werken met grafieken op een laptop

SCADA- en industriële besturingssystemen: analyse en probleemoplossing

Categorie: Security / Forensics
Formaat Open Klaslokaal / Virtueel / In-house
This course is for Networking, Engineering, and Security personnel who need to develop a set of packet investigation techniques through study of the Industrial Control Systems and SCADA networking Protocols (IEC 60870, IEC 60870-5, IEC 60870-6 standard protocols: BACNET, CODESYS,.. lees hieronder meer
Amsterdam / In-house / Virtueel
duur: 5 dagen
5-12 class size
Engels

Nog geen gegevens beschikbaar.

Bent u geïnteresseerd in deze cursus? Vraag meer informatie aan. 

This course is for Networking, Engineering, and Security personnel who need to develop a set of packet investigation techniques through study of the Industrial Control Systems and SCADA networking Protocols (IEC 60870, IEC 60870-5, IEC 60870-6 standard protocols: BACNET, CODESYS, DNP3, EIP, Ethercat, Modbus, Point Protocol, S7, HART IP, and ISO Protocol) using Wireshark and other Open-Source Analysis tools. 

The technologies of Industrial Control Systems and SCADA architecture comprise many of the critical components of the worldwide critical infrastructure. Effective analysis and troubleshooting such advanced technologies encompasses the skills of not only capturing data, but also the ability to discern unusual patterns hidden within seemingly normal network traffic. This course will provide the student with a set of investigate and analysis techniques focusing on the use of vendor-neutral, Open-Source Tools such as Wireshark to provide insight into the following areas:

– Specialized configuration and advanced traffic capture tips

– Recognition, analysis and threat recognition for a many of the Industrial Control Systems currently in use in such sectors as: Energy production, Water, food and transportation technologies including IEC 60870, IEC 60870-5, IEC 60870-6 standard protocols: BACNET, CODESYS, DNP3, EIP, Ethercat, Modbus, Point Protocol, S7, HART IP, and ISO Protocol Stacks

– Specialized ICS Analysis techniques including data traffic reconstruction and viewing techniques.
Real-World examples will be utilized throughout the course in conjunction with numerous hands-on exercises to provide field proven, practical analysis skills. Attendees will receive a student guide including numerous reference files and networking and forensics tools, as well as a library of reference documents

This course is designed for Networking, Engineering and Security personnel that need to develop a set of packet investigation techniques through study of the Industrial Control Systems and SCADA networking Protocols using Wireshark and other Open-Source Analysis tools. Successful completion of this course will provide these individuals with a path-way into the field of both Network and Forensics Analysis.

Introduction to Advanced Network Analysis
Logistics
Network analysis challenges – Nomenclature, Terminology and the Next Generation Protocols

Collecting the Data – Data Capture
Recap – Data Collection
Configuring Wireshark 2.0
New features to enhance capture – USBPcap / Androiddump
Using capture filters to capture specific suspect traffic
Stealth / Silent Collection of Data – Tips & Techniques
WiFi Device Analysis using AirPcap Control Panel
New Wireless Toolbar and WiFi features – WEP / WPA / WPA2 Decryption
Bluetooth capture features
Location – How Network Infrastructure Devices Affect Network Analysis
Hubs, Switches, Bridges, Routers, Firewalls and CSU / DSU

Industrial Control Systems Architecture & Components
Architecture
Supervisory Control and Data Acquisition (SCADA)
Digital Control System (DCS)
Non-Centralized Systems (NCS)
Components
General-purpose computers
Programmable Logic Controller (PLC)
Remote Telemetry (or Terminal) Units (RTUs)
Special purpose systems
Smart sensors and actuators

 

Analysis of Network Applications and User Traffic
Key ICS / SCADA Protocols
What’s Normal vs. Abnormal – The Role of Control System Baseline Files
Color Rules
Filtering & Pattern recognition
Building a Baseline Library – Where Do I go to Find Samples?

