Nozomi Networks released a Wireshark dissector for the TriStation protocol — called the TriStation Protocol Plug-in for Wireshark. The dissector is available as a free download from GitHub, along with a packet capture (PCAP) of network traffic that includes TriStation communications. These tools are intended to give researchers and ICS organizations access to a clear visual dissection of SIS controller communications, helping them identify compromises and cybersecurity risks.
Nozomi Networks’ Research on TRITON Malware
TRITON, also known as Trisis and HatMan, is one of only a few known malware frameworks that have resulted in a direct physical impact on critical infrastructure. In 2017 TRITON was used to attack a Saudi Arabian gas facility, directly interacting with, and remotely controlling, its Safety Instrumented System (SIS). Given the significance of this attack, Nozomi Networks conducted research on the malware to better understand how its multistage injection techniques work.
Nozomi Networks obtained a Triconex SIS controller and successfully communicated with it, including injecting the TRITON malware. Using the network traffic generated, Nozomi Networks was able to analyze the proprietary TriStation protocol used to communicate with Triconex Safety Systems.
Nozomi Networks’ complete analysis of TRITON, along with a live demo of an attack and a second TRITON tool will be shown at an upcoming Black Hat USA presentation with FireEye on August 8, 2018.