Hiển thị các bài đăng có nhãn control systems. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn control systems. Hiển thị tất cả bài đăng

Sandia and Hayden on Cybersecurity Strategies for Microgrids

First off, thanks to friend and colleague Ernie Hayden for writing a microgrid security post following his mini-immersion in the topic last week.  You can read his write-up HERE.

In particular, want you to see something he linked to: SNL's Microgrid Cybersecurity Reference Architecture.  That's Sandia National Labs, btw, not Saturday Night Live; talented though he is, Jimmy Fallon is not a contributor to this piece.



Note: the microgrid concept described by Sandia is principally for energy security in DOD use cases, for emergency fall-back scenarios. Not necessarily for improving day-to-day operations or achieving efficiencies or cost savings, though you get some of those as part of this.

An excerpt from the Executive Summary makes that concept clear:
The design of a microgrid control system needs to be more robust than that of a traditional industrial control system (ICS) for the following reasons:
  • The microgrid is used in emergency situations and may be critical to continuity of operations of an installation 
  • The microgrid must function during active attack by a capable adversary.
As such, the traditional design and implementation for an ICS may not be sufficient for implementing a robust and secure microgrid.
Of course, there are an increasing number of non-military microgrid use cases and a burgeoning technology and integration market that supports them. But my guess is all those civilian applications should go to school on how Sandia and the DOD are hardening theirs, and select from among those approaches security that's right for their own risk tolerance objectives.

SCADA Primers Now for Grades 1-8 and Even More Managers


Earlier this year, the US Air Force's Robert M. Lee brought us SCADA and Me, an intro level graphic novelette optimized for very young children and certain managers. Now comes Haley Wauson of industrial automation company Cimation with a blog post that should help SCADA and Me readers advance to the level of middle school literacy and educate an even more advanced cohort of managers.

In her succinct post "What is SCADA Anyway?" Ms. Wauson uses infographic style visuals and multi-syllabic words to take readers to a level of depth that goes well beyond Robert Lee's Goodnight Moon-esque masterpiece.

Sounds like I'm joking around but actually works like these are just the thing for de-mystifying technology that's foreign to IT-centric folks.  SCADA and control systems are of central importance to making good things happen in our increasingly interconnected "Internet of Things" world, or as my recent alma mater IBM has dubbed it, the Smarter Planet.

Securing these things, now that's another matter. But first you have to know what they are, and where they are, in the first place!

Wrap Up: The 13th Annual ICS Cybersecurity Conference

Another Industrial Control Systems Cybersecurity conference is behind us and, as usual, as documented by founder Joe Weiss, there were signs of a slow awakening to the importance of this topic, mixed with persistent inertia.

You can read highlights from first two days HERE, and Joe's final day summary HERE.

It was nice to hear that my friend (and very good guy) Johan Rambi from large utility Alliander (based in The Netherlands) was playing such an active role.  And this note below reminds everyone that ICS security is not only an energy or power sector problem.  As Joe tells it:
Jeffrey Smith from American Axle gave a great presentation about how they have secured (or very significantly improved security) in their factories world-wide. What I felt was so important is their focus was on productivity and worker safety. Security was simply a threat that needed to be addressed so they could operate safely and efficiently.
This is reminiscent of others who point to the two goals one finds most highly valued in a power co, reliability and safety, and urge the security community to tie physical and cybersecurity tightly to those domains from messaging and business case perspectives.

Security practices are funded and run not merely to check compliance boxes, but to give businesses and government orgs Confidentiality, Integrity, and Availability (CIA) for their systems, networks, apps and data ... so they can continue to pursue their missions with confidence and efficiency.

Or to call out a potential ICS-specific update to the perennial security triad the conference produced: adding O for Operational Controls.  For this very important and highly specialized domain, it might make sense to reverse the prioritized order of CIA and get the O in there too: AIOC.  Ayy-Awk.

