Blog | G5 Cyber Security

IEC 104 Protocol Detection Rules

Cisco Talos has released 33 Snort rules which are used to analyze/inspect IEC 60870-5-104 network traffic. These rules will help Industrial Control Systems/Supervisory Control and Data Acquisition (ICS/SCADA) asset owners to allow the identification of both normal and abnormal traffic in their environments. The rules will require both Snort $EXTERNAL_NET and $HOME_NET variables to be correctly configured for some of the rules to be effective. If a network does not have IEC 104 traffic these rules should not be enabled as they will likely result in false positives (FPs)”]

Source: https://blog.talosintelligence.com/2016/12/IEC-104-Protocol-Detection-Rules.html

Exit mobile version