Hiển thị các bài đăng có nhãn cyber attack. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn cyber attack. Hiển thị tất cả bài đăng

SANS gets Cyber-Physical with ICS Breach Response Guide


With apologies to Olivia Newton John, you may or may not be aware that some bad actors have been helping raise awareness about physical threats to electric infrastructure lately.  You might say, "Are we sure about this, or were they merely after some copper ... or groundnuts?"

Of course, it always pays to be skeptical, but in the age of video cameras, motion detectors and similar, it's clear that these were humans not after enrichment or nourishment, but rather, intent on destruction.

Mike Assante and Scott Swartz of security training firm SANS just released a how-to manual describing how you can help your utility proceed in the event of an attack.  In particular, they want utilities to be on the lookout for cyber security foul play as they investigate breaches of physical defenses.


Here's the intro for you:
The plans and success of any malicious cyber actor depend heavily on their target’s daily routine and complacency, and human nature’s tendency to not look beyond the obvious. This paper addresses the problem of blended intrusions by suggesting a cybersecurity response to facility break-ins that critical asset security managers can use to determine whether cyber assets might have been targeted during the physical breach. The response includes a systematic and graduated series of actions or checks for evaluating the integrity of cyberbased equipment once you have discovered evidence of a physical breach. Again, these are only suggestions, and any actions should be carefully considered in light of operational reliability, procedures and particular safety policies of the owners and operators.
So there's some human psychology involved in this too. You can (and should) click HERE to read the full paper.

ICS Electric Utility Attack Video and Aegis to the Rescue


SANS Securing the Human - ICS Attacker
The excellent security-mined people at the SANS Institute have produced an 8 minute video that walks you through a control systems attack.  The money they saved by using animation instead of Matt Damon or Morgan Freeman was put to good use as you'll see. For such an esoteric subject, this is a first rate video. For more info please visit the Securing the Human site at http://www.securingthehuman.org/

Meanwhile, to calm you down after the video gets your heart rate up, you should start learning about a new tool that's set for release at the upcoming SANS SCADA Summit. It's called Aegis and it's not an anti-ballistic missile system.  It's a testing tool to help ensure systems communicating with one of the most common SCADA and controls systems communications protocols, DNP3, are harder to attack.

You can ready more about Aegis here: http://www.automatak.com/aegis/

And more about the SANS ICS Summit here: http://www.sans.org/event/north-american-ics-scada-summit-2014

Grid Attack Simulation Just Completed: “It was More Severe than Anything We’ve Drilled"


So said the President and COO of AEP subsidiary Southwestern Electric Power Company, of scenario she and her people faced during NERC's second GridEx exercise.

Sounds like NERC CEO Gerry Cauley and his team brewed up something pretty potent this time.  Heck, it even included 7 deaths and 150 casualties ... in quotes of course.

NERC will issue an "after action" report including objectives, what actually happened, lessons learned and recommendations as soon as they get some sleep.  In the meantime, this account from the NY Times Matthew Wald is pretty darn good.  You can check it out HERE.

Photo credit: The Guardian



Super Cyber Security Reading: 2Q ICS-CERT Monitor

Unfortunately, the Energy Sector wins this competition over last 12 months

There are few publications you can read that will tell you more about the current state of cyber awareness and attacks on critical infrastructure orgs and systems than this than the Monitor.


Before we go much further, laypersons, get ready for some advanced acronym unpacking.

Published quarterly by the US Department of Homeland Security (DHS), the Industrial Control Systems (ICS) Computer Emergency Response Team (CERT), this 15 page document gives you the latest findings and trends.

There's a lot of goodness is the 2Q issues, but I'm going to show you just a couple paragraphs and call out some key words in bold that'll give you a feel for the overall messages it contains.  Let's see how this works:
Most recently, ICS-CERT has assisted critical infrastructure entities in the energy and critical manufacturing sectors with response to cyber intrusion attempts and compromises related to an emerging cyber threat actor. These incidents have involved common exploitation techniques and readily available tools that have been deployed successfully against many companies to compromise networks.
OK, so far so good. You can see that attackers are succeeding without having to work too hard. Now this with a bit more in bold:
In the first half of fiscal year 2013, ICS-CERT has deployed five (5) onsite teams compared to six (6) in all of fiscal year 2012. Three of the onsites were in the energy sector and two were in the critical manufacturing sector. All of the onsite incident response engagements involved sophisticated threat actors who had successfully compromised and gained access to business networks
While onsite, ICS-CERT analysts examined networks and artifacts to determine if ICS networks were also compromised. Unfortunately, in many cases that analysis was inconclusive because of limited or non-existent logging and forensics data from the ICS network
While cyber security threats to ICS and other systems can feel overwhelming at times, it's important to note that utilities and other user organizations can do a lot to improve their posture, without either breaking the bank or having to hire dozens of Einsteins. ICS-CERT is a great resource, one that I'd hope you can use as much as possible, proactively vs. reactively.

