BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: OT:ICEFALL - Revisiting a decade of OT insecure-by-d
 esign\n   practices\n   When: Sunday\, Aug 14\, 11:00 - 11:59 PDT\n   Wher
 e: ICS Village Virtual\n\n   SpeakerBio:Jos Wetzels \, Security Researcher
 \n   Jos Wetzels is a security researcher at Forescout specializing in\n  
  embedded systems security. His research has involved\n   reverse-engineer
 ing\, vulnerability research and exploit development\n   across various do
 mains ranging from industrial and automotive systems\n   to IoT\, networki
 ng equipment and deeply embedded SoCs. He previously\n   worked as a resea
 rcher at the Distributed and Embedded Security group\n   (DIES) at the Uni
 versity of Twente (UT) in the Netherlands where he\n   developed exploit m
 itigation solutions for constrained Industrial\n   Control Systems (ICS) d
 evices used in critical infrastructure\,\n   performed security analyses o
 f state-of-the-art network and host-based\n   intrusion detection systems 
 and has been involved in research projects\n   regarding on-the-fly detect
 ion and containment of unknown malware and\n   Advanced Persistent Threats
 .\n\n   Description:\n   More than a decade ago\, Project Basecamp highlig
 hted how many OT\n   devices and protocols were insecure-by-design. Ever s
 ince\, the absence\n   of basic security controls has continued to complic
 ate OT security\n   programs. While the past decade has seen the advent of
 \n   standards-driven hardening efforts at the component and system level\
 ,\n   it has also seen impactful real-world OT incidents abusing\n   insec
 ure-by-design functionality\, which has left many defenders\n   wondering 
 just how much has changed. In this talk\, we will present\n   dozens of pr
 eviously undisclosed issues in products from almost 20\n   vendors deploye
 d in a wide range of industry verticals. We will\n   provide a quantitativ
 e overview of these issues and illustrate how the\n   opaque and proprieta
 ry nature of the systems has resulted in\n   insecure-by-design products a
 chieving security certification as well\n   as complicating vulnerability 
 management. In addition\, we will take a\n   technical deep-dive into seve
 ral RCE vulnerabilities on level 1\n   devices (ab)using nothing but legit
 imate functionality and present\n   quantitative insights into our researc
 h process in order to provide\n   the audience with some hard numbers on t
 he resources required to\n   develop basic offensive capabilities for the 
 issues discussed and its\n   potential implications for the relevant threa
 t landscape.\n   '\n\n
DTEND:20220814T185900Z
DTSTART:20220814T180000Z
LOCATION:ICSV - ICS Village Virtual
SUMMARY:OT:ICEFALL - Revisiting a decade of OT insecure-by-design practices
END:VEVENT
END:VCALENDAR
