Why OT Discovery Is Harder Than IT Discovery

▶ Watch (2:08)

Industrial protocols like Modbus were designed in 1978 for efficiency, not discovery. Modbus TCP simply wraps the serial protocol inside a TCP frame. The protocol has no self-describing data. The only standard function code for identification, report server ID, returns just a unit ID. Modbus 1.1 added encapsulated interface transport in 2004. This extended operation, read device identification, returns vendor name, product code, and major/minor revision. Devices must support at least those three objects.

DNP3: Address Enumeration and Banner Sniffing

▶ Watch (10:32)

DNP3 devices on IP networks have both an IP address and a DNP3 address. They only talk to their designated primary device. Connecting via TCP yields an empty session. To query a device, you must construct a full DNP3 transport and application layer message with the correct destination address and a spoofed primary address. With 65,000 possible addresses, brute force is slow. Most networks use the lower thousand addresses. Banner sniffing works when devices send unsolicited responses containing their own source address and their primary’s destination address.

Ethernet/IP: Recursive Discovery Through Gateways

▶ Watch (15:40)

Ethernet/IP is the adaptation of the Common Industrial Protocol (CIP) for IP networks. It provides a built-in discovery mechanism called list identity. A UDP broadcast or TCP request returns the device’s vendor, product, and revision. The real power comes from CIP’s connection manager object. You can ask the Ethernet/IP adapter to forward a request through a connection to another device on its backplane. This works recursively. You can discover every PLC, motor controller, and thermal monitor in a rack, even devices connected via RS232.

Notable Quotes

i really should not see these sorts of things when i do a public scan a scan of the public internet but i do Rob King · ▶ 6:26

i really like writing protocol parsers like i would do it if they didn’t pay me but they do pay me which is great Rob King · ▶ 16:09

Key Takeaways

  • Modbus read device identification reveals vendor, product code, and revision.
  • DNP3 devices require address enumeration or unsolicited response sniffing.
  • Ethernet/IP’s connection manager enables recursive discovery across gateways.

About the Speaker(s)

Rob King is the Director of Security Research at runZero. Over his career he has served as a senior researcher with KoreLogic, the architect for TippingPoint DVLabs, and helped get several startups off the ground. Rob helped design SC Magazine’s Data Leakage Prevention Product of the Year for 2010, and was awarded the 3Com Innovator of the Year Award in 2009. He has been invited to speak at BlackHat, DEF CON, Shmoocon, SANS Network Security, and USENIX.