Actioning Threat Intelligence: Tuning Intrusion Detection Systems for Nation State Attacks
About This Session
Recent joint alerts from the FBI, CISA, NSA, EPA, DOE, and U.S. Cyber Command warn of active cyber exploitation of internet connected operational technology (OT) devices across U.S. critical infrastructure. Iranian advanced persistent threat (APT) actors—linked to prior IRGC associated CyberAv3ngers activity—are actively targeting PLCs supporting government, water, and energy sectors.
This presentation analyzes the observed OT attack kill chain, from initial access to operational impact, and maps adversary behavior to the MITRE ATT&CK® for ICS framework. We'll also delve into how OT-aware Intrusion Detection Systems (IDS) can help to mitigate each stage of the kill chain. OT IDS identified anomalous remote desktop activity, unauthorized protocol access retrieving PLC attributes, exposed device vulnerabilities, threat actor IP addresses and C2 communications, and unauthorized PLC command and control state changes in near real time.
This presentation analyzes the observed OT attack kill chain, from initial access to operational impact, and maps adversary behavior to the MITRE ATT&CK® for ICS framework. We'll also delve into how OT-aware Intrusion Detection Systems (IDS) can help to mitigate each stage of the kill chain. OT IDS identified anomalous remote desktop activity, unauthorized protocol access retrieving PLC attributes, exposed device vulnerabilities, threat actor IP addresses and C2 communications, and unauthorized PLC command and control state changes in near real time.
Speaker
Leonard Kershteyn
Director of Product Management Cybersecurity - Honeywell International Inc
Leo Kershteyn, CISSP, GICSP is Director of Product Management with over a decade of experience in the industrial cybersecurity sector. He has been closely involved in Honeywell’s strategic cybersecurity portfolio realignment and M&A of an OT intrusion detection platform that has since evolved into Honeywell’s flagship industrial cybersecurity offering.
Leo began his career as an Electrical Engineer and brings deep technical expertise across cybersecurity, OT threat detection, and critical infrastructure protection. He currently resides in the Atlanta, Georgia metropolitan area.
Leo began his career as an Electrical Engineer and brings deep technical expertise across cybersecurity, OT threat detection, and critical infrastructure protection. He currently resides in the Atlanta, Georgia metropolitan area.