Webinar Alert: Energy Sector Learning to Speak a New and Secure Procurement Language


Hat tip to UTC's Nadya Bartol (Twitter @NadyaBartol) for the heads-up on this upcoming webinar to unveil a draft document as follows:

Title: Cybersecurity Procurement Language for Energy Delivery Systems
Project Description: This effort seeks to promote cybersecurity by design through procurement language tailored to the specific needs of the energy sector. Updated language for the energy sector can aid in addressing some of the evolving challenges by helping asset owners, operators, and suppliers establish a baseline of minimum cybersecurity requirements.
When: Monday, October 28, 2013 @ 3:00 - 4:00 PM EDT

Register: HERE

For more info on this effort: click HERE

POC: Eric Wagner at eric.wagner@utc.org

Several Scenes from EnergySec Summit 2013

Click for much Gibber ... I mean, bigger
Was in Denver not far from flooded Boulder last week at the 9th annual EnergySec Summit ... my first.  I'm sure we'll be seeing more articles and posts from EnergySec scribes and some of the other 150 or so attendees soon, but wanted to get my observations out.

I missed a number of presentations due to a mid day arrival on Wednesday and missed a few others to field a few intermittent phone calls, but got to hear most of them (my apologies to speakers not covered below).

First off, Patrick Miller and Steve Parker, EnergySec Presidents past and present, were both outstanding ringmasters and herders of wandering speakers.


Great to see Jack @sintixerr, @SharlaArtz, @LisaNCW Carrington and nearly see @Slad3G Griffin. And the amazing Tweetwall (center screen in picture above) facilitated audience participation, both in the room and globally, scrolling thoughtful 140 character contributions and snarky, succinct broadsides on the unsuspecting speakers! Hashtag for a replay of sorts is #ESS13.

Here's a summary of the talks I caught:
  • Andrew Plato (Anitian) on his Rapid Risk Assessment approach, with special and humorous emphasis urging native security speakers to learn and use business language (maybe RosettaStone or Duolingo can help them with this)
  • Julie Soutuyo (Tennessee Valley Authority) shared her experiences helping make TVA, faced with an onslaught of real-world cyber threats while having to address both FISMA and NERC CIP compliance regs, a more resilient organization
  • Russell Thomas (George Mason University) aka @MrMeritology took us through a Texas Heat Wave movie plot of his own creation to illustrate how a balanced scorecard risk management framework could save the day. Look for it in theaters in 2015!
  • Michael Toecker (Digital Bond) aka @mtoecker provoked the crowd with a great talk on bridging the divide between control systems operators and cyber security pro's, and had us ready to see his concepts on a mock up of an actual operator display. Sadly, he said that will have to wait to next time.  Meanwhile, as SpongeBob would say,  you're free to use your IMAGINATION
  • Chris Sistrunk (Entergy) aka @chrissistrunk, an unabashed squirrel lover, showcased his extraordinary SCADA test lab, described how he built it, the many benefits it confers upon his coworkers at Entergy, and gave practical advice on how folks in the audience could jumpstart their own labs projects
  • Jacob Kitchel (Industrial Defender) walked us through a DevOps approach to improving IT operations in control systems environments. He listed many helpful tools along the way, and made mention of ID's tools near the end. Not entirely security related ... and like Chris's before it, the audience seemed to eat it up.
  • Gib Sorebo (SAIC) gave by far the most business oriented talk, focusing on what security practitioners in the audience need to know to better communicate security risks and requirements to their senior leadership, board members, and shareholders. He also described mature governance structures and business-risk based cybersecurity strategies
  • Nadya Bartol (Utility Telecom Council) walked us through an exploration of the mesmerizing complexities of ICS supply chain security and shed some light on emerging tool that may help utilities get a handle on this challenge: IEC 62443 2-4
  • Spencer McIntyre (SecureState) - two key terms in this one for me: Zigbee, the low power networking standard used in AMI smart meters, and its evil twin: KillerBee, a "practice Zigbee exploitation framework". Good discussion on the current state and some of the continuing security issues with smart meters
Lastly, following University of Houston professor, Dr. Art Conklin's energetic opening, I moderated a Town Hall-style discussion on "Workforce Development in the ICS Workplace." We hit a lot of different notes over the course of several hours, and jointly investigated questions on how to build a robust pipeline of skilled operational security (OT) Security practitioners for utilities.  I'll leave you with this image from my preso, which attempts to depict the current cultural and language divide one finds in many utilities. Just so you know, some of us are working hard to finish these bridges!


Got to go now ... Next year's in Austin!

Rapidly Approaching Training Alert: SANS Control Systems Security

Depending on where you sit at the cyber security table, this might be for you or someone in your org.

Here's how the SANS folks describe it:
A rising number of cyber threats impacting industrial systems have increased the urgency to address security challenges for Industrial Control Systems. Learn how to develop an effective and comprehensive cyber security strategy and equip yourself with the technical know-how and skills to apply in these unique applications. Cyber security is an important element to achieve highly reliable and safe operations. SANS Hosted ICS training courses equip both security professionals and control system engineers with the knowledge and skills they need to safeguard these important systems.
Available classes: SCADA Security Training, Critical Infrastructure and Control System Cybersecurity, and Assessing and Exploiting Control Systems

OK now the details:

  • What: SANS Industrial Control Systems Training
  • When: 12-16 August 2013
  • Where (Generally speaking): Washington DC
  • Where (More specifically) : the Westin hotel in Georgetown
You can register here: http://www.sans.org/event/ics-security-training-washington-dc and if you use this code you'll get a discount: SANSICS_SGSB5

Major SPIDERS (DOD Secure Microgrid) Update

This post just in from Mr. Harold Sanborn, Program Manager at Construction Engineering Research Lab (CERL), US Army and technical manager for the SPIDERS Joint Capability Technology Demonstration (JCTD).  I've removed most of the defense industry speak from a longer version you can find on the DOD Energy Blog.  FYI SPIDERS = an ongoing DOD distributed energy program and the acronym stands for Smart Power Infrastructure Demonstration for Energy Reliability and Security. ab

Here's Harold:

SPIDERS Phase I has finished the "history tour" as we codify and publish the lessons learned.

SPIDERS results demonstrated additional capability for Joint Base Pear Harbor Hickam, including:
  • Synchronizing with the utility service power signal while pushing electricity back on to the base distribution system
  • Operational viewing of other circuits in the substation in addition to the one controlled by the micro-grid, and
  • Power factor improvements and the opportunity to test generators at load

The Navy customer (Navy Facility Command Pacific/Hawaii) provided positive and constructive feedback throughout the technical and operational demonstrations at Joint Base Pearl Harbor Hickam (JBPHH). The only item where Navy utility folks have any residual concerns for on-going operations and maintenance is keeping their workforce trained and ready to employ SPIDERS and dealing with new technology after the buzz wears off. Our contractor (Burns & McDonnell) continues the dialog of training and post contract support. Two devices at JBPHH have had heat related challenges, and we're recommending we paint the boxes white instead of Navy utility brown.

To date, there isn't a system owner. Controls, hardware and software are not static and require some continuing education and occasional attention. DoD will face this challenge across the board as we take a collection of electrical appliances and make them a systems engineered smart grid. Oops, did I say smart grid?  I meant distributed energy management system. The good news is SPIDERS showed the truth in our motto: do no harm. During our operational demonstration, the software "burped" and the system went back to traditional stand alone back up power. The amazing thing: the 24/7 operators (blue collar Navy civilian) saw the system degrade in their 24/7 ops center without tripping loads or causing other electrical problems. Their after action dialog shows true customer values: a system that does what it says it will do. 

Cyber security critiques continue to bubble in the background. Growing areas of concern were anticipated, just not the ramp rate by which DoD is expecting trouble. PACOM (a combatant command and one of two SPIDERS Operational Managers) has invested many dollars and man hours in working closely with DHS and DOE labs to promote a comprehensive set of industrial controls cyber protection test(s). Phase I SPIDERS didn't require external hacking as part of the operational demonstration, yet in the end, we performed a cyber experiment that showed promise in our path forward. Phases II (Fort Carson CO) and III (USMC Camp Smith HI) offer expanded cyber experimentation and we plan to stay current with DoD and DHS process to validate their application in the real world of installation industrial controls.

Overall, most folks still fail to recognize the energy security value of micro-grids. To answer the question of worth for micro-grids, phase III SPIDERS will work to communicate with the local utility service, and provide ancillary services when connected to the utility service; and also offer other measurements to adjust power quality and controls while waiting for the anticipated utility outage so that the security aspect of islanding comes into play. 

