Your IDS Rules For ICS Stink (and how to fix them) @S4Events
Your IDS Rules For ICS Stink (and how to fix them)  @S4Events
Uploaded May 2025 | Updated September 2026, 1 week ago
IDS rules for ICS are no longer bleeding edge. They are common. Unfortunately many are also quite bad. Bad because evasion techniques can bypass a lot of the published rules.

Preprocessors can sometimes 'fix' these failings, and they also can introduce new failings.

Reid helps you evaluate the rules your using, and more importantly provide you with some tips on how to use advanced features to deal with the problems seen regularly in ICS rules for IDS.

Subscribe to Dale’s ICS Security: Friday News & Notes email here:
friday.dale-peterson.com/signup
Check out S4x26. Feb 23 - 26 in Miami South Beach:
s4xevents.com
Your IDS Rules For ICS Stink (and how to fix them)Fireside Chat: Where OPC UA Makes Sense, Standards Adoption, & MoreOT Security Score For ManufacturersAI Analysis of OT Packets For SOC AnalystsWhat To Do 1st, 2nd, 3rd #shortsSAST Tools For Secure PLC ProgrammingAssessing The Cyber Readiness Of A State (Florida)Effectively Using AttributionCreating The OT Security AI Data Model & Data FabricVendor Apologist #shortsRating Deployed OT Firewalls’ EffectivenessClosing The Cyber Physical Risk Capital Gap In Insurance
S4 Events |

Your IDS Rules For ICS Stink (and how to fix them)

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER