What can a small device do in modern industrial World.

Similar documents
nblue TM BR-MUSB-LE4.0-S2A (CC2540)

Agriculture Wireless Temperature and Humidity Sensor Network Based on ZigBee Technology

Wireless Sensor Networks BLUETOOTH LOW ENERGY. Flavia Martelli

Wireless (NFC, RFID, Bluetooth LE, ZigBee IP, RF) protocols for the Physical- Data Link layer communication technologies

C300RU. Version Mbps 11n Wireless USB adapter. Technical Specification Sheet

Reindeer Technologies Pvt Ltd Excellence through Innovation

Digital Circuits Part 2 - Communication

Smart cards are made of plastic, usually polyvinyl chloride. The card may embed a hologram to prevent counterfeiting. Smart cards provide strong

AIM: To create a project for implement a wireless communication protocol on an embedded system- ZigBee.

Amarjeet Singh. February 7, 2012

Product Brief. Model: TLM922S-P01A. Ver.1.0

Bluetooth low energy technology Bluegiga Technologies

Victor Kwong Marketing Manager

Guide to Wireless Communications, 3 rd Edition. Objectives

System Architecture Challenges in the Home M2M Network

Product Brief. Model: TLM922S-P01A. Ver.1.4

Low Power Wide Area Network (LPWAN) Presented By: Dr. Hafiz Yasar Lateef Director, Telxperts Pty Ltd.

1. IEEE and ZigBee working model.

Guide to Wireless Communications, Third Edition. Objectives

New CC430 combines leading MCU and RF technology

LM817 WiFi and Dual Mode Bluetooth Combination Adapter Host Controller Interface (HCI) via USB Interface

CIS 700/002 : Special Topics : Bluetooth: With Low Energy comes Low Security

Unencrypted Mouse Packet

Wireless# Guide to Wireless Communications. Objectives

LM820 WiFi b/g/n Module with IC Antenna Host Controller Interface (HCI) via USB Interface

Cyan Technology Ltd. Smart energy solutions. Meeting the challenges of smart metering in emerging regions

WZRDnet. A Low-Power Wireless Ad-Hoc Mesh Network for Austere Tactical Environments. February 14, 2018

Improving Remote Site Communications Using Wireless Technologies. Eric Swanson

By Ambuj Varshney & Akshat Logar

CM5000 DATASHEET v0.1

UNCLASSIFIED//FOR OFFICIAL USE ONLY INDUSTRIAL CONTROL SYSTEMS CYBER EMERGENCY RESPONSE TEAM

Questions & Answers From Thursday, September 16 Webinar Alternatives Case Examples Frequency and Spectrum Planning Security WiMAX Capabilities

WIRELESS SENSOR NETWORK

LM005 WiFi b/g/n Adapter 300Mbps Host Controller Interface (HCI) via USB Interface

Wireless# Guide to Wireless Communications. Objectives

The dark side of IOT. Francesco Zucca. Automation Instrumentation Summit Wireless Expert

Wireless Terms. Uses a Chipping Sequence to Provide Reliable Higher Speed Data Communications Than FHSS

WIRELESS TECHNOLOGIES

[A SHORT REPORT ON BLUETOOTH TECHNOLOGY]

OpenWay by Itron Security Overview

RESOURCES. By: Chris Downey, Laird Technologies Product Manager, Telematics & Wireless M2M Date: May 25, 2011

Wireless LAN. Access Point. Provides network connectivity over wireless media

Assignment Project Whitepaper ITEC495-V1WW. Instructor: Wayne Smith. Jim Patterson

MOTOTALK DIRECT TALK

SMART Response PE interactive response system Receiver and clicker

nblue TM BR-LE4.0-S2A (CC2540)

br301 DATA SHEET V1.1 Feitian technologies Co., Ltd. Website:

TinySec: A Link Layer Security Architecture for Wireless Sensor Networks. Presented by Paul Ruggieri

