Shodan and ICS systems

Exploring the
Dark Internet
Bill Matonte, Brian Brokling, Chris Hamm
• What is Shodan
o The dark Internet
o The Shodan Story
o How Shodan works
• Industrial Control Systems(ICS) and their
• Countermeasures
The Dark Internet
In order to understand SHODAN, you must
understand where SHODAN operates. That is, the
dark Internet.
• As soon as 2001, there could have been as many
as 100,000,000 hosts that are completely
• Many of these websites can be reached through
"secure gatekeepers", but the security can be very
The Shodan Story
• SHODAN was thought of in 2003 and launched in 2009.
• SHODAN is the brainchild of John Matherly. He named his
creation off of the evil artifical intellegence entity, SHODAN,
from the System Shock series of video games.
• The main idea behind SHODAN is that there are many nodes on
the internet, especially industrial and commercial systems, that
use the internet, but are not normally considered part of it.
• SHODAN changes this paradigm.
Industrial Controls
• Include Many Essential
o Nuclear power plants
o Chemical processing plants
o Energy pipeline monitoring and
• Operate and monitor
systems remotely
• Reduces cost
• Increases security risk
• Designed for function
not security
ICS Continued
• Lack basic security features
o Encryption, Firewalls, Anti-Virus Software
• Systems difficult to update
• Default passwords often unchanged as a “safety
• Before 2011 thought to be “Air-Gapped”
• In 2011 it was revealed that 7500 ICS nodes were
• Only 17% required Passwords
• 20.5% were susceptible to known exploits.
Shodan the Search Engine
• Optimized to search for systems
• Uses Indexed meta-data stored in banners
• Filter information from banners to find vulnerable
• Restrict your devices to only allow packets to be
broadcast inside the internal LAN
• Restrict what IP addresses can access your network
from the internet
• Use VPN to remote access your network
• Change all default device passwords to something
• Surpress or minimize verbose banners
• Run Shodan against yourself
o see if you can find yourself with Shodan
