Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

detect more ICS device make/model/class #121

Closed
mmguero opened this issue Apr 14, 2020 · 3 comments
Closed

detect more ICS device make/model/class #121

mmguero opened this issue Apr 14, 2020 · 3 comments

Comments

@mmguero
Copy link
Collaborator

mmguero commented Apr 14, 2020

It might be cool to look at grassmarlin's fingerprint database and see if there's anything there we could to do identify more kinds of ICS devices. At what point would this fingerprinting be done?

@mmguero mmguero added enhancement New feature or request ics Relating to ICS (Industrial Control Systems) devices labels Apr 14, 2020
@mmguero
Copy link
Collaborator Author

mmguero commented Apr 15, 2020

Since this wouldn't really be a new "parser" per-se, I think using Zeek signatures could actually be a good way to detect these kind of fingerprints.

@mmguero mmguero added the zeek Relating to Malcolm's use of Zeek label Apr 15, 2020
@mmguero
Copy link
Collaborator Author

mmguero commented Apr 15, 2020

So here's my cool idea: I'd like to see if it's feasible to take a python script that reads some selections from grassmarlin's fingerprint database and automatically translates them to zeek signatures. need to check OSS license compatibility, but I think where it's LGPL we'd be ok.

@mmguero
Copy link
Collaborator Author

mmguero commented Sep 9, 2020

Kamino closed and cloned this issue to idaholab/Malcolm

@mmguero mmguero closed this as completed Sep 9, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant