In this episode, host Aaron Crow dives into critical infrastructure and industrial control systems with special guests Matthew Miller and James Warne. Together, they introduce ResetCon—an upcoming conference to close the gap between technical research and practical applications in cybersecurity.
Our listeners get an exclusive discount for attending ResetCon this year! Visit https://rstcon.org/2024/ and use the code PrOTect to receive a 10% discount on your tickets.
The discussion highlights the importance of including cybersecurity in infrastructure design, tackling supply chain attacks, and fostering collaboration among industry experts. With the call for papers closing soon, listeners are encouraged to submit abstracts and join this revolutionary initiative.
Episode 18 promises valuable insights into the intersection of IT, OT, and critical infrastructure cybersecurity. It emphasizes the need for more skilled professionals and community-driven solutions.
Don’t miss this chance to learn, get inspired, and prepare for ResetCon!
Key Moments:
03:32 ResetCon aims to deliver cutting-edge tech talks.
08:47 Debating cause, but the outcome is unchanged.
11:49 Conference seeks to address critical infrastructure issues.
16:06 ICS Village presence at key cybersecurity events vital.
18:34 Sharing industry knowledge and protecting brand integrity.
20:51 Colin O'Flynn presents cutting-edge hardware innovations.
26:05 Diverse audiences at the ponderous conference.
28:34 Understanding same team, goals, critical infrastructure, not experts.
30:37 Submitted on 3rd, some issues, resubmitted 6th.
35:52 High-tech talks, networking, and exploring Savannah.
38:39 Discussing boat transportation as part of long-term goal.
40:38 Collaboration can lead to innovative infrastructure solutions.
44:10 Discussing relevance of Wi-Fi and security measures.
About the guests :
James Warne
Jay's work in research has affirmed his commitment to technology, security, and computation. His time on and leading high-performing teams codified his desire to enable and support his scientists and engineers. Jay constantly seeks ways to contribute to his field; one may find him testing his theories, reading and sharing papers, problem-solving with industry, arming investors with technical knowledge, coordinating RSTCON, developing instructive/ research presentations, mentoring new industry hopefuls, advising the Cornell Cyber Club, or outdoors.
Matthew Miller
Matthew spent eight years in the United States Navy and Special Operations as a CNO Operator. After the military, he shifted his career toward security research and software engineering. Recently, Matthew co-founded ResetCon to address growing cybersecurity concerns in critical infrastructure. He's passionate about his family, work, and about giving back to the community
Know more about Reset Conference - https://rstcon.org/
Attend ResetCon this year!
Visit https://rstcon.org/2024/ and use the code PrOTect to receive a 10% discount on your tickets.
Connect With Aaron Crow:
Learn more about PrOTect IT All:
To be a guest or suggest a guest/episode, please email us at [email protected]
Aaron Crow (0:2.434): Awesome. Welcome to the show. Another show of a protected all podcasts. This is a, special episode. I usually do these one -on -one, but today I have a Matt and Jay with us with me today. We're going to talk about a conference that you guys started, but let's just kick it off. Matt, why don't you tell us who you are a little bit about your background and then Jay, we'll kick it over to you to kind of do the same. And then we'll get into the other fun
Matthew Miller (0:26.438): Sure. Yeah, my name is Matthew Miller. I go by Matt or whatever. I'm a veteran of the United States Navy, spent some time with special operations and did a lot of CNO operations. then when I got out, I switched to be a software developer where I focus on kind of the offensive side of security and also do some vuln research as well. And
Matthew Miller (0:56.420): Yeah, recently started a con, but we'll get into that later.
Aaron Crow (0:59.596): All right, what about you, Jay?
Jay (1:3.244): So I kind of had a different path. I started off with a finance education and realized I didn't like any of that. So I had always played computer games. was 14 year old managing a TeamSpeak server, things like that. So I was like, OK, well, I really liked my computer science classes, the electives I took in college. So I doubled down on all that and ended up doing a little bit of consulting in the risk.
Jay (1:33.300): side of things. So understanding it from the management perspective. I got bored, went to graduate school because I wanted to do research, did defensive operations for a little while, touched a little bit of offensive tooling, and then moved full time into research. for the last five years or so, I've been doing DARPA style, advanced research types of things. And it's just been an absolute blast.
Jay (2:0.798): So that's kind of where I come from and where I've been. And I ran into Miller somewhere along the
Aaron Crow (2:5.944): I was about to say like, so how did, how did you guys meet? What is that story?
Matthew Miller (2:11.162): We were doing contracting for the same customer and I was mostly remote, but my on -sites would travel to the DC area and got to know Jay. He worked for an adjacent team. yeah, I guess competence met competence.
Jay (2:30.044): I remember we would take breaks and go for like a walk around the building, because that's what you do. So we were taking a break one day and we're walking around the building. And I think the words, did we just become best friends, were uttered. And that was the hard confirm on something that was already brewing.
Aaron Crow (2:54.870): Right. Yeah, the step brothers. Did we just become best friends? Yeah, but. So so let's why don't we kick it off next? Just kind of what is reset con and kind of walk through high level? What's the focus of
Jay (3:1.751): I think we just became best friends.
