OT-REX: testing what cannot be switched off
Over 18 months Yekta IT reproduces sector environments on real industrial hardware in its own laboratories, assesses industrial plants against them and publishes what can be generalised: attack paths from the offensive side, detection patterns from the defensive one. Co-funded by the European Union through the CYSSDE programme.
Who, how long, out of what
Duration
18 months of support through the CYSSDE programme.
Funding
Co-funded by the European Union, carried by the European Cybersecurity Competence Centre and its members.
Selection
Open Call 3, tendered for penetration testing and vulnerability assessment. More than 150 applications, thirteen projects selected, one of them from Germany.
Scope
Thirteen assessments are planned across the programme.
Scope of application
Industrial plants in power supply, rail and water, along with adjacent OT environments in industry and transport.
Our part
Offensive security and blue teaming from one house, together with our own laboratory environments, extended during the project with real industrial hardware.
Attack and detection from one house
A control room cannot be switched off because somebody wants to run a scan. A controller that has been in the field since 2009 sometimes answers a port scan differently from what its data sheet promises, and you find that out afterwards. An active test against a plant in operation is therefore not a procedure with a known outcome.
The run is rehearsed in our own laboratory environments first and only then carried out on the plant. YekCity is one of them; alongside it stand rigs for further sectors. In the lab, the things that must not go wrong on the plant are allowed to.
That rehearsal is the expensive part. It costs hardware, build time and people who know the sector, and all of it falls due before the first finding exists. Through the project we extend the laboratories with real industrial hardware, so that sector environments are reproduced rather than simulated.
Both sides we have in the house go into this. Offensive security supplies the attack paths and the test steps. Blue teaming answers the question of what the same attack would have looked like from the defending side. A finding on its own changes little in a plant as long as nobody knows what signal it raises in monitoring.
What leaves the circle of those involved
A programme like CYSSDE does not pay for reports. It pays for what the assessments leave behind for everybody else: test steps that can be repeated, attack paths that work in more than one plant, and detection patterns an operator can take into their own monitoring. That goes out anonymised, without names, addresses or configurations.
Then there is what stays in the laboratory. Every sector environment reproduced there remains usable afterwards, for the next assessment, for exercises and for work on detection rules. Which is why the laboratory build is part of the project and not a by-product of it.
Where this already sits in the house
- YekCity, the testbed where sector environments are reproduced and attacks made tangible.
- OT penetration testing and assessments, the same procedure outside the project.
- FINESSE, the completed research project on attack detection in road and rail transport.
- OT-REX at CYSSDE, the programme's own project page.