WIRELESS MESH NETWORKING: ZIGBEE VS. DIGIMESH WIRELESS MESH NETWORKING: ZIGBEE VS. DIGIMESH

ArduCAM CC3200 UNO board

RF4431 wireless transceiver module

Alternative Designs and Decision Making for Top Design Selection

Wireless technology Principles of Security

Sensor-to-cloud connectivity using Sub-1 GHz and

WirelessHART, Technology and Deployment ( ETSI Nov. 09 ) Jean-Luc Griessmann, HART Communication Foundation Europe

CHAPTER- 2 WIRELESS TECHNOLOGIES FOR POWER SYSTEM APPLICATIONS/MANAGEMENT

Developer & maintainer of BtleJuice. Having fun with Nordic's nrf51822

SMART Response XE interactive response system Receiver and clicker

What do we expect from Wireless in the Factory?

TRESCCA Trustworthy Embedded Systems for Secure Cloud Computing

# ROLE DESCRIPTION / BENEFIT ISSUES / RISKS

1 WATT/900 MHZ STAND-ALONE RADIO MODEMS

STA-MU-A0028S (MiniCard-USB version)

A Wireless Identification System to Assist Sight- Constrained People

Employing Wireless Bluetooth for C 3 in Industrial Automation C. Norz C. Miller

Co-Existence of WirelessHART with other Wireless Technologies

Wireless networking with three times the speed and five times the flexibility.

BT2540 Bluetooth 4.0 BLE (CC2540) Module Users Manual

Cigré Colloquium SC D2 / India 2013 Paper D SMART, UTILITY-GRADE WI-FI MESH FOR DISTRIBUTION GRIDS

Lecture Objectives. Lecture 1 Wireless Environment and Wireless LANs. Agenda (1) Agenda (2) Wireless Spectrum (1)

IoTECH* *Internet of Things Extensible Car Hub. MDR Presentation

Breaking and Fixing Cri.cal Infrastructure. Jus.n Searle Managing Partner U.liSec

im871a Wireless M-Bus

Chapter 3.1 Acknowledgment:

Error characteristics and their prediction in ZigBee transmission at coexistence conditions

Wireless# Guide to Wireless Communications. Objectives

Plan. powerline network technology. Ref. :

Specification of JBT Mesh Bluetooth Module

Wireless Local Area Networks. Networks: Wireless LANs 1

STA-UI-A003D (USB version)

Welcome to my presentation: Message Denial and Alteration on IEEE Low- Power Radio Networks.

VertexCom. VC83X0 Product Brief. Version: 0.4 Release Date: June 28, Specifications are subject to change without notice.

BLE MODULE SPECIFICATIONS

Announcements / Wireless Networks and Applications Lecture 9: Wireless LANs Wireless. Regular Ethernet CSMA/CD.

Security. Reliability

Product Description. Applications. Features

Green Lights Forever: Analyzing the Security of Traffic Infrastructure

A Real-Time BLE enabled ECG System for Remote Monitoring

Qualcomm Wi-Fi Connectivity Selector Guide

LM820 WiFi b/g/n Module with IC Antenna Host Controller Interface (HCI) via USB Interface

SPECIFICATIONS LR802UKG. Ver. 2A1 Date: 06/15/ b/g Wireless LAN USB Module. Approved by :

IEEE Testing Signal Compliance of ZigBee Standard

Pass4suresVCE. Pass4sures exam vce dumps for guaranteed success with high scores

Wireless Local Area Networks (WLANs)) and Wireless Sensor Networks (WSNs) Computer Networks: Wireless Networks 1

WHITE PAPER. Expert Tips for Planning an Industrial Wireless Network. Mike Werning Field Application Engineer, Moxa Americas

WP-PD Wirepas Mesh Overview

Security and Privacy in Smart Meters and Smart Grids. EECE 512 Konstantin Beznosov

ReMutt Control. Critical Design Review

Wireless Connectivity Options for IoT. By: MIST Makers John Varela and Nicholas Landy

Outline. Multi-Channel Reliability and Spectrum Usage in Real Homes Empirical Studies for Home-Area Sensor Networks. Smart Grid

Transcription:

What can a small device do in modern industrial World Alexey.Polyakov@kaspersky.com Konstantin.Sapronov@kaspersky.com

Agenda Smart badge Sub 1Ghz RF Demo with RFCat Smart Grids Inside Smart Meters Threats for smart devices by RF Conclusion

ToorCon 14 Badge and DK_Dongle

HardWare Texas Instrument CC1111 chip CC1111F32 Sub 1-Ghz Max power 1W, good to transmit to 230Meter! With external antenna can transmit even miles away 32 kb of in-system programmable flash memory 4 kb of RAM, can buffer up to 500 bytes in memory full-speed USB 2.0 interface

Sub 1Ghz RF Sub 1Ghz ISM bands: 900Mhz 433MHz Cell phones, Cordless phones, Personal Two-Way Radio; Medical equipment 315 MHz Car/Garage Remotes 915/868MHz (US/EU) Smart meters and more P25 Policy radios

Using Sub 1GHz device: Demo with RFCat Establishing peer-to-peer session with 2 CC1111 devices We will show how simple it can be done. Advantage: not able to capture unless you have another one. You can use it without risk of been detected

Discovering RF World: Home Devices Power Meters (also as for gas, water measuring devices) 90% in US household, used by all Power Providers - Use 902-928 MHz to operate, FHSS, Remote reading

Inside Smart Meters Elster Rex2 1. Power converts 2. Teridian 71M6531F SOC with a microprocessor core, a real-time clock, flash memory, and an LCD driver 3. Texas Instruments low-power LM2904 dual operational amplifier. 4. medium-power RFMD RF2172 amplifier IC. 5. less-than-1-ghz Texas Instruments CC1110F32 SOC with a microcontroller and 32 kbytes of flash memory.

Smart Grid Infrastructure Power Line equipment Transformers, Isolators, Condensers, Switches and line breakers; Power meters, field equipment 90% still with Leased line (expensive). Moving towards RF grid Remote area Readers and Control devices may use RF feature

Impacts of exploitation for RF devices If you exploit such devices you can : remote keys / car fobs : open or close 2-ways phones : listen power meters : monitor and control Smart Grids : power outage SCADA : damage medical devices: kill

Threats by RF for smart devices Attacks : Reading private data Theft of service Jamming Tx/Rx signals Possible damaging power line equipment: Isolators condensers Switches power transformers Cost of repair can be small (5K) to high (2M for Transformers)

Discovering Smart Meters troubles - Before able to read, need to understand next Tx frequency - Usually, it is shifted from original basic frequency May take days or week of analysis - The transmission is preset with SYNCWORD - Usually 2 bytes, but, need to look at thousands of transmission to find correct one. - RFCAT is able to help, but, luck and luck needed! - Another challenge is package length and transmission data ratio

Security? Current prevention solutions: FHSS SYNCWORDS DSSS dynamic routing tables Security: encryption. AES 128 session authentification

Discovering Smart Meters FHSS Beginning: transmitting session #1 (approx 913MHz) 3 min later: transmitting session #2 (approx 904 MHz)

Discovering Smart Meters more 5 hours later Full 902-928MHz spectrum is covered FHSS predefined rules for selecting next transmitting frequency Unknown Baud rate unknown packet length Same packets sent over and over many times Remote receiver

Discovering Smart Meters - SYNCWORD

Conclusion Power Meters is a good and typical example of Industrial reading devices More recently, they were not easy ways to find equipment for security researches in this area Now, we have a good RF device for testing Smart Meters. However, it takes a lot of time to understand how Smart Meters work Security by design (FHSS, frequency hopping, predefined communication list) is widely used but it is not enough. Some advanced ideas (data encryption, session authentication) is less used You can discover what happens around by just using available devices like the one presented earlier. The cost is between $50-$100.

Thanks to Toorcon team for badge Mike Ossman for specan Atlas for RFcat And YOU for attention Questions?!