AI-Augmented Attacks on Industrial Control Systems and the Road Ahead
About This Session
When John Matherly presented Shodan at DEF CON 18 in 2010 he highlighted a world of exposed industrial infrastructure. It was a surreal moment as he navigated through the engine to interact with web-connected ICS/OT devices. While we think of that as the past critical infrastructure assets still populate the tool and it provides enumeration and reconnaissance for security professionals and threat actors even today.
Similar to this famous presentation 15 years ago, the community is starting to witness the rise of AI-assisted threat actors. In an intrusion against a municipal water and drainage utility in Monterrey, Mexico, an adversary used commercial AI tools to carry out core intrusion activities with no prior knowledge of or intent to target OT infrastructure. What distinguished this campaign was not the novelty of its techniques, publicly available offensive methods, but the speed and autonomy with which AI operationalized them.
While making predictions about the future of technology is always a dubious task, there is a short runway of action to take in the near time to harden security controls against the weaponization of AI by adversaries. AI is being used to shorten that time from IT compromise to weaponization of stage 2 ICS-capable attacks that can have a direct impact on the operations of the victim’s organization.
Similar to this famous presentation 15 years ago, the community is starting to witness the rise of AI-assisted threat actors. In an intrusion against a municipal water and drainage utility in Monterrey, Mexico, an adversary used commercial AI tools to carry out core intrusion activities with no prior knowledge of or intent to target OT infrastructure. What distinguished this campaign was not the novelty of its techniques, publicly available offensive methods, but the speed and autonomy with which AI operationalized them.
While making predictions about the future of technology is always a dubious task, there is a short runway of action to take in the near time to harden security controls against the weaponization of AI by adversaries. AI is being used to shorten that time from IT compromise to weaponization of stage 2 ICS-capable attacks that can have a direct impact on the operations of the victim’s organization.
Speaker
Mackenize Morris
Principal Industrial Consultant - Dragos
Mackenize Morris is a Principal Industrial Consultant at the industrial cybersecurity company Dragos, Inc. where he assists the professional services teams in conducting network and vulnerability assessments.
Previously, Mackenize worked as a chemical engineer and system architect and administrator for a DOE contractor for a DCS system until fully switching over to an ICS cybersecurity position within the DOE complex.
Mackenize received his B.S. in Chemical Engineering and MBA from the University of South Carolina as well as a Masters in Information Security Engineering from the SANS Technology Institute. He currently holds a dozen GIAC Certifications.
Mackenize’s name is pronounced like Mackenzie; the IZE spelling was a result of a spelling error on his birth certificate.
Previously, Mackenize worked as a chemical engineer and system architect and administrator for a DOE contractor for a DCS system until fully switching over to an ICS cybersecurity position within the DOE complex.
Mackenize received his B.S. in Chemical Engineering and MBA from the University of South Carolina as well as a Masters in Information Security Engineering from the SANS Technology Institute. He currently holds a dozen GIAC Certifications.
Mackenize’s name is pronounced like Mackenzie; the IZE spelling was a result of a spelling error on his birth certificate.
