Black Hatters Target Industrial Wireless Sensor Networks #wireless #WirelessHART #ISA100 #Zigbee

Jan. 1, 2000

At Black Hat this week, two researchers from IOActive, Lucas Apa and Carlos Penagos, presented a paper and slide presentation entitled, "Compromising Industrial Facilities from Forty Miles Away."

At Black Hat this week, two researchers from IOActive, Lucas Apa and Carlos Penagos, presented a paper and slide presentation entitled, "Compromising Industrial Facilities from Forty Miles Away."

I've read the paper and seen the slides, although I didn't hear the actual presentation at Black Hat. I have some comments.

They discuss 802.15.4 devices, but focused on two proprietary protocols and one that may be a product that is obsolete and no long manufactured. One of the proprietary protocols (they called it Vendor 1) has a very small footprint in process automation, and even in factory automation it isn't large. Vendor 3 is also a proprietary protocol device family, built on the 802.15.4 platform.

Apa and Penagos concentrated on Zigbee, which has extremely well known security problems, but they mentioned IEC62591WirelessHART and ISA100.11a as though they share the same problems. In fact, the reason the ISA100 committee and the team that built WirelessHART didn't use Zigbee was these same vulnerabilities and instabilities in that protocol.

Zigbee has a very small footprint in manufacturing, being confined to building automation and some Smart Grid applications.

I have gone to all of the vendors mentioned and asked for statements. Should  I get any, I wll reveal who the vendors are. If you see the slides, you can pretty easily see who the three vendors are, even though the devices are barely disguised.

I have a problem with presenting poorly researched papers like this, and hyping them the way these presenters did. It isn't stated anywhere in the paper what the 40 miles away figure means, and their discussion did not clearly separate the differences between the protocols they discussed, or dissed.

There's a word for cyber researchers like this: irresponsible.

It would be excellent to have them contact me and discuss this, but I bet they won't.

Sponsored Recommendations

Make Effortless HMI and PLC Modifications from Anywhere

The tiny EZminiWiFi is a godsend for the plant maintenance engineers who need to make a minor modification to the HMI program or, for that matter, the PLC program. It's very easy...

The Benefits of Using American-Made Automation Products

Discover the benefits of American-made automation products, including stable pricing, faster delivery, and innovative features tailored to real-world applications. With superior...

50 Years of Automation Innovation and What to Expect Next

Over the past 50 years, the automation technology landscape has changed dramatically, but many of the underlying industry needs remain unchanged. To learn more about what’s changed...

Manufacturing Marvels Highlights Why EZAutomation Is a Force to Be Reckoned With

Watch EZAutomation's recent feature on the popular FOX Network series "Manufacturing Marvels" and discover what makes them a force to be reckoned with in industrial automation...