当前位置:首页 > 报告详情

Debug7:利用固件修改攻击远程调试西门子 S7 PLC.pdf

上传人: 鲁** 编号:615403 2025-03-03 62页 5.92MB

1、#BHASIA BlackHatEventsDebug 7Leveraging a Firmware Modification Attack for Remote Debugging of Siemens S7 PLCsRon Semel|Eyal SemelJoint work with Prof.Eli Biham,Dr.Sara Bitan and Alon DanknerFaculty of Computer Science,Technion Israel Institute of Technology#BHASIA BlackHatEventsWho Are We?Ron Semel

2、Software engineer at MicrosoftMicrosoft Defender for Endpoint(MDE)Security researcherComputer science faculty,Technionhttps:/ SemelSecurity researcherComputer science faculty,Technionhttps:/ BlackHatEventsTalk Topics Introduction and Previous Research Runtime Manipulation of Siemens S7 PLCs Firmware

3、 Implementation of Debug 7-a Remote Debugger for Siemens S7 PLCs Debugger Video Demo Conclusions#BHASIA BlackHatEventsThe 4thIndustrial Revolution Industry 4.0 Can anyone imagine life without:Our necessities are made accessible via automated industrial control systems.Wastewater treatment plants pur

4、ify water.Complex signaling systems manage traffic.Food is grown using automatic irrigation systems.Drinking waterFoodTransportationAmazonAutomated warehouses manage our online purchases#BHASIA BlackHatEventsThe 4thIndustrial Revolution Industry 4.0 These smart control systems include:Mass integrati

5、on of IOT devices.Extensive cloud communication.Smart automationAll these cool new features come with risks#BHASIA BlackHatEventsAttacks on Critical Infrastructure Cyber attacks on critical infrastructure can be catastrophic!We have a great responsibility securing these systems!https:/ BlackHatEvent

6、sPLC Programmable Logic ControllerPLCs are rugged computers used for industrial automation.They are the core component of an ICS.They read input data from field devices such as sensors.Outputs are triggered based on pre-programmed code.A bridge between the virtual world and the physical world.#BHASI

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
本文介绍了Ron Semel和Eyal Semel等研究人员对Siemens S7 PLCs的研究成果。他们发现S7 PLCs的固件存在严重安全漏洞,可以通过修改Windows OS中的文件来远程修改PLC的SWCPU。研究人员实现了一个名为Debug 7的远程调试器,可以动态分析SWCPU的运行情况,甚至可以注入恶意代码。他们还通过Web服务器实现了数据的远程提取。Siemens S7 PLCs是市场上领先的PLC产品,但现在变得非常脆弱。研究人员呼吁行业采取措施,如实施安全的启动链,以保护PLC免受固件修改攻击。
"如何远程调试西门子S7 PLCs?" "西门子S7 PLCs存在哪些安全漏洞?" "如何为西门子S7 PLCs构建远程调试器?"
客服
商务合作
小程序
服务号
折叠