Closing the Control-Layer Visibility Gap
About This Session
Cyber defenders are often asked a critical question: Are your controllers compromised, and has their logic or configuration been tampered with? If someone were to ask you these questions right now, would you have a good answer? What tools would you reach for to answer it?
The control layer remains a major visibility gap, and process logic and device configurations are rarely verified against a trusted baseline, if a reliable baseline even exists. Although vendor software can interact with these devices, it is frequently heavyweight, expensive, proprietary, and difficult to scale for continuous or fleet-wide assessment.
This session examines the challenge of data collection from the control layer, followed by a deep dive into an open-source tool to help address that challenge: the Process Extraction and Analysis Tool (PEAT).
https://github.com/sandialabs/peat
The control layer remains a major visibility gap, and process logic and device configurations are rarely verified against a trusted baseline, if a reliable baseline even exists. Although vendor software can interact with these devices, it is frequently heavyweight, expensive, proprietary, and difficult to scale for continuous or fleet-wide assessment.
This session examines the challenge of data collection from the control layer, followed by a deep dive into an open-source tool to help address that challenge: the Process Extraction and Analysis Tool (PEAT).
https://github.com/sandialabs/peat
Speaker
Christopher Goes
Researcher IV - Cybersecurity - National Laboratory of the Rockies
Chris Goes is an operational technology cybersecurity researcher focused on OT cyber ranges and the development of practical defensive capabilities for OT environments. He brings more than a decade of experience in OT cybersecurity, turning research into deployed solutions. Previously at Sandia National Laboratories, he is now with the National Lab of the Rockies in Golden, Colorado.