Jay (3:16.012): So ResetCon at a high level is, Matt and I were a little disappointed. We had been going to conferences our entire careers, more or less. And we had noticed a distinct change in the focus of the conferences away from the deep research and the stuff that you would hear at an Infiltrate back in the day or early DEF CON, the Sky
Jay (3:42.856): And we would go to these conferences. And there would always be a few really good talks. But a lot of them were defensive -oriented or they were management -oriented. And they didn't have those really good, interesting, wow, that's so cool kind of through lines. And we were like, want our conference, or we want a conference to deliver that to people so that people have this opportunity to sort of feel that wonder that we felt. And simultaneously,
Jay (4:10.816): We're existing at a point in time in history where there's a lot of focus being given on operational technology, ICS, but not necessarily a lot of defensive focus. So we see things happening across East Asia, things in the Ukraine area, where there are a lot
Jay (4:38.206): attacks and a lot of things happening that aren't necessarily tailored towards defense, but are instead kind of pointed at the populace. You you're preventing people from getting what they need. And that is a tactic to like wear down an opposing force. And we're seeing that be used. And I don't know, I can't speak for Matt, but personally, like the global economy and protecting that for whatever that may mean, you know, and the people who are not directly involved.
Jay (5:8.702): seems important. So we're trying to bring both the interest in the research and novel exploitation and then a little bit of focus in this area that's a little under, it doesn't quite get as many eyes as it needs and we're trying to do that at the same
Aaron Crow (5:23.564): Yeah, yeah, that makes sense. It's an interesting space. mean, right now, especially this week, right? We're in the middle of a, in the United States, we're in middle of a presidential election. We just had an assassination attempt. We had this big crowd strike issue that came across, which wasn't exactly a cyber issue, but still it's an impact in operational technology. And it just really showcases, you know, it lifts the curtain for the general populace. It's incredible. was at a fam...
Aaron Crow (5:52.222): a couple of family functions in the last couple of days. And I've been cybersecurity and a technology nerd my entire life, basically. But now all of these normies, people that are not in this space, right, are coming up to me and asking me all these questions and think it's just like they're, my mother -in -law is listening to my podcast. Like it's really weird that my mother -in -law wants to listen to a cybersecurity focused podcast.
Aaron Crow (6:17.822): and is interested in the things because it's getting thrown in everybody's faces. So all this stuff is there and it's more needed now than ever. It's maybe not more needed. It's probably always been needed. It's just more people understand how needed it is and then it's getting more and more attacked. So what I heard you say then is this ResetCon is really focused on deep dive into the technical aspects of how, when, why, all those things around
Aaron Crow (6:46.912): O .T. I .C .S. Critical infrastructure, critical manufacturing, et cetera. Is that right?
Jay (6:52.044): Exactly. And also, you know, as you mentioned, a lot of these attacks are happening. There's a lot of like, there's a lot of, there's a big intersection between the IT and the cybersecurity space in the OT space, especially with like the manufacturing 4 .0 push, like the smart manufacturing and, you know, smart devices, autonomous vehicles, all these different things that are now merging the two where one was previously analog and totally separate. Now you
Jay (7:21.344): this very tight meshing where previously an IT system might go down. The OT can still run because Jerry, the intern's pulling the lever. But now if that system goes down, like you mentioned with CrowdStrike, well, there's a lot of stuff that governs the OT now sitting in that IT space. So it isn't just the ICS material, but also those sensors and architectures that are shared across
Aaron Crow (7:39.202): Right.
Matthew Miller (7:50.096): Yeah, something I'll add to something Jay said a while ago was in the military, we call this irregular warfare or multi -domain warfare where you leverage, you take advantage of weaknesses in infrastructure or civilian populace in order to soften the target before a conventional invasion. I think we all have seen recent examples of that in many areas, but it's kind of funny.
Matthew Miller (8:17.831): We call it irregular warfare, but it's becoming more more regular. So I think this style of conflict is definitely going to become mainstay.
Aaron Crow (8:30.414): Yeah, 100%. I mean, I see a lot of arguments, even with this CrowdStrike or any number of others. Was this a cyber attack? this an OT incident? And a lot of the vendors are having those conversations or either side of the coin. But what difference does it make? At the end of the day, all that matters is this stuff went down. Was it a bad actor? Maybe, maybe not. But at the end of the day, the output, the results was the same.
Aaron Crow (9:1.560): planes weren't flying, airports were closed down, people were stranded, all of those things happened. Like how it happened, was it a nation state attack or was it just an intern that did something stupid? Who cares? I mean, we care, we need to do a root cause on it eventually, but right now I need to get it back up and running.
Matthew Miller (9:22.032): My family asked a bunch of the same questions about the Baltimore, the Francis Scott Key Bridge and like the speculation on Twitter, the speculation from my family. mean, speculation everywhere was, you know, it was a perfect storm of cyber attack and wouldn't it be funny? Maybe. I mean, maybe it was just negligence and the fact that the company wasn't taking care of their equipment and then the perfect series of events happened.
Jay (9:23.308): actually.
Aaron Crow (9:27.448): Yeah. Yep.
Matthew Miller (9:51.316): But yeah to your point. Yeah, exactly to your point. It's the same. It's the same effect
Aaron Crow (9:51.404): Occam's razor.
Jay (9:56.864): So I mentioned that I did defensive stuff for a little while and I had a mentor who I'm not in as good of touch with as I should be. He did a phenomenal job. And one thing that he said early on when I was still in the defense side of things was, know, attribution is the most dangerous activity.
Jay (10:22.046): Right? Because we have all these things to deal with, but everyone wants to think about who done it and why. And you absolutely get to that at some point, you know, but right now we have a system that we don't know the status of. We need to be focused on this. We need to get it back, cleaned up, up and running, because what is our deliverable at the end of the day? Our deliverable is systems that people can use. And if you're a large, you know, logistics supplier, know, major shipping, for instance.
Jay (10:51.904): The last thing you want is to have people spending all this time speculating and pay into that instead of just solving the problem as fast as you
Aaron Crow (11:0.120): Yeah. Yeah. And, and there's all these talking heads. It's the same thing you see with everything, right? Is, is who's to blame? What was the cause? Again, at the end of the day, these companies only care about getting their thing, like doing, like they want to fly. They want to build their widgets. They want to produce electricity at the end of the day. That's the goal, right? We can figure out the RCA later. So this is awesome. So how do you guys go from walking around the building to having these conversations, to becoming best friends,
Aaron Crow (11:29.590): all of a sudden, let's launch a con and what was that process?
Matthew Miller (11:34.606): I think the big one was kind of like you said earlier, it was a couple of buddies over beers or many beers. But eventually we kind of just got to the point where we realized that, know, as we like to call it critical infrastructure, how is it that critical infrastructure is never represented by more than a village at a conference? And not to say that the village is not any good. It's great. Most of the villages are great.
Matthew Miller (12:3.898): But it's kind of time we started focusing an entire conference on these kind of core issues of addressing the attack surface of an entire nation. And that's really what it came down to was just a couple of buddies having beers, making a great idea, and then having the ability to just say, OK, so how do we do this? And we just started the ball rolling. And it's been a nightmare ever since.
Jay (12:35.105): It really has been. I think Matt phrased it really well. There was kind of this moment of like either both the technical focus, both the impact focus. We had aired these not grievances, but these wants, right? The things that we wanted. We want to see this more in conferences. This really should be focused on a little bit more. We kept having these wants and we kept seeing the industry.
Jay (13:3.114): Basically every year when we had the same conversation, moving a little bit further from where we wanted it to start moving. I get, we, you know, we kind of looked at each other across our beers and we're like, well, well, shoot. I guess, I guess it's us then, right? And we, kind of called our own number and you know, we've regretted it ever since.
Aaron Crow (13:22.668): Nobody's coming to save you, right? You got to do it yourself, right? If you want it done, it's got to get done. You know, it's the same, same, same adage that we see, like, you know, we've got to step up and do something. So obviously, as you know, I'm a big part of ICS Village, I speak at conferences with them. I volunteer all the time. You know, I do podcast episodes with them. Like there's all sorts. And why do I have a podcast? Why do I do this myself? Like my job is full enough, but doing this is for that exact reason, right? I want to continue
Aaron Crow (13:52.248): point that conversation back and do more, right? Because we need more focus. ICS Village is awesome to Matt's point earlier, but a lot of times they're in the corner of a conference that is not focused on them, right? You have to come search that out. And it's a small section in this one bigger, larger thing, which is not a bad thing. Again, I'm not, I love, I'm going to Black Hat, I'm going to DEF CON, like I'm at RSA and S4 and all these different conferences are great. No shade on them whatsoever.
Aaron Crow (14:20.408): that's not their focus. Like you go to Black Hat, what is Black Hat? We know Black Hat is commercial, know, see whatever the newest thing is and get a bunch of swag and be in Vegas and drink a lot, right? Parties, vendors, support, all that kind of stuff. Defcon, the anti -conference, again, started out being very technical. It's so large now. I don't know how many people are even technical there. Like some of them are just, they want to go because they want to hang out, which is fine too. Like I love Defcon. I'll be a Defcon this year, but, but
Aaron Crow (14:50.038): I love the idea of a hyper -focused, technical -focused ICS industry because it's such a small niche, but it is so, by name, critical that we understand and focus on it because I want my lights to work. I want my water to turn on. I want to be able to get on an airplane and know it's safe. I want to be able to go to the airport and get on my plane.
Aaron Crow (15:16.844): and not have blue screens of death everywhere that we see, right? Like all of these things are super critical. And we know from an insider perspective, there's a single domino that can fall and can have this giant spread, again, CrowdStrike, not to beat up on CrowdStrike, but little things make big impacts in these environments. The consequences are huge, which is why I love the fact that this is dedicated and focused on critical infrastructure.
Jay (15:44.406): Well, there are kind of two things that I really like about our approach, just kind of to repeat kind of what you said. by giving people, you mentioned that you guys, ICS Village, you're at DEF CON, Black Hat, RSA, and that's super important because without your presence, nobody could see it. There are a lot of people who would never see it and say, wait, what? Like that's actually really cool. You get that first checkpoint. You get that first interest.
Jay (16:12.416): But now that we also have something that's a little bit more dedicated and a little bit more focused, the people who are coming just to hang out, come on, come show up. Because not only will you see, you will get to see what you saw at ICS Village at DEF CON, you will also get to see it drilled down at its depths. Come see how deep does the well go. Come see. And literally, come see.