Life cycle configuration management of smart systems might need a DoD PM to solve deployment issues. Frankly, it isn't an ownership definition that challenges DoD, although that's often the red herring slow thinking folks suggest. Ownership needs simple definitions that already exist in DoD. Accountable, physical, and custodial owners of distributed energy management systems will likely need to agree on metrics to begin programming for their responsibilities.

The take away, no, the bottom line is that smart systems are coming and we can manage those if we apply just a modicum of intellectual activity up front. SPIDERS isn't the first micro-grid. SPIDERS is a systems engineered solution using hardware and controls to insert new technologies to installation transmission and distribution systems to enable more energy security from existing and planned assets. How much is it worth? I'll answer that question in a future post. HS

Super Cyber Security Reading: 2Q ICS-CERT Monitor

Unfortunately, the Energy Sector wins this competition over last 12 months

There are few publications you can read that will tell you more about the current state of cyber awareness and attacks on critical infrastructure orgs and systems than this than the Monitor.


Before we go much further, laypersons, get ready for some advanced acronym unpacking.

Published quarterly by the US Department of Homeland Security (DHS), the Industrial Control Systems (ICS) Computer Emergency Response Team (CERT), this 15 page document gives you the latest findings and trends.

There's a lot of goodness is the 2Q issues, but I'm going to show you just a couple paragraphs and call out some key words in bold that'll give you a feel for the overall messages it contains.  Let's see how this works:
Most recently, ICS-CERT has assisted critical infrastructure entities in the energy and critical manufacturing sectors with response to cyber intrusion attempts and compromises related to an emerging cyber threat actor. These incidents have involved common exploitation techniques and readily available tools that have been deployed successfully against many companies to compromise networks.
OK, so far so good. You can see that attackers are succeeding without having to work too hard. Now this with a bit more in bold:
In the first half of fiscal year 2013, ICS-CERT has deployed five (5) onsite teams compared to six (6) in all of fiscal year 2012. Three of the onsites were in the energy sector and two were in the critical manufacturing sector. All of the onsite incident response engagements involved sophisticated threat actors who had successfully compromised and gained access to business networks
While onsite, ICS-CERT analysts examined networks and artifacts to determine if ICS networks were also compromised. Unfortunately, in many cases that analysis was inconclusive because of limited or non-existent logging and forensics data from the ICS network
While cyber security threats to ICS and other systems can feel overwhelming at times, it's important to note that utilities and other user organizations can do a lot to improve their posture, without either breaking the bank or having to hire dozens of Einsteins. ICS-CERT is a great resource, one that I'd hope you can use as much as possible, proactively vs. reactively.

--------------------------

URL for Monitor report

http://ics-cert.us-cert.gov/sites/default/files/ICS-CERT_Monitor_April-June2013.pdf

Training Alert: ICS / 2 Control Systems Security Sessions Coming Up

SGSB readers: first a brief housekeeping note. Due to a dose of awareness I just received yesterday, I'll no longer be including live links in posts. When I want to recommend a web page for you to visit I'll give you the full URL, which you can paste into the browser of your choice (see below).

OK moving on. SANS is developing an ICS & utility focused security practice with NIPSCO's Tim Conway assisting.  And this effort is already bearing fruit, with training classes coming up next month.  Here are the deets for you:

  • When: June 11, 2013 (Saturday)
  • Where: Westin Houston Memorial City, Houston, TX USA
  • What: two courses:

1) SCADA Security Training 
    2) Pen testing ICS and Smart Grid
      For more info and to register, do what you need to do with the following URL: 
      http://www.sans.org/event/scada-training-houston-2013

      Special SGSB Offer: use the code SmartGrid2013 when you register and you'll receive $150 off the Pentesting ICS or the Smart Grid or the SCADA Security Training course.

      Webcast Alert: Establishing Security Baselines at Industrial Facilities

      I love good baselines, and I'm not the only one. When famous jazz composer arranger Gil Evans (see Sketches of Spain) heard the early Police playing Walking on the Moon, he took time to personally compliment the stunned base player, Gordon Sumner aka Sting.

