Blog

AIS Brings Hands-On ICS Cybersecurity Expertise to Colorado State University Workshop

AIS supported the Front Range Consortium in their Cybersecurity and Critical Infrastructure Workshop hosted by Colorado State University (CSU) on August 18-20.

Graduate and master level students from CSU, Colorado College, University of Colorado Boulder, University of Colorado Denver, University of Colorado Colorado Springs, and University of Denver attended this event to learn about cybersecurity and critical infrastructure. AIS staff members Dan Salloum and Eric Thayer Supported the event as participants in conjunction with members from the Front Range consortium, Idaho National Laboratory, and private security firms. AIS staff served as instructors and panel participants focusing on security of control systems bringing along expertise from DARPA’s Assured Micro-Patching (AMP) and ByteRI SBIR Phase II programs.

AIS supported the workshop dedicated to advancing the transition of DARPA’s AMP technologies into industrial control system (ICS) environments that underpin critical infrastructure nationwide. The event brought together college students, National Laboratories, and technology partners from the power and water sectors to explore AMP capabilities. AIS, as a mission-driven integrator, showcased its role in delivering field-ready solutions and facilitating hands-on demonstrations, training, and security focused panel discussions.

AIS delivered a two‑part hands‑on introduction to Reverse Engineering (RE) and Binary Patching & Verification for industrial control system (ICS) environments. Led by Daniel Salloum, these two sessions emphasized practical skills using DARPA-developed binary analysis and manipulation tools, equipping students with both conceptual understanding and real-world application experience.

In the first session, participants analyzed a real ICS-relevant binary that controls wind turbine behavior via MODBUS-TCP, GPIO, and PWM interfaces. Through guided exercises, students learned to dissect binary architecture, trace critical logic paths, identify functional vulnerabilities, and understand how low-level control signals affect ICS system behavior. They employed tools such as OFRAK and Angr-management to perform unpacking, disassembly, decompilation, and symbolic execution.

The second session focused on creating and validating binary patches using Patcherex2, demonstrating how to introduce safe behavioral constraints to prevent unsafe control states. Verification workflows using Angr-management, VeriBin, and COZY gave participants experience in confirming functional correctness, detecting unintended side-effects, and analyzing structural impacts of patch modifications.

Overall, the two-course session successfully provided students with a complete RE, Patch, and Verify lifecycle example, reinforcing safe firmware manipulation practices and enhancing student proficiency with advanced ICS binary analysis tools. The training improved student readiness for operational debugging, binary hardening, and vulnerability remediation tasks across ICS programs while exposing them to state-of-the-art tooling that could be critical to future threat mitigation.

Conversations were steered towards the most pressing security challenges facing modern industrial and commercial systems

In addition to ICS and security training sessions, students were also presented with a panel discussion with leaders in product cybersecurity, industrial systems security, engineering, and academia to address real-world challenges facing modern connected products and critical infrastructure devices. Eric Thayer, an AIS Chief Engineer, participated in the panel of cybersecurity and engineering composed of Chris York (Electronic Systems Cybersecurity Architect at Cummins), Indrakshi Ray (CSU Computer Science Professor), and Derek Catterfeld (Head of Engineering at Duc Engineering). The discussion was moderated by Dr. Jeremy Daily (CSU Systems Engineering) who steered conversations towards the most pressing security challenges facing modern industrial and commercial systems. The discussion shed light on strategic gaps in applying traditional IT security models to operational technology (OT) environments, highlighted systemic risks across legacy protocols and supply chains, and emphasized the urgent need for industry-wide improvements in secure product design, lifecycle maintenance, and workforce readiness.

The discussion centered on vulnerability realities in embedded systems, risks in legacy ICS protocols, software maintenance and patch cycles, and threat implications for operational systems. Panelists underscored that critical infrastructure systems operate under real‑time, safety‑critical, and hardware‑constrained conditions that make standard IT playbooks insufficient and securing industrial and commercial products requires operation across legacy systems, evolving threat landscapes, and tightly constrained hardware environments. The session provided students with realistic expectations of the work, emerging tools, and the mindset needed to contribute meaningfully to modern cyber physical security challenges.

Overall, the discussion reinforced a strategic message: organizational resilience in cyber‑physical systems depends on modernizing security approaches, reducing legacy risk exposure, enhancing supply chain assurance, and developing a technically capable workforce that understands both digital and physical operational realities.

The Cybersecurity and Critical Infrastructure Workshop brought together a diverse group of cybersecurity professionals, researchers, and industry leaders from Idaho National Laboratories, National Laboratory of the Rockies, AIS, the Front Range Consortium, academia, and industry partners across multiple sessions and collaborative activities. The agenda featured expert-led discussions and demonstrations on distributed energy systems, ICS communications, reverse engineering tools, binary patching, grid system control, critical infrastructure security, electric vehicle supply equipment, and product cybersecurity. By sharing the classroom and stage with these distinguished experts, AIS strengthened its industry relationships, gained valuable insights into emerging threats and best practices, and contributed to workforce development through active engagement with academic and industry partners.

The collaborative environment and breadth of topics addressed not only expanded our technical knowledge but also equipped us to better anticipate and respond to customer needs in the evolving cybersecurity landscape.

LEARN MORE ABOUT TECH INTEGRATION at AIS

Privacy Settings
We use cookies to enhance your experience while using our website. If you are using our Services via a browser you can restrict, block or remove cookies through your web browser settings. We also use content and scripts from third parties that may use tracking technologies. You can selectively provide your consent below to allow such third party embeds. For complete information about the cookies we use, data we collect and how we process them, please check our Privacy Policy
Youtube
Consent to display content from - Youtube
Vimeo
Consent to display content from - Vimeo
Google Maps
Consent to display content from - Google
Spotify
Consent to display content from - Spotify
Sound Cloud
Consent to display content from - Sound
Assured Information Security
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.