Aaron Crow (16:19.747): Yep.
Aaron Crow (16:29.774): All right. Yep.
Jay (16:40.300): Whether it's your area of focus, fantastic, contribute, or you're just there to learn, it gives people that sort of that platform to really just be focused on it. And I think that's what we're most excited
Aaron Crow (16:52.312): No, I love
Aaron Crow (16:54.894): That's, it's so needed. And to your point, is there aren't enough of people focused on it in general. We hear all the time where there's a skills gap, there's a need for resources that have the skill. You look at LinkedIn, you looked at job requests and people are asking for somebody that's got the unicorn, somebody that's got 20 years experience in something that hasn't even been around that long. Like I've been doing critical infrastructure, cybersecurity stuff way longer than it's actually been called that.
Aaron Crow (17:25.431): but there aren't many people that have, right? And I'm not tooting my own horn. I'm just actually saying why there's gray in my beard, right? it's because exactly, but we need more folks. need new, new blood. need to understand. And the more that we, what I love about critical infrastructure, one of the main things I love it and, coming from a power utility and critical manufacturing, the way I generate electricity is not proprietary, right? You know, from company a to company
Aaron Crow (17:52.184): We do it the same. not, it's not the secret recipe for Coke. There's no secret here, right? We can share. So there's a lot of sharing that goes on in that industry and a lot of these critical infrastructures because the way I do my water is not this, that's not how they make their money. Their IP is not around how I generate or how I create this thing. It's more just around brand and I need to go buy and provide, it's more the coverage than it is the IP
Aaron Crow (18:19.648): What that allows us to do is actually share and have some conversations where I may not be able to do that between Pepsi and Coke. But even those industries are able to say, here's how I'm protecting my manufacturing without releasing the secret sauce to my recipe. How I create an assembly line, we can share that stuff because there's not as much and how do I make sure that my brand is okay? And those are the bigger conversations that we can have and deep dive into the technology side of things because
Aaron Crow (18:49.762): How do we solve like being able to look at the crowd strike incident? How do we solve that in the future? How do we make sure that that doesn't happen again? It wasn't a cyber issue. It wasn't a nation state attack, but to Matt's point earlier, it could have been. So how do we make sure that isn't used in the future? Cause now our adversaries just saw, wow. One, one product just took down all of these critical infrastructures. Hmm. Maybe we should use that as an idea on how we could use that in the
Matthew Miller (19:16.282): Yeah, that's been a huge part of like any supply chain attack. You get, you swim far enough upstream and all of a sudden the trickle down effect is massive.
Aaron Crow (19:26.861): Yeah, absolutely.
Jay (19:29.448): One of the things that we really like about the ICS space and the OT space, and one of the reasons I personally am so excited about the conference, you mentioned finding the solutions and sharing the solutions. There are a lot of research groups in academia and universities that either know or may not know that some of the work they're doing is critically relevant.
Jay (19:58.080): there's kind of a bit of a disconnect at the moment between like pure, like the research that I was doing in, in DARPA land and like applicability in the field, right? So there's always kind of been a disconnect there, but if we look just in the last year or so of, research, we can see that the solutions and some of the sharing, can already go on. There are, there are groups out there that are working
Jay (20:29.045): you know, I, ICS systems that really should probably know about like voltage fault injection, right? And what can it do at it's like, we, in fact, we're, we're fortunate to have Colin O 'Flynn as, one of our speakers, you know, kind of one of the granddaddies, not granddaddies, not old, but you know, one of the fathers of this area. And, know, he's got new AE.
Jay (20:54.336): and the chip shouter, chip whisperer, all that great stuff that he puts out. And he loves his hardware, like, you know, the oops, I glitched it again paper that came out. Yeah, it's that came out and they're performing multiple fault injections on a single trigger. You know, that's something that might not be relevant to everybody, but on those.
Jay (21:20.246): people who are using like arm trust zone chips. Well, arm's pretty prevalent. So maybe, you know, if those researchers got to sit down with, I don't know, let's pick a firm, right? Like some large manufacturer who just has a bunch of arm. Well, what are you manufacturing? Well, we're pressing like airplane components. That's a big deal. Like maybe you should be aware, you know,
Jay (21:50.068): whether it ends up funding it or we talked about, I talked about airplane components. So you have CAN bus, which is how vehicles communicate, know, who knows that better than Aaron Crowe? No one probably. So, you know, they've got this research coming out that's focused on CAN bus both on like using like the inner frame spaces
Aaron Crow (21:55.406): Mm -hmm. Yep.
Jay (22:13.836): They create a signature and time trapping of injected attacks and replay attacks with 100 % success rate. I think that was ZB scan. then Redos or Redus that came out. I'm pretty sure that's like, they keep track of the transmit error counters and they kind of emulate it. And they use that to, they can inject bits into things that they think are wrong, create a faulty message, put the attacker.
Jay (22:43.114): device into an error state, and then they can scan through and say, okay, here is the device that we think is the problem, talking about attribution, right? And how hard that can be in the ICS space. So this is stuff that came out in the last like, a year, I guess they were pre -publication like a year ago. There are a lot of groups that could probably use that. Fund this lab, go find these guys, email them, talk to them. They did great work.