IEC 60870, IEC 60870-5, IEC 60870-6 standard protocols
ICS / SCADA Protocol Stacks
How do the standard TCP / IP Protocols fit in?
BACNET
CODESYS
DNP3
EIP
Ethercat
Modbus
Point Protocol
S7
HART IP
ISO Protocol Stacks

 

Network Analysis Methodology
Analyzing the Network Communication Architecture
Analyzing Conversations and Activities
Analyzing Conversations and Activities Using Expert Systems to Determine Unusual Activity
Determining Which Conversations Are Suspect – Analyzing Latency and Throughput to recognize and analyze suspicious user traffic
A Sample Advanced Network Analysis Methodology
6 Steps for practical ICS / SCADA Network Analysis
Answering the key questions
A Sample Network Analysis Methodology
Diagraming Conversations – A Picture is worth 1024 Words
Related Packet and Intelligent Scrollbar features

 

Security Concerns in the ICS / SCADA Environment – When Things go Wrong
Exploiting the Target & Exploits
Drive-by-Downloads
Ransomware, Crimeware and Malware – Worms & Virus’s
Fake Login’s & Password Hijacks
Overflow’s
Internet-Based Exploits
Attacks
Bots, Botnets, Bot Herders
Denial of Service (DoS / DDoS)

Studentenquotes

"Ik vond Phill de beste leraar, en ik leer erg veel van hem. Dank je wel, Phill"

- Paul Broyd

Cursus: TCP/IP Analysis and Troubleshooting met Wireshark

"Het is absoluut de meest interessante cursus die ik heb gevolgd"

- Karin van der Plas

Cursus: TCP/IP Analysis and Troubleshooting met Wireshark

"Het was een zeer, zeer, zeer interessante cursus, en gegeven door de absolute topman"

- Matthew Steenwijk

Cursus

"Het was een waar genot om de Wireshark-training te krijgen van een zeer toegewijde trainer"

- Wim de Vries

Cursus: Voice & Video over IP Netwerkanalyse

"Ik dacht dat ik Wireshark al kende. Ik had het mis, heel erg mis"

- Jeroen Valkonet

Cursus: TCP/IP Analysis and Troubleshooting met Wireshark

"Deze cursus is een absolute must-have voor iedereen in de IT"

- Johan den Besten

Cursus: TCP/IP Analysis and Troubleshooting met Wireshark

"Geweldig voor netwerkanalyses of forensisch onderzoek"

- Sven Schneider

Cursus: Masterclass – Geavanceerd Netwerk & Introductie tot Beveiligingsanalyse

"Veruit de allerbeste cursus die ik ooit heb gevolgd"

- Joachim van Doeselaar

Cursus: TCP/IP Analysis and Troubleshooting met Wireshark

"Als er een datapakket is, kan het worden gewireswarked!!"

- Elena Petrova

Cursus: WiFi & Wireless Network Analysis Using Wireshark

"Extreem tevreden over de training. Zeer behulpzame instructeur en geweldige lesmethoden"

- Lars Mikkelsen

Cursus: Masterclass – Geavanceerd Netwerk & Introductie tot Beveiligingsanalyse

More courses within category Security / Forensics

Amsterdam / In-house / Virtueel
duur: 5 dagen
Nog te bepalen.
Netwerk- en forensische analyse omvat de vaardigheden van het vastleggen van data en het vermogen om ongewone patronen te onderscheiden die verborgen zijn in schijnbaar normaal netwerkverkeer. Deze cursus biedt de student een..
Amsterdam / In-house / Virtueel
duur: 5 dagen
Nog te bepalen.
Geavanceerde netwerkforensische training met Wireshark Netwerkforensica is het proces van het verzamelen, analyseren en interpreteren van netwerkverkeer om te bepalen wat er op een netwerk is gebeurd, hoe een incident heeft plaatsgevonden en...

Meld je aan en registreer je voor SCADA- en industriële besturingssystemen: analyse en probleemoplossing

Kies een cursusdatum *
Voornaam *
Achternaam *
Bedrijf *
Land *
E-mailadres *
Telefoonnummer
Aanwezigen *
Opmerking
Hoe heb je over deze cursus gehoord? *
Een cursus gaat alleen door bij voldoende deelname.
*
= verplicht

Informatie aanvragen voor SCADA- en industriële besturingssystemen: analyse en probleemoplossing

*
= verplicht

Wilt u informatie aanvragen voor meer dan één cursus? Klik hier