В продолжение доклада Димы Даренского
@ironbang на митапе в Казахстане про мониторинг событий с ПЛК. Запись доклада «When the Network is Not Enough: Monitoring Level 1 for Insider Threats»
The ICS security community tends to focus on Level 2 and above, emphasizing network segmentation and network monitoring with little attention paid to the Level 1 controllers that form the critical bridge between the cyber and physical worlds. However, network segmentation and monitoring provides little help when the threat comes from inside your network boundaries with trusted personnel physically interacting with your PLCs. Thankfully, most PLC vendors provide diagnostic information that can be monitored to detect malicious and accidental modifications to the PLC if you know where to look.
https://ics2021.sched.com/event/muLY