Showing posts with label SCADA. Show all posts
Showing posts with label SCADA. Show all posts

Wednesday, March 25, 2009

Expert: Hackers Penetrating Control Systems

The networks powering industrial control systems have been breached more than 125 times in the past decade, with one resulting in U.S. deaths, a control systems expert said Thursday.

Joseph Weiss, managing partner of control systems security consultancy Applied Control Solutions, didn't detail the breach that caused deaths during his testimony before a U.S. Senate committee, but he did say he's been able to find evidence of more than 125 control systems breaches involving systems in nuclear power plants, hydroelectric plants, water utilities, the oil industry and agribusiness.

"The impacts have ranged from trivial to significant environmental damage to significant equipment damage to deaths," he told the Senate Commerce, Science and Transportation Committee. "We've already had a cyber incident in the United States that has killed people." .. More >>

Industrial Control Systems Killed Once and Will Again, Experts Warn

On June 10th, 1999 a 16-inch diameter steel pipeline operated by the now-defunct Olympic Pipeline Co. ruptured near Bellingham, Washington, flooding two local creeks with 237,000 gallons of gasoline. The gas ignited into a mile-and-a-half river of fire that claimed the lives of two 10-year-old boys and an 18-year-old man, and injured eight others.

Wednesday, computer-security experts who recently re-examined the Bellingham incident called its victims the first verified human causalities of a control-system computer incident. They argue that government cybersecurity standards currently under debate might have prevented the tragedy. ... More >>

Sunday, February 17, 2008

Idaho National Laboratory - Research on National Security

The Idaho National Laporatory's (INL) National and Homeland Security Division is one of serveral organisations inthe USA involved in CNII protection research.

The National and Homeland Security Division conducts sustainable programs focused in Global Security, Homeland Security, National Defense, Energy Security, and Special Programs.

Thursday, January 3, 2008

LOGIIC – Linking the Oil and Gas Industry to Improve Cyber Security

LOGIIC is a unique collaborative forum (initiated by the US Department of Homeland Security) where government and industry are focusing on cyber security issues for the oil and gas industry that are best addressed collaboratively. The needs of the infrastructure owners and operators are driving the formation of projects, supported by government and independent experts. The forms for future collaboration are currently being established, and new projects will be forthcoming.

One such project was the the LOGIIC 2005-2006 Correlation Project.

The LOGIIC Correlation Project was a 12-month technology integration and demonstration project jointly supported by industry partners and the U.S. Department of Homeland Security Science and Technology Directorate (DHS S&T). The project demonstrated an opportunity to reduce vulnerabilities of oil and gas process control environments by sensing, correlating and analyzing abnormal events to identify and prevent cyber security threats.

A detailed description of the LOGIIC Correlation Project can be downloaded from here.

This collaboration model between Government and industry can be similarly applied to other industry sectors.

SCADA Security and CNII - Digital Bond

This Digital Bond site is a site that has articles and blogs on SCADA security with a focus on CNII issues. There are several blog categories that discusses a wide range of related topics. Have a look at the site to get some key information and knowlegde about SCADA security. >> More ..

Wednesday, January 2, 2008

SCADA and Control System Security - Views From An Expert

Joseph Weiss is one of the leading experts in control system security. He provides some interesting insights about control systems and including SCADA, DCS and PLC and the security issues surrounding these in an interview found here.

He explains among other things that "A control system has several unique attributes. Number one, a control system must be absolutely highly reliable. It can't shut down very often. So, unlike a business system where you can shut it down over the weekend, the system that controls the power plant must have almost 100 percent reliability or some form of backup to maintain the 100 percent reliability. It is extremely important." This characteristic brings in itself a very unique perspective about security implementation related to control systems.

In a later part of the interview he has this to say about control systems getting hit: "My very, very, very strong feeling is, if and when we get hit, we will never know why we were hit. All we will know is breakers are opening, valves are closing, certain things are happening. But we won't have a clue as to why."

The interview contains a lot of other interesting insights and examples of incidents and lessons learnt that would be useful for anybody interested in CNII and control systems in particular. >> More ..

Wednesday, October 17, 2007

How To Take Down The Power Grid

Ira Wrinkler, who performs espionage or terrorist simulations (or mundanely known as penetration tests) wrote:

"The first time I broke into our country’s electrical power grid was a decade or so ago. Hacking into the control systems set up by utility companies wasn’t surprising then, and it isn’t surprising now. While people find this shocking, it really isn’t. When you think about how insecure computer infrastructures are, why would you think that the power grid would be any more secure? Frankly, the power grid is even less secure than most other computer networks. I wrote about it many times, including some details in my recent book, Spies Among Us." >> More ..

(Text in bold are my emphasis.)

Monday, October 15, 2007

Hole Found in Protocol Handling Vital National Infrastructure

Researchers on March 21 announced that the systems which control dams, oil refineries, railroads and nuclear power plants have a vulnerability that could be used to cause a denial of service or a system takeover.