Jay (23:11.806): and they can contribute immediately right now, maybe not to your in production systems, but to getting this forward and then getting those solutions out. It doesn't have to be a decade. It can be a couple of years.
Aaron Crow (23:24.386): Yeah. Well, you know, I just spent time at, yeah, yeah. And I just spent time at Idaho national labs and, and, and they have their, you know, cyber informed engineering. And that that's really the idea behind that, right? Is, is I need to be thinking about these things and what are my risks and where am I, where are my vulnerabilities? And it's not always a software vulnerability, right? It's all, you know, it's not software building materials. Sometimes it's, it's a lot of different things and there's a lot of perspectives there. We do really well at designing these systems and critical infrastructure to be reliable.
Matthew Miller (23:26.214): And that's why we wanted this conference.
Aaron Crow (23:53.346): to be available, but we haven't been designing them with the cyber and technology aspect as part of the equation. We kind of bolt it on after the fact, we try to figure it out. And even when we do that, we're not bringing in the best of the best. We're like, we're making your plumber figure out the electrical, right? Yeah, he's a smart guy, can probably figure it out, but that's not what he went to school with. That's not his expertise. Can he do it? He's a super smart guy, he's done it before. Yeah, he probably
Aaron Crow (24:20.152): But that's not his job. Like bring in the electrician, bring in the specialist, the HVAC guy. Can your electrician wire your HVAC? Yes. But is he as good as the HVAC guy that that's all he does and that's all he's ever done and he's seen all these different examples and the do's and don'ts? Of course not. Like that's the specialty side of it. And we need to make sure that all those people are at the table.
Matthew Miller (24:44.026): Yeah, that was one of the goals with Resetcon was to get all these people together, was to get money from vendors together with the brains behind some of these research projects together with the offensive security minded people and just brainstorm solutions to these problems. Because you're not going to do it anywhere else unless you have a shop that's got all of those components in the mixing bowl. we have to do it at a conference. We have to do it where...
Matthew Miller (25:13.082): you know, everybody's willing to talk and discuss and yeah, so we started ResetCon.
Aaron Crow (25:19.266): So who's your ideal audience? Like who do you want to show up? Obviously from a vendor perspective, from a speaker, you've already talked about some of the speakers there, but just normal audience. who are those ideal folks and what goal do you want to come out of this from them, from an individual as an attendee, but also from a larger community of, this reset con thing, we went away and what can we say we want to get? Like in five years, at year five of this thing, what is a good outcome that you guys are hoping to get
Jay (25:50.144): We have a couple different audiences and I think that's why this conference is particularly ponderous. We have the exploit, like the exploiters, like the on keyboard operators who could benefit from understanding like, there's this whole space to play in. And your offensive people, your red teamers, those guys. We also have the defensive people who are in the ICS space, who are dedicated security people.
Jay (26:19.166): Of course, those are our security audiences, but it's more than that. Because if you look and you go into actual industry, you have the people who are managing, managing these whole like an oil platform, right? You have the guys who run that, not necessarily day to day, but the decision makers who can sit down and look at the problems at hand and say, hey, we do lidar sensing. There is an attack out.
Jay (26:46.796): that allows called, you can't see me that yeah, that explicitly uses lasers to prevent LIDAR from reflecting back and you can target it and it's like 92 .7 % effective at removing 90 % of like the LIDAR pillars. That's a lot, that's a problem. So the guy, the cyber people, they can understand and know like, oh, we can use this to make the car crash,
Jay (27:15.616): But the guy making the car fundamentally has to be aware that this is a possibility. And now that he's aware that it's a possibility, he can go focus on that. So we have also like executive level and like technology decision makers from industry. And those are two very different groups. They're very hard to get together because they don't like the same things. And we're finding that now, you
Aaron Crow (27:43.694): They are different, but they are at the end of the day. And it's one of the things I say a lot is, we're all we're on the same team, right? You know, we have different roles and we have different specialties, but we all want to make sure again, I said a minute ago, I want to make sure when I turn my light switch on that, that it works right. And most people don't understand the complexity it takes to generate, transmit and distribute electricity or water or gas or our,
Aaron Crow (28:10.154): electric system, like all of these things, they're just so difficult and complex. Most people just take it for granted. just, pay their light bill, they turn their light on and it just works. Right. And really understanding that, that we're, we're, on the same team. have the same goal. IT and OT, we're not on different sides. You know, executives and, and the people hands on keyboard. We, have the same goals,
Aaron Crow (28:33.294): You know, everybody wants to have a safe environment that their kids can go to school, that we can, you know, invest in real estate or invest in stocks or buy whatever we want and do our job and retire and, you go on vacation and all these types of things. And all those things are dependent upon this foundation of critical infrastructure and everything that it works and all the sub components. And we're not asking everyone to understand all of that stuff. You know, you don't need your offensive linemen to necessarily be able to play, you
Aaron Crow (29:3.126): safety. But they at least need to understand a little bit because we are on the same team. Like we need to have a general awareness of certain things, especially if it's your job to do whatever that task is to defend against whatever or to be offensive on it, depending on what your, what your role
Aaron Crow (29:24.214): When did y 'all, when did y 'all start this thing? Like how, how, how long ago did you start kicking this off and turn this into something that's tangible?
