Loading…
OWASP 25th Anniversary Virtual Conference (September)
Tuesday September 22, 2026 10:00am - 10:55am PDT
Operational Technology (OT) environments face a critical paradox: sophisticated attacks like TRITON, CRASHOVERRIDE, and INCONTROLLER routinely target multiple facilities, yet operators remain blind to cross-site attack patterns due to strict privacy regulations, competitive secrecy, and an inherent lack of trust. The current "share after detection" model—where threat intelligence is exchanged only after a breach is confirmed—creates a deadly information asymmetry. Attackers see the entire battlefield, while defenders fight isolated skirmishes.

This talk introduces a cryptographic framework that flips this paradigm to "share to detect." Aligned with OWASP's focus on Privacy Controls and IoT/OT Threat Intelligence, this session will demonstrate how multiple OT sites (refineries, power plants, water utilities) can collaboratively identify globally significant threats before individual sites recognize them as localized attacks. Crucially, this is achieved without exposing sensitive operational data, process telemetry, or revealing which facility discovered the threat.

By deploying autonomous "hunter agents" at historian databases and SCADA systems, the proposed architecture leverages commutative encryption and secure multi-party computation (SMC). It safely answers the question: "Is this anomalous PLC behavior a coordinated, industry-wide attack?"

We will walk through a practical scenario demonstrating how an alliance of sites can collectively validate a suspicious Modbus command sequence. We will show how a weak signal—appearing at only 15% local prevalence—can be cryptographically verified as a global Indicator of Compromise (IoC) active across 87% of participating sites. This validation triggers an immediate, coordinated defense while mathematically guaranteeing that Site A never learns Site B's process parameters, alarm rates, or asset inventory.

Target Audience: Security architects, OT/ICS defenders, and threat hunters looking to implement privacy-preserving intelligence sharing without centralizing sensitive telemetry.

Attendees will learn:

The Pitfalls of Centralization: Why traditional, centralized threat intel sharing and data lakes fail in highly regulated OT environments (and the lessons learned from those failures).

Applied Cryptography for Blue Teams: A functional breakdown of the cryptographic primitives enabling "origin-anonymous" threat artifact exchange.

Practical Deployment: How to deploy autonomous threat-hunting agents directly within existing ICS historian infrastructure.

Measurable Impact: Real-world attack scenarios where cryptographic collaborative detection provides 10-100x faster response times.
Speakers
avatar for Ahmed Elmesiry

Ahmed Elmesiry

Principal Security Researcher, Fujitsu Research of Europe

Dr. Elmesiry is a principal security researcher at Fujitsu Research of Europe with a Ph.D. in information security and assurance. He has extensive experience in R&D, having held academic and industrial positions in various countries on six continents. He has worked on projects related... Read More →
Tuesday September 22, 2026 10:00am - 10:55am PDT

Attendees (1)


Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link