SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client...

65

Transcript of SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client...

Page 1: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET
Page 2: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

*All pictures are taken from Dr StrangeLove movie and other Internets

Sergey GordeychikAleksandr TimorinGleb Gritsai

SCADA STRANGELOVE

SCADA.SL

Page 3: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

Group of security researchers focused on ICS/SCADA

to save Humanity from industrial disaster

and to keep Purity Of Essence

Alexander TimorinAlexander TlyapovAlexander ZaitsevAlexey OsipovAndrey MedovArtem ChaykinDenis BaranovDmitry EfanovDmitry Nagibin

Dmitry SerebryannikovDmitry SklyarovEvgeny ErmakovGleb GritsaiIlya KarpovIvan PoliyanchukKirill NesterovRoman IlinSergey Bobrov

Sergey DrozdovSergey GordeychikSergey ScherbelTimur YunusovValentin ShilnenkovVladimir KochetkovVyacheslav EgoshinYuri GoltsevYuriy Dyachenko

Page 4: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

Aleksandr Timorin

ICS security researcher

Industrial protocols fan and 0-day PLC hunter

SCADAStrangeLove team member

The Ocean band fan

atimorin

[email protected]

Page 5: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

ICS basics 101

Vulnerabilities

• Input validation

• Design and architecture

Safety and security as a whole

Page 6: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

What is ICS world and why we should develop carefully

Today is the digital era (welcome back captain obvious!)

Automated processes is everywhere – from home

automation to big energy plants, from brewery to traffic

control systems

Page 7: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

What is ICS world and why we should develop carefully

Industry automatization processes becoming more

comfortably for engineers and operators

Page 8: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

What is ICS world and why we should develop carefully

Switching from analog to digital brings old and absolutely not

secure software development process

Page 9: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

What type of ICS products are vulnerable:

• Client/Server software

• Field devices: RTU, PLC, protective relays, power meters,

converters, actuators and so on

• Network switches, gateways

• GSM/GPRS modems, wireless AP

• Mobile applications

• Industrial protocols

• Human factor

Page 10: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

Analytics and statistics of ICS vulnerabilities

• Analyzed CVE since ~2010

• Data source: ics-cert.us-cert.gov

• CVE details: NVD

• Total unique CVE: 689

• CVSS 2.0: min score 1.7 , max score 10.0 , avg score 6.5 ,

high and critical count of scores 285 (41%)

Page 11: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

Analytics and statistics of ICS vulnerabilities

• CWE statistics:

CWE - Common Weakness Enumeration

Definitions and full detailed description at

https://nvd.nist.gov/cwe.cfm

Unique number of CWE = 43

Page 12: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

Analytics and statistics of ICS vulnerabilities

• CWE statistics (TOP 20):$ sort cwe.all.raw | uniq -c | sort –nr | head -20

Page 13: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

Analytics and statistics of ICS vulnerabilities

• CWE statistics (TOP 20):

Page 14: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

Buffer Errors

Information Leak / Disclosure

Input Validation

Permissions, Privileges, and Access ControlXSSCryptographic Issues

Credentials Management

Resource Management Errors

Path Traversal

Authentication Issues

Use of Hard-coded Credentials

CSRF

Improper Access Control

SQL Injection

Unrestricted Upload of File with Dangerous Type

Untrusted Search Path

Security FeaturesCode Injection

NULL Pointer DereferenceNumeric Errors

Other (after TOP20)

Page 15: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET
Page 16: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

• Honeywell EPKS, CVE-2014-9189

Page 17: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

• Honeywell EPKS, CVE-2014-9187

Page 18: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

• cb is a buffer size

Page 19: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET
Page 20: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

• SpiderControl SCADA Web Server, stack-based bof, CVE-

2015-1001

Page 21: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

• Siemens SIPROTEC 7SJ64 (protective relay) XSS

Page 22: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

• Siemens WinCC

Page 23: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET
Page 24: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET
Page 25: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

PLC1

PLC2

PLC3

Some networks

WinCC Web-Client

WinCC SCADA-Clients

WinCC SCADA-Client +Web-Server

WinCC DataMonitor

WinCC Web-Client

WinCC DataMonitor

WinCC Servers

LAN

PROFINET

PROFIBUS

Internet, corp lan, vpn’s

Engineering station(TIA portal/PCS7)

Page 26: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

WinCCExplorer.exe/PdlRt.exe

Create and use your own security featuresInstead of standard features – that’sA bad idea!

Page 27: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

• Hardcodes are for protocols with auth: SNMP, telnet, HTTP,

etc.

• You can hardcode keys, certificates, passwords

• SMA Sunny WebBox

Page 28: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

• Siemens SIPROTEC 4 protective relay confirmation code

“311299”:

- System log

- Device info

- Stack and other

parts of memory

- More ?

Page 29: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

• Siemens SIPROTEC 4 protective relay confirmation code

“311299”:

“SIPROTEC 4 and SIPROTEC Compact devices allow the

display of extended internal statistics and test information…

To access this information, the confirmation code “311299” needs

to be provided when prompted.”

“...Siemens does not publish official documentation on these

statistics. It is strongly recommended to work together with

Siemens SIPROTEC customer care or commissioning experts to

retrieve and interpret the statistics and test information...”

