lavorare con i grafici sul portatile

Analisi e risoluzione dei problemi di SCADA e sistemi di controllo industriale

Category: Security / Forensics
Format: Open Classroom / Virtual / In-house
This course is for Networking, Engineering, and Security personnel who need to develop a set of packet investigation techniques through study of the Industrial Control Systems and SCADA networking Protocols (IEC 60870, IEC 60870-5, IEC 60870-6 standard protocols: BACNET, CODESYS,.. read more below
Amsterdam / Interno / Virtuale
durata: 5 giorni
5-12 class size
English

No data available yet.

Or you interested in this course? Request more information. 

This course is for Networking, Engineering, and Security personnel who need to develop a set of packet investigation techniques through study of the Industrial Control Systems and SCADA networking Protocols (IEC 60870, IEC 60870-5, IEC 60870-6 standard protocols: BACNET, CODESYS, DNP3, EIP, Ethercat, Modbus, Point Protocol, S7, HART IP, and ISO Protocol) using Wireshark and other Open-Source Analysis tools. 

The technologies of Industrial Control Systems and SCADA architecture comprise many of the critical components of the worldwide critical infrastructure. Effective analysis and troubleshooting such advanced technologies encompasses the skills of not only capturing data, but also the ability to discern unusual patterns hidden within seemingly normal network traffic. This course will provide the student with a set of investigate and analysis techniques focusing on the use of vendor-neutral, Open-Source Tools such as Wireshark to provide insight into the following areas:

– Specialized configuration and advanced traffic capture tips

– Recognition, analysis and threat recognition for a many of the Industrial Control Systems currently in use in such sectors as: Energy production, Water, food and transportation technologies including IEC 60870, IEC 60870-5, IEC 60870-6 standard protocols: BACNET, CODESYS, DNP3, EIP, Ethercat, Modbus, Point Protocol, S7, HART IP, and ISO Protocol Stacks

– Specialized ICS Analysis techniques including data traffic reconstruction and viewing techniques.
Real-World examples will be utilized throughout the course in conjunction with numerous hands-on exercises to provide field proven, practical analysis skills. Attendees will receive a student guide including numerous reference files and networking and forensics tools, as well as a library of reference documents

This course is designed for Networking, Engineering and Security personnel that need to develop a set of packet investigation techniques through study of the Industrial Control Systems and SCADA networking Protocols using Wireshark and other Open-Source Analysis tools. Successful completion of this course will provide these individuals with a path-way into the field of both Network and Forensics Analysis.

Introduction to Advanced Network Analysis
Logistics
Network analysis challenges – Nomenclature, Terminology and the Next Generation Protocols

Collecting the Data – Data Capture
Recap – Data Collection
Configuring Wireshark 2.0
New features to enhance capture – USBPcap / Androiddump
Using capture filters to capture specific suspect traffic
Stealth / Silent Collection of Data – Tips & Techniques
WiFi Device Analysis using AirPcap Control Panel
New Wireless Toolbar and WiFi features – WEP / WPA / WPA2 Decryption
Bluetooth capture features
Location – How Network Infrastructure Devices Affect Network Analysis
Hubs, Switches, Bridges, Routers, Firewalls and CSU / DSU

Industrial Control Systems Architecture & Components
Architecture
Supervisory Control and Data Acquisition (SCADA)
Digital Control System (DCS)
Non-Centralized Systems (NCS)
Components
General-purpose computers
Programmable Logic Controller (PLC)
Remote Telemetry (or Terminal) Units (RTUs)
Special purpose systems
Smart sensors and actuators

 

Analysis of Network Applications and User Traffic
Key ICS / SCADA Protocols
What’s Normal vs. Abnormal – The Role of Control System Baseline Files
Color Rules
Filtering & Pattern recognition
Building a Baseline Library – Where Do I go to Find Samples?

