
Pre-DEFCON Session: Hacking & Defending OT with AI
Keywords
Summary
203 words
Critical Evaluation
Value of the Information & Strength of the Argument
The session provides valuable insights into the practical application of AI in OT security, demonstrating real-world use cases with tools like Claude and LabShark. The argumentation is solid, grounded in the speaker’s experience and current threat landscape. Holcomb effectively argues that AI is a double-edged sword, and his demonstration of using AI to analyze an HMI and generate attack scenarios is compelling. He also emphasizes the importance of fundamental security practices, which is a pragmatic approach. However, some claims, such as the speed of AI-driven attacks, are presented without detailed evidence, and the session is more of an expert opinion than a rigorous study.
Scientific Rigor, Source Quality, Title Accuracy
The speaker references known incidents like Colonial Pipeline and mentions tools like LabShark and OT Threat Feed, but does not provide formal citations. The title accurately reflects the content. The session is based on the speaker’s expertise and practical demonstrations, which adds credibility, but the lack of formal references and the anecdotal nature of some claims limit the scientific rigor. The audience interaction shows engagement, but no specific comments are provided for analysis.
192 words
Title / Content Match
The title accurately reflects the content, which focuses on using AI for both attacking and defending OT systems.
Quality & Reliability
7/10
The speaker demonstrates practical expertise in OT security, using real tools and examples. Claims are generally supported by references to known incidents and tools, but some assertions lack detailed evidence and rely on anecdotal experience.
Key Moments
Markers derived by PSI from the transcript: the creator did not define chapters.
- Introduction and purpose of the session
- Discussion on the evolution of OT attacks and the role of AI
- Demonstration of using AI to analyze an HMI from LabShark
- AI generating attack scenarios and defensive checklists
- Q&A on network monitoring and latency in OT
- Discussion on SBOMs and importing OT equipment
- Mention of OT Threat Feed and its purpose
- Further Q&A and discussion on AI in OT defense
- Wrap-up and final thoughts
Cited Sources
- LabShark — Mentioned as a free platform for simulating OT environments
- OT Threat Feed — Created by the speaker to track OT security incidents
Concurring Sources
- Dragos — Referenced in the context of the Frosty malware research
Contribution & Novelties
The session provides a practical, hands-on demonstration of using AI to analyze and attack OT environments, which is valuable for defenders. It emphasizes that AI lowers the barrier for attackers and that defenders must adopt similar tools. The speaker’s approach of using AI to generate attack scenarios and then defensive checklists is a novel method for improving OT security posture.
Pour aller plus loin :
- OT Cybersecurity — Provides background on OT and its security challenges.
- Artificial Intelligence in Cybersecurity — Overview of AI applications in cybersecurity.
- NIST SP 800-82 — Guide to Industrial Control System (ICS) Security.
98 words
Radar Profile
The radar profile shows a balanced score across all dimensions, with slightly higher scores in information quantity and reliability, indicating a well-rounded presentation. The technical level is moderate, making it accessible to a broad audience.