Speaker

Yenting Lee

Yenting Lee

Threat Researcher, TXOne Networks

Actions

Yenting Lee is a threat researcher at TXOne Networks, blending experience in ICS/SCADA, cyber offensive and defensive exercises, penetration testing, honeypot, and image processing. Yenting has spoken at several conferences such as FIRST Conference, ICS Cyber Security Conference USA/APAC, CYBERSEC, PPAM India, and InfoSec Taiwan. So far, he has also contributed several white papers and vulnerabilities on the topics of ICS.

The Lost Vision in Cyber-Physical Systems - The Anatomy of Programmable Asset Attack Vectors

A programmable asset means that the asset provides a flexible programming function, the asset can execute physical behavior automatically according to the code. In the driven modernized OT environment, we found common programmable assets including PLC, CNC, AM, and industrial robots. However, with the benefit of efficiency and adaptability, it also carries on a more complex lifecycle, leading the assets to be exposed the cyber threats.
We believe increased visibility of the threats can reduce cybersecurity risks and the overall cost of asset owners. In light of this, we analyze the lifecycle of programmable assets and survey their cyber threats at all stages. In addition to supplementing currently less-researched threats, we also show novel attack vectors from programmable assets. In this talk, we will share how attackers execute the initial attack according to the character of the programmable asset, having the opportunity to spread malicious code in the OT environment. Finally, we propose a hybrid SBOM and OT zero trust strategy to mitigate the threats.
*Draft outline, slide, and takeaway are attached in Notes part

Yenting Lee

Threat Researcher, TXOne Networks

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top