37C3 - Why Railway Is Safe But Not Secure

  Рет қаралды 4,629

media.ccc.de

media.ccc.de

Ай бұрын

media.ccc.de/v/37c3-11717-why...
Security Of Railway Communication Protocols
The railway communication network looks different from your standard corporate IT. Its hardware, software and protocols have many peculiarities since it is an old, distributed, fragmented and highly standardised system. This creates problems when trying to introduce state-of-the-art IT security, and then there is the mindset: "But we always have done it this way!"
Although railways are one of the safest means of travel, they are not the most secure. What are railway engineers and IT experts fighting about? We will elaborate on the terms: Sicherheit, safety, security, and funktionale Sicherheit; and their implications.
The first railways were closed systems where employees had visual contact with the equipment. With the increasing amount of software and network growth, IT security is becoming a major concern. On the other hand, railway systems are made from various components with real-time and dependability requirements, and proprietary protocols, resulting in some security via obscurity. The main difference from other systems is the high degree of standardisation necessary for obtaining a permit. Consequently, changes take time and effort, resulting in the longevity of protocols.
This talk explains railway-specific protocols, such as GSM-R, RaSTA, and ETCS/ERMTS, their security model and known attacks. Nothing of this is new, but still, it is widely unknown.
So, join the talk, have fun, and learn how to stop a train - which is much simpler than starting one.
Katja Assaf
events.ccc.de/congress/2023/h...
#37c3 #Security

Пікірлер: 4
@camaycama7479
@camaycama7479 8 күн бұрын
My god, your channel is so consistent since many years. Keep up running the "hardware security" topic living for long!
@Julian_Legacy
@Julian_Legacy 28 күн бұрын
Great talk :) Thanks for providing some insights.
@mojoblues66
@mojoblues66 20 күн бұрын
Interessantes Thema, holprig präsentiert.
26 Incredible Use Cases for the New GPT-4o
21:58
The AI Advantage
Рет қаралды 58 М.
GPT-4o: What They Didn't Say!
14:14
Sam Witteveen
Рет қаралды 27 М.
The Noodle Stamp Secret 😱 #shorts
00:30
Mr DegrEE
Рет қаралды 27 МЛН
Balloon Pop Racing Is INTENSE!!!
01:00
A4
Рет қаралды 15 МЛН
The magical amulet of the cross! #clown #小丑 #shorts
00:54
好人小丑
Рет қаралды 21 МЛН
Communications and Network Security | CISSP Training Videos
2:05:52
Simplilearn
Рет қаралды 158 М.
Breaking Bitlocker - Bypassing the Windows Disk Encryption
9:11
stacksmashing
Рет қаралды 837 М.
The Dire State Of Intel...What Happened?
13:03
Logically Answered
Рет қаралды 120 М.
The Five Most Dangerous New Attack Techniques and How to Counter Them
46:51
37C3 -  Unlocking the Road Ahead: Automotive Digital Forensics
36:05
37C3 -  Finding Vulnerabilities in Internet-Connected Devices
47:22
media.ccc.de
Рет қаралды 25 М.
37C3 Infrastructure Review
1:11:41
media.ccc.de
Рет қаралды 2,7 М.
The Noodle Stamp Secret 😱 #shorts
00:30
Mr DegrEE
Рет қаралды 27 МЛН