Snort Rules for Industrial Controls Protocols
-
Hey, this thread pertains to my question, but it's a bit old and that's why I'm starting a new one. (https://forum.pfsense.org/index.php?topic=54545.msg291693#msg291693)
I know there is a package written and maintained somewhere out there to handle IDS in a manufacturing environment with all the various Industrial Controls protocols (modbus, profinet, EtherNet/IP, DeviceNet, etc) handled correctly.
I know it's fairly current because these guys (https://www.securecrossing.com/) are using it with their implementation of PFSense for manufacturing and all they are doing is customizing a DIN rail mounted PC with PFSense and preconfiguring this custom Industrial Controls Protocol addon. I do know that they're not developing it themselves.
So we had a line on how to get the package licensing, but haven't heard back from our contact so I am now trying to track down the package and licensing on my own.
Any help would be appreciated. If I recall correctly, I think Chris and/or Jim were involved in the add-on originally.
Thanks,
Adam -
I thought I would post a quick followup. I did get some additional information and some corrections.
I guess Secure Crossing did originally develop the DPI addon and not Chris/Jim, but then sold it to another individual/company due to some legal issues (not their fault, just big business bullies).
SafeComm is the company that maintains the package now. I am still having a tough time locating a contact that I can get any information from so if anyone here on the boards has any insight or other avenues for information I would still appreciate it.
Thanks,
Adam -
If you wish to discuss this, I suggest a phone call.
+1 512 646 4100 x253