Page 30: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

• Siemens S7-1200 PLC, CVE-2014-2252

“An attacker could cause the device to go into defect mode if

specially crafted PROFINET packets are sent to the device. A

cold restart is required to recover the system. ”

Just “set” PROFINET request: set network info (ip, netmask,

gateway) with all zero values.

Page 31: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

Not secure by design: default credentials, autocomplete

• Defaults, factory settings (sometimes unchangeable) is

everywhere

SCADA StrangeLove Default/Hardcoded Passwords List

https://github.com/scadastrangelove/SCADAPASS

Page 32: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

KIOSK mode:

Limit access to OS

functions

Page 33: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

KIOSK mode: Limit access to OS functions

Page 34: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

• Wincc accounts: “secret” crypto key

Page 35: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

• WinCC accounts: “secret” crypto key fixed

• It’s XOR, they should not bother hardcoding for XOR

Page 36: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

PLC password “encryption”

Password (8 bytes)

Page 37: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

• TIA Portal PEData.plf passwords history

Page 38: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

• Winccwebbridge.dll: please hash your hardcoded account

Page 39: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

• Siemens S7-1200, S7-1500 PLC, CVE-2014-2250, CVE-

2014-2251

Page 40: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

• Siemens S7-1200, S7-1500 PLC, CVE-2014-2250, CVE-

2014-2251

• Seed = plc_start_time + const

Page 41: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

Target – Siemens S7-1200 PLC

Page 42: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

Profinet “feature” and PRNG vulnerability - real attack vector.

Result - PLC takeover.

Page 43: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

- Hash passwords

- SHA is not good enough

- Put length of plaintext nearby

Redbox_value = len(pwd)*2+1

Page 44: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

Architecture looks like ideal (from developers point of view)

Page 45: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

Reality looks like ideal too (from attacker point of view)

Page 46: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

Reality looks like ideal too (from attacker point of view)

Page 47: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

Many vendors tend to develop bicycles own services (ftp,

telnet, ssh, http etc.)

Guten Tag WinCC:

• WinCC Server

Windows/MSSQL based SCADA

• WinCC Client (HMI)

WinCC runtime + project

• WinCC Web Server (WebNavigator)

IIS/MSSQL/ASP/ASP.NET/SOAP

• WinCC WebClient (HMI)

ActiveX/HTML/JS

Page 48: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

Third-party services:

• deploying with default and example.config configurations (i.e.

lot of busybox based devices with default root account)

• No patches and updates

Page 49: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

Mirai DDos botnet

DVR, NVR, IP cameras

Over 0.5 million IoT devices are vulnerable

What’s the problem? Hardcoded root:xc3511

Moreover, not so easy to change it

Page 50: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET
Page 51: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

to get firmware?to get debug symbols?to debug?..PowerPC

no “operation system”

Page 52: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET
Page 53: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET
Page 54: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

― Interlocking security (by Jakob Lyng Petersen)

• Trains must not collide

• Trains must not derail

• Trains must not hit person working the tracks

—Sadly, animals can’t handle the interview

― Formal methods and verification (rtfm)

• B Method, Event B

—Underground rail network in Beijing, Milan and Sao Paulo

• Prover.com

—Sweden, USA

Page 55: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

― Safety critical systems

― Abstract machines + formal methods

― Atelier B

• Available IDE and C translator

• No Ada translator

― Newer version – Event-B

• See Rodin framework

Page 56: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET
Page 57: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET
Page 58: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

• “Everything will be C in the end. If it's not C, it's not the end.”

– almost John Lennon

Page 59: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

― KVB: Alstom

• Automatic Train Protection for the French railway company (SNCF), installed on 6,000 trains since 1993

—60,000 lines of B; 10,000 proofs; 22,000 lines of Ada

― SAET METEOR: Siemens Transportation Systems

• Automatic Train Control: new driverless metro line 14 in Paris (RATP), 1998. 3 safety-critical software parts: onboard, section, line

—107,000 lines of B; 29,000 proofs; 87,000 lines of Ada

― Roissy VAL: ClearSy (for STS)

• Section Automatic Pilot: light driverless shuttle for Paris-Roissy airport (ADP), 2006

—28,000+155,000 lines of B; 43,000 proofs; 158,000 lines of Ada

Page 60: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET
Page 61: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET
Page 62: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

• RTFM

• SSDLC

• ICS best practices

• Follow CERTs

• Common Weakness Enumeration at cwe.mitre.org

• More practice: OWASP TOP 10

• TESTING TESTING AND TESTING AGAIN!

Page 63: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

Mr. ICS developer, are you creating your products within

SSDLC concepts?

Page 64: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET

*All pictures are taken from googleand other Internets

Alexander TimorinAlexander TlyapovAlexander ZaitsevAlexey OsipovAndrey MedovArtem ChaykinDenis BaranovDmitry EfanovDmitry NagibinDmitry SerebryannikovDmitry SklyarovEvgeny ErmakovGleb GritsaiIlya KarpovIvan PoliyanchukKirill NesterovRoman IlinSergey BobrovSergey DrozdovSergey GordeychikSergey ScherbelTimur YunusovValentin ShilnenkovVladimir KochetkovVyacheslav EgoshinYuri GoltsevYuriy Dyachenko

Page 65: SCADA STRANGELOVE - GOTO Conference · • GSM/GPRS modems, wireless AP ... SCADA-Client +Web-Server WinCC DataMonitor WinCC Web-Client WinCC DataMonitor WinCC Servers LA N PROFINET