      Now another baseline for you, less musical but more actionable, courtesy of the new ICS-ISAC:
      • Title: Raising All Boats: Establishing Security Baselines at Industrial Facilities
      • Date: Monday April 29th, 2013
      • Time: 1:00-2:00pm USA Eastern Time
      • Registration and more info here: http://ics-isac.org/events.html
      Hope you can make it. Oh, and here's Miles for you: http://www.youtube.com/watch?v=7KDQNoqKya0

      ICS Lab for Grid Security Research, Training and Demonstrations

      In case you're not already tuned into this community, but might want to be, I submit for your review the contents of an email I received yesterday.  It goes like this:
      Greetings ICS-ISAC Members and partners! 
      The ICS-ISAC and MS-ISAC are partnering with several key Members to create an ICS Security Lab as a shared asset for research, training and demonstrations. Physically hosted in Livermore, CA by Robot Garden the Lab is now in Phase One of procuring equipment and establishing the virtual capabilities that Members can have access to. 
      If you are interested in participating in this activity or have equipment that would be of benefit to this endeavor please send a note to ICS-ISAC Chair Chris Blask at chris@ics-isac.org
      There is also a LinkedIn group for collaboration at http://www.linkedin.com/groups?home=&gid=4932821&trk=anet_ug_hm&goback=%2Emyg

      Acronym Legend:

      ICS-ISAC = Industrial Control Systems Information Sharing and Analysis Center

      MS-ISAC = Multi-State Information Sharing and Analysis Center


      That's all I got.

      NatGas Cybersecurity getting a lot more Visibility


      Thanks to colleague H. Chantz for spotting this article and sending this way.

      As has been the case quite a bit this year, once again we are in the realm of SCADA/Control System security. William Rush of the Gas Technology Institute states it plainly, if somewhat dramatically:
      Anyone can blow up a gas pipeline with dynamite. But with this stolen information, if I wanted to blow up not one, but 1,000 compressor stations, I could,” he adds. “I could put the attack vectors in place, let them sit there for years, and set them all off at the same time. I don’t have to worry about getting people physically in place to do the job, I just pull the trigger with one mouse click.
      There are no NERC CIPs for the gas industry, but with 25-30% of US electric power and a whole lot of home heating coming from gas, it's time to get moving on better securing this infrastructure.

      Pipeline operators, now alerted to the fact that sensitive access control information to important subsystems is in the hands of folks outside the industry (and outside the country it seems), need to get moving. And I'm sure they will, but it's a BIG job.

      The whole Christian Science Monitor article is HERE.

      Photo credit: War News Updates

      Recommended Reading: Industrial Safety and Security Source

      3/8/13 Flash update - SGSB reader and contributor Ernie H suggests you visit Joel Langill's www.scadahacker.com site as well to further enrich your budding control systems security knowledge.
      --------------------------------

      As I've mentioned a few times before, this year I'm working on getting my OT security chops up to speed, and that means getting a lot more familiar with the way SCADA and ICS systems work when they're functioning properly, to better appreciate how they can be exploited when reached by those with impure thoughts and nefarious motives.

      To that end I reach out to folks who seem to know more about this part of the world than I do (sadly, a group that must number in the hundreds of millions). I'm not always successful, but when I am, am happy to share my success so you can advance your own understanding, if necessar, as well.


      So after a great intro talk, I asked Greg Hale to send me a few words about his site. Not all the articles are my cup of tea, but the fact that they span multiple industries and sometimes discuss security and safety is.

      Here's a brief intro for you:
      Launched in April 2010, Industrial Safety and Security Source (www.isssource.com) is a web-based information provider devoted solely to keeping manufacturers current on safety, cyber and physical security news, products, features, applications and trends.  
      Our mission: To be the one-stop web resource that provides safety and security information to manufacturers that will help them find the right solution to improve the way they do business. Industrial Safety and Security Source is a web site offering news, features, analysis, research, blogs and opinions on safety and security issues within the manufacturing automation market. 
      Editor and Founder Gregory Hale has over 30 years in the publishing industry covering manufacturing automation ... and is the co-author of the book, Automation Made Easy: Everything You Wanted to Know About Automation – and Need to Ask.
      OK, have at it.