Matthew Miller (29:32.422): think we founded the company that holds the conference 18 months ago. Is that about right? A year ago. Yeah, I would say.
Aaron Crow (29:39.536): wow. Wow. So one year, one year from foundation to the conferences in, you know, a little over a month, month and a half, two months.
Jay (29:40.502): No, a year ago, even less.
Matthew Miller (29:48.941): months.
Matthew Miller (29:51.770): Yep.
Jay (29:51.968): Yeah, so we had been thinking about it before, but our official incorporation date is this month. Like this is our year anniversary.
Matthew Miller (30:1.650): Yeah, the ball has been rolling for about 18 months like officially though. We were constructing a plan and figuring out names and getting a logo built and buying domains about 18 months ago. But yeah, incorporation is yet not today, but this month is certainly kind of a monument, I guess.
Aaron Crow (30:1.966): That's epic.
Jay (30:26.060): I think it was actually the 6th of July. We had submitted it on the 3rd, but there were like some issues with our submitters. So I just had to do it myself a few days later. One of the things, I'd also want to shout out, I don't know how familiar you are with ShmooCon and the Shmoo group, but shout out Heidi Potter. She got on the phone with us at the outset and we presented her with our timeline and our plans.
Aaron Crow (30:42.830): Mm -hmm. Mm -hmm.
Jay (30:54.356): And she kind of validated and helped us orient and said like, well, move this one up here, change this around. You need at least this much time for, and that kind of guidance, as much as we either succeeded or failed to adhere to it, was very helpful. So, you know, shout out the shmoo group.
Aaron Crow (31:11.832): That's excellent. I've experienced a lot of, again, going back to that whole we're all one team. We're not a competition. Like having more focused and different is not bad, right? There's a lot of conferences out there, but there's a reason they stood up and there's a reason their purpose, at least when they started, right? So I'm excited about this. I'm excited to have another opportunity to speak about ICS. There is so few that really have any significant focus on critical infrastructure.
Aaron Crow (31:41.142): specifically around the technology side of things. All of them will have a talk track maybe, or maybe they've got a few speakers there, ICS Village will be there, other villages will be there, but actually having a focus on it, S4 obviously focuses on critical infrastructure, but again, even that, it's less on the technical side. mean, they do definitely have talks. I love S4, it's one of my favorite conferences, but still having one that's even more focused down in the weeds is not a bad
Aaron Crow (32:11.062): And it's good that we have diversity of thought. We have diversity of attendees and not everybody can go to us for, for many reasons, right? Miami is expensive and all the different things, or I couldn't go this month, right? So having another place that I can go and be able to expand and deeper dive with different people and having the same conversation around different people, I'll have a different outcome of my opinion or maybe even outcome of thought and results, which is incredibly powerful.
Jay (32:42.870): personally really excited not just about having the focus on ICS, but also go in the other direction. One thing that I think gets lost a lot. I was at Hack the Capital. got to, you I was fortunate to be on Derek Harp's podcast. You know, it was fun to talk to him and you know, we have a lot. There is some focus in the ICS space, but some of what's missed isn't just the lack of focus directly in the ICS space. It's the cross -domain applicability.
Jay (33:13.054): So consider actually one of our other speakers, Daniel Ginkin, know, let me ring the bell. He worked on something last year that was focused on off -path USB injection attacks. Well, as USB, that's just a pretty general computer. We use it everywhere. But you know where it gets used a lot? AirGap systems. So we have, you know, he put together
Jay (33:39.564): with, you know, not alone, obviously, he and like his co -authors put together an attack that allows command injection, keystroke injection, and like file rewriting. You plug in that USB, you think you know what's on the files, the configuration that you're uploading into your system, and it writes something totally different. It's issued commands, it's been completely hijacked. And if you're focused entirely
Jay (34:7.424): purely on operational technology, you might not see that hole in the USB driver, but we have the opportunity as just generalists and cyber focused people to say, here's the hole in the USB driver, look where your USB driver is. So I think going the other direction also has a real broadening effect that I think we can see or that I really hope to see come out of
Aaron Crow (34:33.390): No, that's huge, right? And I've seen this firsthand in nuclear power plants, for instance, where completely air gapped, no network connection whatsoever, and a vendor brings in a drive that's been scanned and all of the things and everything looked fine on it, and it gets brought in and it causes an issue. And this was 2010. So this is not new. I mean, you look at Stuxnet air gap system, right? That whole environment, and that's where we get
Aaron Crow (35:2.604): We have this false sense of security because of the way that we architect or these systems are and they're not necessarily there. So what is the day, what can you expect is when you're showing up? what are the talks, are the hands -on, what are the, kind of walk us through that expectation of when I'm showing up to this place as whatever my role may be in my corporate world.
Matthew Miller (35:29.412): You want me to take that? Yeah. I mean, so like any, any conference you're going to, you're to walk in and get registered. You're going to trade in your, your barcode or your ticket for a, for a badge. and then, we'll have, we'll have some opening remarks, some really high technical talks. a couple of villages have committed to coming. and, it's really just going to be focused, like Jay mentioned on, some really specific research.
Aaron Crow (35:30.070): Matt, you want to give us a?
