Showing posts with label Aegis. Show all posts
Showing posts with label Aegis. Show all posts

Wednesday, March 12, 2014

AEGIS Releases Fuzzer

As promised, Adam Crain announced this morning on TWITTER® that AEGIS had publicly released their DNP3 Fuzzer. It is available, along with documentation, on the AEGIS web site.

Adam and Chris Sistrunk have made something of a name for themselves over the last year testing various DNP3 applications with this tool and publicly disclosing the vulnerabilities they found through a strict coordinated disclosure process (so strict that we still don’t know who 11 of the 28 vendors are). So far, they claim that they haven’t found an application that did not have a discoverable vulnerability.

While most people that will be downloading this Fuzzer will be security researchers wanting to get a good look at the tool that Adam and Chris have been using to such good effect, Adam has made it clear that he really wants DNP3 system owners to get and use this tool to identify for themselves the vulnerabilities in their particular systems.

To my way of thinking, it certainly would be smart to know what your system vulnerabilities are before someone with a black hat starts testing.


BTW: Adam and Chris already are putting to use a similar Modbus TCP tool. I will be keeping an eye out for the ICS-CERT Advisories.

Monday, September 23, 2013

Aegis Update and Vulnerability Debate

Adam Crain has a very interesting blog post over at Automatak.net providing additional information about his Aegis project (earlier blog post on Aegis). The Aegis Consortium is an important new business model for researchers and for that reason alone this post is worth reading. More importantly, he is adding an important new dimension to the disclosure debate.

Background

Adam is relatively new to the control system security field, but he has already made a significant mark. His first vulnerability discovery was reported by ICS-CERT in June of this year and he already has 8 ICS-CERT advisories with his name on them (along with Chris Sistrunk). All of these have been coordinated disclosures. His Project Robus lists 17 additional vulnerability disclosures that are wending their way through the coordinated disclosure process.

All of the disclosures that have been made public to date have dealt with vulnerabilities in various implementations of the DNP3 protocol. I assume that a number of the pending vulnerability disclosures will also involve that protocol. Adam is quick to note that the problem isn’t with the DNP3 protocol, but with the various implementations by the affected vendors. In fact he goes so far as to say “we have yet to find a proprietary DNP3 implementation without an issue”.

Fuzzer Tool Release

Adam developed the fuzzer tool that he used (again along with Chris and a new associate Adam Todorski) to find these 25 vulnerabilities. Now fuzzer tools are not new in the cybersecurity realm, and I don’t know what make his different than others, but his tool certainly has an impressive early track record. Adam has promised that he will publicly release his fuzzer in March at the SANS NA ICS Security Summit.

Again, I have no idea how user friendly his fuzzer is, but presumably anyone with a modicum of cybersecurity research experience will be able to use this tool to find new vulnerabilities in control system applications. Adam has demonstrated its efficacy with DNP3 so any vendor with a DNP3 application has cause to be concerned that currently undiscovered vulnerabilities in their systems might not remain undiscovered for long after this tool is released.

Now a fuzzer is just a tool, not inherently good or bad. A security researcher like Adam puts it to good use identifying vulnerabilities in a system and reporting them to the vendor. A vendor can use it to find and correct the same vulnerabilities. And a terrorist can use it to find a way to gain system access and control for part of a control system attack.

With this in mind, Adam is offering vendors and researchers access to his fuzzer before its public release; for a fee. After all Adam needs to make a living just like anyone else and he should be able to profit from his talents and efforts.

Vulnerabilities are Available

Some will complain that Adam is making the job of the black hat hacker that much easier by making this tool publicly available. I would seriously disagree. With making this tool available to vendors and other white hat researchers ahead of time, Adam is decreasing the potential attack surface that is vulnerable to attack.

Any criticism of Adam’s making this tool publicly available ignores a very important point in the vulnerability disclosure debate. Adam did not put these vulnerabilities in the DNP3 implementations; he just made them easier to find. They were put there by vendors that did not do an adequate job of testing their product before they made them available to the public. It is the vendor, not the researcher, who is responsible for the vulnerabilities.


Now it is hard to blame the vendor when the owner/operators have already given them a free pass for any vulnerabilities that exist in their systems. We as a user community have accepted the almost universal vendor terms of service that declaim that the vendor is not responsible for any defects in their product and that they don’t warrant its use for any particular application. As long as we give vendors a free pass on the quality of their products, we have little room to complain about the existence of vulnerabilities or researchers who find them.

Friday, September 13, 2013

Tools for Testing DNP3 – Aegis Platform

I got an interesting email from Adam Crain today. It was part of a continuing message chain, but he tossed off a new subject:

“FYI, I just announced the release of the DNP3 fuzzer at SANS SCADA in March 2014”

He then provided a link to a new page on his Automatak.com web site - http://www.automatak.com/aegis/.

Adam and his compatriot, Chris Sistrunk, have demonstrated a talent for finding vulnerabilities in DNP3 applications. They have made a name for themselves in the last couple of weeks from their being listed as the responsible researcher on 8 ICS-CERT advisories. I don’t know the details of their disclosure agreements with the affected vendors, but I seriously doubt that they have made much, if any, money off of these disclosures.

BTW: There are now 17 ‘pending’ disclosures on the Project Robus web site; two more than earlier this week. So, contrary to my earlier supposition, they haven’t stopped their testing efforts.

This is the problem that most ‘ethical researchers’ have run in to; there is little or no money to be made from coordinated disclosures. This is one of the reasons that so many cybersecurity researchers have turned to selling vulnerabilities on either the black or grey markets; it’s a way to pay the bills and keep food on the table. The rub, of course, is that these markets put owner/operators at risk.

Adam, it seems has come up with a slightly different marketing angle. Instead of selling vulnerabilities he is effectively going to sell tools he develops to find vulnerabilities. It is not explicitly pointed out on his web site, but his email makes clear that he is looking to vendors and utility owner/operators to be members of his “consortium of industrial control system (ICS) stakeholders” thus staying on the side of ‘ethical hackers’.

BTW: I made the comment in an earlier blog post that other ICS protocols might undergo examination by Crain-Sistrunk. A side-bar on the AEGIS page points out that there is a “Modbus master/slave” under development. I suspect that we will shortly begin seeing ICS-CERT advisories pointing out vulnerabilities in Modbus related applications. Fortunately (sarcasm warning) there aren’t too many of those out there. In fact, some of those 17 pending disclosures might be Modbus related instead of DNP3. Some people would be happy to see that.


It will be interesting to see how well Automatak does with this project. I hope that he succeeds, we need more owner/operator-friendly hacker business-models.
 
/* Use this with templates/template-twocol.html */