Research and security lab
Three demonstrators with real controllers: a model city, a train and a vehicle. Plus a lab in which attacks are allowed to run.
Attacks need a place where they may run
In a plant you cannot try out what a manipulated telegram does. In a simulation you can show it but not prove it, because the controller that would react is missing.
So we build rigs with real technology: the same controllers, the same field buses, the same protocols. What works there works in the plant, and what gets detected there can be carried over as a detection rule.
Three environments
Three environments out of our own research, all with real hardware and real protocols. On each of them attacks can be run, detected and practised.
Research, training and testing
In research they produce publications and tools. VATT&EK, our taxonomy for attacks on road and rail vehicles, was developed on these rigs and presented at conferences.
In training, teams work on them: the attacking side runs complete chains, the defending side has to detect and respond, and in joint formats the SOC, the control room and management sit at one table and experience the same incident from three roles.
In client projects they serve as a substitute environment: what may not be tried in the plant can be reproduced here.
What clients book the lab for
Red and blue team exercises
OT attacks such as Industroyer have physical consequences. On the miniature plants, practical scenarios run with real protocols, the effect is visible, and it can be fed straight into a SIEM. The red team runs complete attack chains, the blue team has to detect and respond. Teams from the SOC, the control room and management see the same attack on the same plant.
OT penetration tests
We develop and try attack techniques on the platforms before they are used in a client plant. What we run at your site has run on comparable hardware first.
SOC detection testing
Your analysts check on the platforms whether their use cases fire. Which signature catches an IEC 104 manipulation? What does Modbus abuse look like in the SIEM? We provide the test environment with real attacks.
Courses and training
Your teams work on hardware that functions. What does a CAN bus attack look like? What happens with an IEC 104 injection? How does a rail IDS react to an MVB manipulation?
Common questions about the lab
Yes. We give tours of the test environment in Dortmund, and the rigs appear regularly at trade fairs and conferences.
What to expect:
- A tour of the OT test environment
- A live demonstration of an attack on a platform of your choice
- Technical questions to our OT security testers
- A discussion of your own use cases
Yes. Controllers, control units and components can be tested in the lab without a plant standing still. That is also the route for manufacturers who need evidence to IEC 62443.
The results are peer-reviewed and published, among others at ACM CSCS and CRITIS, and the FINESSE project ran with funding over three and a half years. The rigs are the instrument for that.
For three groups. Operators who want to play a crisis exercise through without risking production. Security staff who need to learn on real technology. And manufacturers who want a component tested before it goes into a plant.
Certifications and memberships.
Talk to us.
A first conversation usually takes 30 minutes. We look at where you stand and tell you frankly whether we are the right partner.