IEC 60870, IEC 60870-5, IEC 60870-6 standard protocols
ICS / SCADA Protocol Stacks
How do the standard TCP / IP Protocols fit in?
BACNET
CODESYS
DNP3
EIP
Ethercat
Modbus
Point Protocol
S7
HART IP
ISO Protocol Stacks

 

Network Analysis Methodology
Analyzing the Network Communication Architecture
Analyzing Conversations and Activities
Analyzing Conversations and Activities Using Expert Systems to Determine Unusual Activity
Determining Which Conversations Are Suspect – Analyzing Latency and Throughput to recognize and analyze suspicious user traffic
A Sample Advanced Network Analysis Methodology
6 Steps for practical ICS / SCADA Network Analysis
Answering the key questions
A Sample Network Analysis Methodology
Diagraming Conversations – A Picture is worth 1024 Words
Related Packet and Intelligent Scrollbar features

 

Security Concerns in the ICS / SCADA Environment – When Things go Wrong
Exploiting the Target & Exploits
Drive-by-Downloads
Ransomware, Crimeware and Malware – Worms & Virus’s
Fake Login’s & Password Hijacks
Overflow’s
Internet-Based Exploits
Attacks
Bots, Botnets, Bot Herders
Denial of Service (DoS / DDoS)

Student qoutes

"Ho trovato che Phill sia il miglior insegnante e imparo molto da lui. Grazie Phill"

- Paul Broyd

Corso: TCP/IP Analysis and Troubleshooting with Wireshark

"È sicuramente il corso più interessante che abbia seguito"

- Karin van der Plas

Corso: TCP/IP Analysis and Troubleshooting with Wireshark

"È stato un corso molto molto molto interessante, tenuto dal numero uno"

- Matthew Steenwijk

Corso:

"È stato un vero piacere ricevere la formazione su Wireshark da un formatore molto dedicato"

- Wim de Vries

Corso: Analisi di reti Voice & Video over IP

"Pensavo di conoscere già Wireshark. Mi sbagliavo, mi sbagliavo di grosso"

- Jeroen Valkonet

Corso: TCP/IP Analysis and Troubleshooting with Wireshark

"Questo corso è assolutamente da non perdere per chiunque lavori nell'IT"

- Johan den Besten

Corso: TCP/IP Analysis and Troubleshooting with Wireshark

"Ottimo per analisi di rete o indagini forensi"

- Sven Schneider

Corso: Masterclass – Reti Avanzate e Introduzione all'Analisi della Sicurezza

"Di gran lunga il corso migliore che abbia mai seguito"

- Joachim van Doeselaar

Corso: TCP/IP Analysis and Troubleshooting with Wireshark

"Se c'è un pacchetto, può essere intercettato con WireShark!!"

- Elena Petrova

Corso: Analisi di reti WiFi e wireless tramite Wireshark

"Estremamente soddisfatto della formazione. Istruttore molto disponibile e ottimi metodi di insegnamento"

- Lars Mikkelsen

Corso: Masterclass – Reti Avanzate e Introduzione all'Analisi della Sicurezza

More courses within category Security / Forensics

durata: 5 giorni
T.B.A.
Network and Forensics Analysis encompasses the skills of capturing data and the ability to discern unusual patterns hidden within seemingly normal network traffic. This course provides the student with an..
durata: 5 giorni
T.B.A.
Advanced Network Forensics Training with Wireshark Network forensics is the process of collecting, analyzing, and interpreting network traffic to determine what happened on a network, how an incident occurred, and..

Sign up and register for Analisi e risoluzione dei problemi di SCADA e sistemi di controllo industriale

Choose a course date *
First name *
Last name *
Company *
Country *
Email address *
Phone number
Attendees *
Comment
How did you hear about this course *
A course only takes place if there is sufficient participation.
*
= required

Request information for Analisi e risoluzione dei problemi di SCADA e sistemi di controllo industriale

*
= required

Do you want to request information for more than one course? Click here