Matthew Miller (35:59.002): There's going to be a floor for vendors to advertise for themselves for being at the conference, maybe do some recruiting. And there will be spaces for people to have conversations, get to know each other, socialize. So outside of the conference floor, there's the rest of Savannah to explore, which is a great city.
Matthew Miller (36:28.528): plenty of good food, good drinks, good sightseeing, lots of American history. And there's plenty to do there. yeah, I mean, at the conference, it's gonna be structured a lot like most other conferences. With talks, we have a CTF that we're putting together that's focusing on a lot of industrial control system aspects. We've got some emulated PLCs, some DNP3,
Matthew Miller (36:58.242): stuff for people to attack. There's going to be no shortage of activities and it's a five -year goal of mine to have something really special on the floor. I don't know if it's going to be an aircraft engine or maybe a mock -up of a maritime control system network. It would be really cool to have like a miniature reactor or
Aaron Crow (37:21.058): Mm
Matthew Miller (37:25.656): a mock -up of a power plant available on the floor and just, you know, let people go at it. Kind of like the car hacking village started. They put like the dash of a car on the floor and said, go nuts. Yeah, that's kind of my five -year goal. I'm hoping we can get there eventually. Savannah is pretty uniquely positioned. There's the Port of Savannah nearby. It would be really awesome to get like a busload of hackers.
Aaron Crow (37:38.348): Have fun.
Matthew Miller (37:54.482): onto a ship and you can kind of see where that might go. But no, mean, there's gonna be a lot of fun to be had, a lot of learning to be had, a lot of networking to be had, and hopefully get researchers, vendors, and hackers thinking along the same lines. And like Jay mentioned earlier, maybe we can get some of this really cool research funded and implemented before it becomes a problem.
Aaron Crow (38:23.554): Yeah, I love that. Anything to add,
Jay (38:27.896): You know, the only thing I wanted to add was when we were out there having having our beers and Getting the conference like kind of kind of walking the grounds. We were gonna be Matt had that idea He was like, well, what if what if we just like got a boat and like everybody could get on the boat? And I was like, hey, how would that work? And he did, you know, he described the bus and I was like, well, you
Jay (38:52.332): I guess like if they wanted, they could just have sleeping pads and a sleeping bag and they could just sit in there and just go nuts. So long as like, I don't know, insert shipping company name here was okay with, you know, having something import and then reflashing their systems afterwards, you know, that would be quite the experience. I think that would be an amazing five, 10 year goal. I think my ultimate goal is as Matt said, which is to see some of this research, to see some of these labs.
Jay (39:22.294): connect with industry and actually not just for the sake of getting funding, but to actually deliver
Matthew Miller (39:27.652): Yeah. Imagine a track on your CTF being, you know, steal the boat. Not really. We would have probably like exemplar systems that are just physically located on the boat. but, you know, being immersed in that environment and being told that you can steal the boat would be incredible.
Aaron Crow (39:33.880): Right.
Aaron Crow (39:49.474): Yeah. Yeah. You know, it's, it brings up something that is near and dear to my heart. And I've built a lot of very large labs for power utilities and others and their purpose built, right? So they have control systems, they've got turbo controls and balance a plan and, and, know, the, transmission substation environments, all that kind of stuff, but there there's special built for those, whatever they're using them for. Imagine if that was available to this environment, right? So a bunch of people are coming together, not to just break
Aaron Crow (40:18.316): because it's fun, but also just find things that nobody else thought of, to find fixes, to find solutions, to find new architectures and capabilities. When we put our minds together, it's amazing what we can come up with, but you can't go buy, I don't have the money to go buy a control system or recreate a power plant in my lab. Like I've got a lab over there that I'll actually be bringing.
Aaron Crow (40:41.976): But it's small and it's a small use case. But imagine if I had all of the access to an entire environment and those labs exist. Like again, I've built two or three myself and that's in public companies, not counting the ones that are in these lab environments like Idaho National Labs and NREL and MXD up in Chicago for manufacturing. A lot of those labs have a lot of these spaces, but they don't necessarily have people that are coming in to do this type of thing.
Aaron Crow (41:11.078): I love the idea. I think more insight and visibility into these environments where unfortunately up until now critical infrastructure has kind of been this security by obscurity. I don't know what's going on. That's my security. Don't look behind here. Everything's good. Just trust me. And I think now we're in a space where we know that's not enough and it's not going to help us and we need to get some young blood. We need to get some hackers in here.
Aaron Crow (41:38.798): because we want them to break stuff, but because by them breaking something, it can help us fix something before that bad thing, before the bus hit or the boat hits the bridge, before all the power plants go down or that type of attack happens in a bad thing that we don't know how to recover
Matthew Miller (41:57.805): Absolutely.
Aaron Crow (41:58.038): I love it gentlemen. Alright, so how give us the call to action? How do they? How do people buy tickets? How do they? If I'm a sponsor, how do I reach out to like give us all all the all that info?
Matthew Miller (42:9.690): Yeah, resetcon, R -S -T -C -O -N dot org. We've got a sponsorship page if you want to sponsor us. All the tiers and information about how to submit to be a sponsor is on that page. Call for Papers is open at the CFP page. Again, everything's listed there. We've got a lot of interesting categories and interesting calls for papers.
