Chapter 5: Span Me If You Can
In the previous chapter, we covered the importance of using open source research to build a profile of your client, their company, users, and technology. In this chapter, we are going to dive deeper down the rabbit hole and discuss out-of-band network monitoring. For the last few years, intrusion detection systems (IDS) have been dominating the industrial cybersecurity space.
Companies such as Security Matters (acquired by ForeScout), Indegy (bought by Tenable), Sentryo (bought by Cisco), CyberX (bought by Microsoft), Claroty, Nozomi Networks, SCADAfence, and many others have flourished. Money from venture capital (VC) and investment banking (IB) has been poured into the passive monitoring space to provide awareness about the importance of automation technology, and the impact it has on critical infrastructure has grown as well.
All this technology relies on the network infrastructure to be able to either use a Switch Port Analyzer (SPAN) or Test...