tips

– Recognition, analysis and threat recognition for a many of the Industrial Control Systems currently in use in such sectors as: Energy production, Water, food and transportation technologies including IEC 60870, IEC 60870-5, IEC 60870-6 standard protocols: BACNET, CODESYS, DNP3, EIP, Ethercat, Modbus, Point Protocol, S7, HART IP, and ISO Protocol Stacks

– Specialized ICS Analysis techniques including data traffic reconstruction and viewing techniques.
Real-World examples will be utilized throughout the course in conjunction with numerous hands-on exercises to provide field proven, practical analysis skills. Attendees will receive a student guide including numerous reference files and networking and forensics tools, as well as a library of reference documents

This course is designed for Networking, Engineering and Security personnel that need to develop a set of packet investigation techniques through study of the Industrial Control Systems and SCADA networking Protocols using Wireshark and other Open-Source Analysis tools. Successful completion of this course will provide these individuals with a path-way into the field of both Network and Forensics Analysis.

Introduction to Advanced Network Analysis
Logistics
Network analysis challenges – Nomenclature, Terminology and the Next Generation Protocols

Collecting the Data – Data Capture
Recap – Data Collection
Configuring Wireshark 2.0
New features to enhance capture – USBPcap / Androiddump
Using capture filters to capture specific suspect traffic
Stealth / Silent Collection of Data – Tips & Techniques
WiFi Device Analysis using AirPcap Control Panel
New Wireless Toolbar and WiFi features – WEP / WPA / WPA2 Decryption
Bluetooth capture features
Location – How Network Infrastructure Devices Affect Network Analysis
Hubs, Switches, Bridges, Routers, Firewalls and CSU / DSU

Industrial Control Systems Architecture & Components
Architecture
Supervisory Control and Data Acquisition (SCADA)
Digital Control System (DCS)
Non-Centralized Systems (NCS)
Components
General-purpose computers
Programmable Logic Controller (PLC)
Remote Telemetry (or Terminal) Units (RTUs)
Special purpose systems
Smart sensors and actuators

 

Analysis of Network Applications and User Traffic
Key ICS / SCADA Protocols
What’s Normal vs. Abnormal – The Role of Control System Baseline Files
Color Rules
Filtering & Pattern recognition
Building a Baseline Library – Where Do I go to Find Samples?

IEC 60870, IEC 60870-5, IEC 60870-6 standard protocols
ICS / SCADA Protocol Stacks
How do the standard TCP / IP Protocols fit in?
BACNET
CODESYS
DNP3
EIP
Ethercat
Modbus
Point Protocol
S7
HART IP
ISO Protocol Stacks

 

Network Analysis Methodology
Analyzing the Network Communication Architecture
Analyzing Conversations and Activities
Analyzing Conversations and Activities Using Expert Systems to Determine Unusual Activity
Determining Which Conversations Are Suspect – Analyzing Latency and Throughput to recognize and analyze suspicious user traffic
A Sample Advanced Network Analysis Methodology
6 Steps for practical ICS / SCADA Network Analysis
Answering the key questions
A Sample Network Analysis Methodology
Diagraming Conversations – A Picture is worth 1024 Words
Related Packet and Intelligent Scrollbar features

 

Security Concerns in the ICS / SCADA Environment – When Things go Wrong
Exploiting the Target & Exploits
Drive-by-Downloads
Ransomware, Crimeware and Malware – Worms & Virus’s
Fake Login’s & Password Hijacks
Overflow’s
Internet-Based Exploits
Attacks
Bots, Botnets, Bot Herders
Denial of Service (DoS / DDoS)

Citas de estudiantes

"Me pareció que Phill es el mejor profesor y aprendo mucho de él. Gracias, Phill"

- Paul Broyd

Curso: TCP/IP Analysis and Troubleshooting with Wireshark

"Es sin duda el curso más interesante que he seguido"

- Karin van der Plas

Curso: TCP/IP Analysis and Troubleshooting with Wireshark

"Fue un curso muy, muy, muy interesante, y hecho por el mejor"

- Matthew Steenwijk

Curso:

"Fue un verdadero placer recibir la formación de Wireshark de parte de un instructor muy dedicado"

- Wim de Vries

Curso: Análisis de Redes de Voz y Video sobre IP

"Pensaba que ya conocía Wireshark. Estaba equivocada, muy equivocada"

- Jeroen Valkonet

Curso: TCP/IP Analysis and Troubleshooting with Wireshark

"Este curso es imprescindible para todos en TI"

- Johan den Besten

Curso: TCP/IP Analysis and Troubleshooting with Wireshark

"Excelente para análisis de redes o investigaciones forenses"

- Sven Schneider

Curso: Clase magistral – Redes avanzadas e introducción al análisis de seguridad

"Por mucho, el mejor curso que he tomado jamás"

- Joachim van Doeselaar

Curso: TCP/IP Analysis and Troubleshooting with Wireshark

"Si hay un paquete, ¡se puede WireSharked!!"

- Elena Petrova

Curso: Análisis de redes inalámbricas y Wi-Fi con Wireshark

"Extremadamente satisfecho con la capacitación. Instructor muy servicial y excelentes métodos de enseñanza"

- Lars Mikkelsen

Curso: Clase magistral – Redes avanzadas e introducción al análisis de seguridad

More courses within category Security / Forensics

duración: 5 días
Por anunciar.
El análisis de redes y forense abarca las habilidades de captura de datos y la capacidad de discernir patrones inusuales ocultos dentro de un tráfico de red aparentemente normal. Este curso proporciona al estudiante un...
Ámsterdam / Interno / Virtual
duración: 5 días
Por anunciar.
Capacitación Avanzada en Forense de Redes con Wireshark El análisis forense de redes es el proceso de recopilación, análisis e interpretación del tráfico de red para determinar qué sucedió en una red, cómo ocurrió un incidente y...

Regístrate y suscríbete para Análisis y resolución de problemas de SCADA y sistemas de control industrial

Elige una fecha para el curso *
Nombre *
Apellido *
Empresa *
País *
Dirección de correo electrónico *
Número de teléfono
Asistentes *
Comentario
¿Cómo se enteró de este curso? *
Un curso solo se realiza si hay suficiente participación.
*
= obligatorio

Solicitar información para Análisis y resolución de problemas de SCADA y sistemas de control industrial

*
= obligatorio

¿Desea solicitar información para más de un curso? Haga clic aquí