      Conference Alert: European Smart Grid Cyber and SCADA Security


      The European wing of our global grid security tribe is gathering soon in London. Some great speakers and plenty of utility participation at this one.

      Recommend you check it out - here are the basic deets:
      • When: March 11 & 12
      • Where: The Copthorne Tara Hotel, Scarsdale Place, Kensington, London, W8 5SR
      • For more info and registration, click HERE
      SGSB point of contact: Jamison Nesbitt, jnesbitt@smi-online.co.uk

      Photo credit: Magnet Magazine

      ICS-ISAC Webinar on Municipal Utility Control Systems Security

      The ICS-ISAC (that's Industrial Control Systems Information Sharing and Analysis Center if you want it spelled out for you) has a webinar coming up soon if you want a bite-sized dose of control systems security best practice knowledge. As the site says:
      ICS-ISAC Member Briefing Miki Calero, Chief Security Officer for the City of Columbus Ohio, will provide a first-hand assessment of the challenges and opportunities presented to those responsible for securing municipal infrastructures.
      For me, this is interesting because in addition to getting more info out on control systems security, we'll also get to hear the municipal (or "muni") point of view. Muni's are everywhere and are often below the radar of the sector press, who like to focus on  the large investor owned utilities (IOUs). Yet muni's, responsible for medium sized cities and above, play a critical role in keeping the lights on for millions (maybe billions) around the world, especially at the distribution level.

      The webinar will also include ICS-ISAC Chair Chris Blask brief ISAC members on new developments at the Center.

      When: February 20, 1-2 pm ET

      Here's a LINK to learn more and register.

      Conference Alert: SANS ICS Summit coming up fast

      Smart Grid Security Blog readers: heads-up. I've decided that this year the time has come to do a massive press on Operational Technology (OT) Security issues.  I think the reason for the timing is obvious, but I'll make my case in a future post when I have more time.

      And this won't be just for the US and North America, and it won't be limited solely to the electric sector. We'll look at OT security challenges and efforts in other industrial equipment-oriented critical infrastructure sectors.

      But for now, get ready to see some announcements for upcoming conferences and webinars on this topic by some of the best and most experienced folks in the business. Details on the first one are right here:

      Name

      The 8th Annual SCADA and Process Control System Security Summit

      Dates

      Feb 6-11: Pre-Summit Courses
      Feb 12-13: Summit (click HERE for Summit agenda)
      Feb 14-15 :Post-Summit Courses

      Venue

      Walt Disney World Disney's Yacht & Beach Club
      1700 Epcot Resorts Boulevard
      Lake Buena Vista, FL 32830

      To Register

      Click HERE to register for Summit
      Disney Website: Walt Disney World Disney's Yacht & Beach Club
      Reservations & Discounted Park Tickets: http://www.mydisneymeetings.com/sans2013

      This week and half would enable one to really immerse themselves in the topic. And maybe enjoy a little Disney time too.

      Security Double Dutch: Shodan Points out Critical Infrastructure Gaps in the Netherlands


      Hat tip to friend and colleague Steve D for shooting this my way.
      Security researcher Oscar Koeroo, working for the Dutch nuclear physics institute NIKHEF, found out that national infrastructural systems were listed on Shodan, (a database of cyber security vulnerabilities) and could be easily accessed remotely. Those systems, controlling pumping stations and sluices, are vital for the water management of a large part of the Netherlands. Because a large part of the country lies below sea-level, those systems keep the Dutch feet dry!
      I've been to the Netherlands several times and saw the country in the news a lot recently when UberStorm Sandy raised concerns that New York City should perhaps get similar types of protective systems. I can assure you that this is about much more than a preference for dry feet.

      Read on to find out how control system search engine Shodan once again reveals what systems are directly connected to the Internet. Warning, it paints a full picture, but it's not a pretty picture, and hopefully you won't find systems in your charge popping up in the findings window!

      Here's the complete article from Tofino, replete with lurid details of password mismanagement, accusations, denials and counter-accusations, and that sort of thing. Best keep a Heineken or two handy.

      Photo credit: nrc.nl

      DHS ICS-CERT reports malware on power control systems

      Happy 2013!