The flaw, reported by Neutralbit , is the first remotely exploitable SCADA security vulnerability, according to the security services provider.

Neutralbit identified the vulnerability in NETxAutomation NETxEIB OPC (OLE for Process Control) Server. OPC is a Microsoft Windows standard for easily writing GUI applications for SCADA. It's used for interconnecting process control applications running on Microsoft platforms. OPC servers are often used in control systems to consolidate field and network device information. >> More ..

Those who want more technical details on the vulnerabilities can find them here.

Tuesday, October 9, 2007

NIST Guide to Industrial Control Systems Security (SCADA)

The second draft of the above document which deals with security for Supervisory Control and Data Acquisition (SCADA) systems, Distributed Control Systems (DCS) and Programmable Logic Controllers (PLC) has been released for public comment on 28 Sep 2007.

The draft can be downloaded here.

The document is 157 pages and information on what other organisations are doing in this area can be found in Appendix C of the document. This Appendix C provides useful information to those who are doing further research or comparative studies or implementation alternatives on SCADA security.

Monday, October 8, 2007

New security standards to strengthen SCADA

This 2004 Computerworld article says that "The security of critical-infrastructure processes, long festering as a thorny issue in securing everything from food and water to energy and transportation, will be getting a boost from proposed standards for industrial controls. The National Institute of Standards and Technology (NIST) fostered the creation of the Process Control Security Requirements Forum in 2001. The group issued the first draft of its System Protection Profile for Industrial Control Systems (SPP ICS) in October." >More...

Sunday, October 7, 2007

Knowledge is Greatest Threat to Critical Infrastructure

Australia's critical infrastructure is still under threat due to a shortage of educational resources, according to researchers and security experts.

The major concern is security of Supervisory Control and Data Acquisition (SCADA) systems -- the central nervous system for sensors, alarms and switches that provide automated control and monitoring functions for utilities such as water, gas and electricity, as well as large manufacturers. More ..

ISA99 cyber security guidelines provide full user resources

Manufacturers concerned about cyber security as it relates to plant equipment and factory automation systems should look at the new ‘ISA-99 Security Guidelines and User Resources for Industrial Automation and Control Systems’ CD-ROM.

There are two technical reports: ANSI/ISA-TR99.00.01-2004, ‘Security Technologies for Manufacturing and Control Systems’, and ANSI/ISA-TR99.00.02-2004, ‘Integrating Electronic Security into the Manufacturing and Control Systems Environment’.

The former provides an evaluation and assessment of current types of electronic security technologies and tools that apply to the manufacturing and control systems environment, including development, implementation, operations and maintenance.

The latter provides a framework for developing an electronic security programme and provides a recommended organisation and structure for the security plan. The information provides detailed information about the minimum elements to include.

The original article can be found here.

Hackers Step Up SCADA Attacks

This 2004 article says that "A majority of cyber attacks on industrial control systems now come from the outside, reversing earlier assumptions, according to research at the British Columbia Institute of Technology."

The full article can be found here.

Control Systems, Instrumentation Systems and Automation Security

A number of articles relating to Control Systems, Instrumentation Systems and Automation security can be found from the Instrumentation Systems and Automation site here.

Amongst the relavant articles are:
1. Making Cyber Security Work in the Refinery
2. Uncovering Cyber Flaws
3. SP99 Counterattacks
4. Securing the Power Grid . This article also has a good chronological chart on the 2003 power blackout in OHIO that crippled a part of the nation.
5. ISA99, Manufacturing and Control Systems Security ISA99 is a new standard for Manufacturing and Control Systems Security. The current edition covers only security technologies and their strengths/weaknesses in the manufacturing environment. Eventually this would be expanded to include traditional strengths and weaknesses of the different types of control systems (DCS, PLC, SCADA, HMI, etc). The end of the article contain a list of materials in the development of ISA99 by the ISA SP-99 Committee.

America's Hackable Backbone

This article is a MUST READ article. It highlights the vulnerability of SCADA systems.

SCADA systems are used around the country to control infrastructure like water filtration and
distribution, trains and subways, natural gas and oil pipelines, and practically every kind of industrial manufacturing. And as some security professionals are pointing out, those weaknesses are increasingly connected to the Internet, leaving large parts of America's critical infrastructure exposed to anyone with moderate information technology training and a laptop.

The full article can be found here.

However those who want a pictorial rundown of the story can find it here. The pictorial story covers incidents and potential vulnerabilities of SCADA systems controlling power plants, oil and gas pipelines, transportation, dams, manufacturing, water distribution.

Water Utility Computer System Susceptible to Cyber Attack

In a 2005 article, it was reported that computer-based monitoring and control systems installed by water utilities "may be susceptible to attacks" by cyberterrorists.

See here for the full article.

US Video Shows Hacker Hit on Power Grid

A government video shows the potential destruction caused by hackers seizing control of a crucial part of the U.S. electrical grid: an industrial turbine spinning wildly out of control until it becomes a smoking hulk and power shuts down.

See here for the full story.