Matthew Miller (42:40.013): And then the 2024 page is kind of where we're putting all of the All of our sponsors and kind of our headline speakers And then there's a couple different places to buy tickets on the 2024 page on the tickets page You can reach out to us directly for group rates if There's a big group that wants to come and you want a group rate
Matthew Miller (43:5.382): And then also there's student pricing available. yeah, students just get a flat 50 % off. So it's $100 for a student to show up. Yeah.
Jay (43:20.136): our CFP, it is still open. we, we have some, some really good talks lined up already, but we, I want to impress upon people that the thing that they're working on at home might be more applicable than they think. You know, I referred to the USB thing, talked about like LIDAR, if automated patching in main memory, you know, maybe you're doing something.
Jay (43:47.926): that's on a RISC -V system, those are everywhere. There's a lot of RTOS stuff. There's a lot of embedded stuff that is now in all of these industries that wasn't necessarily before. So don't be gun shy just because you're like, well, you know, I did this thing, but it's really just focused on like Wi -Fi or like this Zigbee or a TLS connection, you know.
Jay (44:15.860): It's probably relevant. You'd be surprised how much of the, how much overlap there is. And every time I sit down with like a student or a professor, I've had some opportunities recently to like talk with industrial and like systems engineering groups. And sometimes they're like, yeah, well, we're working on optimization. Right. That's relevant to us. And like, well, how is optimization relevant to you guys? I say,
Jay (44:44.064): Daniel Groose, another one of our speakers, he's bringing suit, which is a, he and Jonas Ufinger are bringing and discussing suit, which is like, they did a whole attack based on undervolting, right? We talked about fault injection before, undervolting, you know, and they've realized while they were undervolting that a lot of these things run more efficiently or they run just as efficient. They run just as correctly at lower voltages and
Jay (45:12.830): as a manufacturer or as an embedded system user can actually undervolt things to a certain threshold, make sure you test it first and save on your power bill by like double digit percents. So optimization, it might not seem relevant. It is relevant. So please, even if it's just an abstract, our submission is not that ponderous, just send it out there. It could end up being big. Go for
Aaron Crow (45:20.718): Sure. All
Aaron Crow (45:35.586): Yeah.
Matthew Miller (45:37.850): The other thing I'll mention about the CFP is there are timelines on there, but us being a new conference, still trying to figure out schedules and all that stuff. Even if you have something that's a little bit late, just get us an abstract and we can, we can help work with you on getting the rest of the research done and, and figuring it out. Our timeline, at least for the CFP is pretty soft. So even if it's even if it's, you know, a week late,
Matthew Miller (46:7.274): We'd still love to hear from you. I think as it stands now, the CFP is due to close on August 1st. We plan to leave the page up there. So again, if it's a couple weeks, a week or two, three weeks late, still shoot us a spot or an email and we'll see what we can
Jay (46:29.332): Yeah, what's the worst that can happen? Well, it'll take time to review everything. So while I'm reviewing everything, you might as well slide one in the stack. It's fine.
Aaron Crow (46:37.506): All right, exactly. That's awesome. Well, I'll definitely make sure all the details are in the show notes, folks. So definitely look there for all the details around those links. Definitely get in your CFP. It's a great opportunity for your career, for networking, presenting, even if you're uncomfortable. I highly recommend it. Doing podcasts and speaking.
Aaron Crow (47:3.320): There's a soft skill that goes to that, that is important. It doesn't matter how smart you are. If you can't convince others and explain it to others, then it doesn't matter. And part of that is presenting abstracts, presenting papers, getting up and talking to a group of your peers. We've all been there, right? Nobody's expecting it to be perfect. It doesn't have to be polished. It's better to get the content out there and trip and say, or be sweaty and not know what to do with your hands and all that kind of stuff. Who cares? Get out there. Like take the risk.
Aaron Crow (47:32.768): greatly impact your career, but beyond that, it can greatly impact this whole critical infrastructure thing. The knowledge that you guys have is what matters. And if it's in your head and you can't get it out there, then it's not helping. We need it out there so that we can do something about it and we can get it. You you have a knowledge and then you tell it to Jay and then me, Jay and Matt, and we're all sitting there like, wow, now we can do this other thing that none of us have thought of because now that we have this new information. So it's super important and powerful to get that knowledge
Aaron Crow (48:4.248): Well, thank you, gentlemen. I appreciate it. I'm looking forward. I'm definitely going to be there. I'm actually going to be representing ICS Village. I'll be bringing this. It's actually in a little bit of construction right now, but the case I have behind me. definitely come out. It's got PLC and some secure mode access and some fun stuff that people can actually put hands on. And we'll have a lot of information around ICS Village if people want to volunteer, all that kind of stuff. So definitely excited to be there. And obviously,
Aaron Crow (48:33.400): be at the conference and hear the other speaking and all that kind of stuff. So definitely come out, sign up and get there and it's gonna be a lot of
Jay (48:41.558): We'll make sure you're not in the corner of this
Aaron Crow (48:42.754): There we go. Thank you, gentlemen.
Matthew Miller (48:45.946): Yeah, see ya.
Jay (48:47.958): Take care.
Transcript lightly edited for readability.
Subscribe to PrOTect IT All and stay ahead of the threats targeting critical infrastructure.