      OK, enough frivolity. Let's turn down the Nat King Cole, step out from under the mistletoe, and get down to brass tacks.

      First, in case that compound acronym is new to you, it stands for: the Industrial Control System - Computer Emergency Readiness Team, and it lives in the US Department of Homeland Defense.

      This organization just issued a public quarterly report that describes, at a high level, a recent incident at a power generation company you'll be interested in. I'll get out of the way and let you read the first bits for yourself:
      MALWARE INFECTIONS IN THE CONTROL ENVIRONMENT
      ICS-CERT recently provided onsite support at a power generation facility where both common and sophisticated malware had been discovered in the industrial control system environment. The malware was discovered when an employee asked company IT staff to inspect his USB drive after experiencing intermittent issues with the drive’s operation.

      The employee routinely used this USB drive for backing up control systems configurations within the control environment. When the IT employee inserted the drive into a computer with up-to-date antivirus software, the antivirus software produced three positive hits. Initial analysis caused particular concern when one sample was linked to known sophisticated malware.

      Following analysis and at the request of the customer, an onsite team was deployed to their facility where the infection occurred. ICS-CERT’s onsite discussions with company personnel revealed a handful of machines that likely had contact with the tainted USB drive. These machines were examined immediately and drive images were taken for in-depth analysis.
      ICS-CERT also performed preliminary onsite analysis of those machines and discovered signs of the sophisticated malware on two engineering workstations, both critical to the operation of the control environment. Detailed analysis was conducted as these workstations had no backups, and an ineffective or failed cleanup would have significantly impaired their operations.

      The full article can be seen HERE.

      Thoughts on the Explosive MI6 OT Breach in Skyfall


      Have you seen the new 007 movie yet, the third of the series that features Daniel Craig as Bond? Called Skyfall, one of its key plot drivers occurs when the evil mastermind blows up part of British spy headquarters, MI6, in London, with a handful of deft key strokes. By the way, OT in the title of this post = Operational Technology, as differentiated from business information technology or IT.

      Stuxnet this is not, but it is clearly depicted as a cyber attack on physical assets, and others who have weighed in on the plausibility/authenticity of this depiction (see HERE and HERE) cannot help but point to Stuxnet as the real world proof of concept.

      To free up more time for mayhem, Javier Bardem's well played psychopath might have started with Shodan, the online search engine that helps both good guys and charismatic bad guys quickly locate internet-connected control systems.

      The SimplySecurity site provides some good context for all of this:
      Between 2005 and early 2010, when Stuxnet was first discovered, analysts observed just nine confirmed ICS or SCADA vulnerabilities. That figure suddenly spiked to 64 vulnerabilities in 2011, while an additional 98 were highlighted in the first eight months of 2012. What's more, 50 of the exploits discovered between 2011 and September 2012 were freely published across cybercriminal forums. As report authors noted, these security loopholes could compromise everything from public transit systems and water supplies to gas pipelines and nuclear power plants. And with more than 40 percent of the observed ICS/SCADA systems containing components that face the open Internet, film fiction could quickly become regrettable reality. Just this month, Chevron became the first U.S. company to admit that its systems had been infected by a mutation of the Stuxnet virus.
      Chances are, evil geniuses will have better luck targeting SCADA and control systems in water or gas utilities where cyber security has been given less attention than the British equivalent of the CIA. And should they target environmental control systems in government buildings, it's possible but unlikely that they can cause explosions that will kill multiple persons and create fireballs that will blow the walls off (as above).

      Nevertheless, the risks and potential harms involved with operational technology (OT) cybersecurity are substantial, and merit everyone's prompt and continued attention ... right after the next martini, that is.

      Photo credit: Business Insider

      Conference Alert: Smart Grid & Control Systems Security for Europe


      Sometimes I don't give enough lead time, here's a case where maybe I'm giving you too much lead time. Anyway, you know how time flies when you're having fun, so 5 short months from now, you might want to be here:

      • What: 3rd European Smart Grid and SCADA Security Forum
      • Where: The Copthorne Tara Hotel, London
      • When: 11-12 March 2013
      • Web: For more info and to register, click HERE