--------------------------

URL for Monitor report

http://ics-cert.us-cert.gov/sites/default/files/ICS-CERT_Monitor_April-June2013.pdf

Oil and Natural Gas Co's became Primary Attack Targets Last Year


At least according to analysis from cyber security company Alert Logic. This detail and more is captured in a report just released by the US Council on Foreign Relations (CFR).

According to authors Blake Clayton and Adam Segal:
Cyber attacks on energy companies are increasing in both frequency and sophistication, making them more difficult to detect and defend against. Cyber espionage is being carried out by foreign intelligence and defense agencies, even organized crime or freelance hackers.
Attacks affecting the sector over the past several years including Night Dragon, Stuxnet and Shamoon are all given a nod, as are all the past and present legislative efforts to improve cyber security and information sharing functions. On the international front as well (see: foreign relations).

Nothing new here I think, but this is a good Oil & Gas industry-specific rollup of challenges and potentially mitigating solutions.

Announced on a very high news day it may not get much notice, though I've seen it written up in a number of outlets including Reuters and FoxNews.  But timing may be propitious ahead of Department of Energy's efforts to start a cyber security maturity model for Oil & Gas sector shortly. Stay tuned for more on that.

-----------------

URL for CFR report summary with link to full report (8 pages)

http://www.cfr.org/energy/addressing-cyber-threats-oil-gas-suppliers/p30977

-----------------

Photo credit: Peter Carson at Flickr.com

Energy Sector Orgs: How Would You Know if You Were Secure Enough?

Along with my friend and IBM colleague Jeff Katz, I was recently cited in an article by a new publication called Breaking Energy. One of the things they captured was this statement:
[Legislators and regulators] hear statements that the grid is not secure enough .... That begs the question: how would you know? how do you know how secure it is now?”
If one was hellbent on better securing the grid, how would define your destination and how you know you were making progress towards it? Sorry so many questions.  Maybe you can provide some in the comment space below.

Meanwhile, in this USA Today piece, senior leaders in Washington continue to make alarming sounds about our industry's preparedness:
The power industry [ranges widely in security maturity] from companies that are very good to companies that need a lot of work and a lot of help," Gen. Keith Alexander, commander of Cyber Command, said Friday.
Meanwhile, in the NYTimes, two senior [DHS] officials just said "[a new wave of intrusions] were aimed largely at the administrative systems of about 10 major American energy firms, which they would not name."

Seems we have the motivation. And maybe the means. But I still question whether we have a roadmap, tools, or even language recognize progress. More on this coming up.

Cybersecurity Workforce Developers Need You !!!


The following is an un-paid public service announcement from one of my favorite organizations (note: while this is intended for US-based cybersecurity professionals,  there's a lot to learn, and a lot of similar tasks that need to be accomplished, if you live and/or do your work in other regions):
Power industry security stakeholders!
The National Board of Information Security Examiners (NBISE) is partnering with the Pacific Northwest National Laboratory to contribute to the development of the U.S. cybersecurity workforce. Toward this effort, a utility SME panel has mapped power system cybersecurity job responsibilities to the objectives of two workforce frameworks (NICE and ES-C2M2), the domains of training/education programs, and the objectives of key certifications.
NBISE is excited to announce the opening of the Review and Comment System that allows power industry security stakeholders to comment on the results of these job responsibility mappings by the SME panel and we want your feedback on these results. This review system will be open for three weeks of public comment (planned closing on 15 March 2013).

To participate click here or paste/type http://racs.nbisesites.org into your browser.
Note:
  • The review will require approximately 15 minutes

  • You may participate in this survey using any web browser and will require no special software
As well, please forward this opportunity to anyone you think can provide valuable feedback and insights to this effort.
If you have any questions or feedback, please contact Tom Vanderhorst at NBISE via email at thomas.vanderhorst@nbise.org. The results of our first phase of work (cybersecurity operations competency models) can be found at https://www.nbise.org/institute/resources/
Thank you, Michael Assante
President & CEO
National Board of Information Security Examiners (NBISE)

Electric Sector Vulnerability & Breach Round-Up


Thanks to Jeff St. John at Greentech Media for doing all the legwork required to put together this comprehensive yet readable account summarizing most/all of the recent activity.

As a non-alarmist, there are a few lines I'd write differently, I'd use a different image, and the term Smart Grid is used loosely, as a number of these events and vulnerabilities are not related in any way to Smart Grid technologies.

But overall, I like that all of these things are in one article. And I think Jeff does a good job, as a non-security expert, of capturing the scope of this problem set:
That makes securing today’s grid a matter of upgrading the ability of millions of endpoints like smart meters and grid controls, along with the chain of networking and software that binds them to the utility enterprise, to protect themselves from attack, as well as warn the system when that attack is occurring, which can trigger a series of security responses to detect, prevent or minimize it -- a so-called “defense in depth” approach.
So, have a look HERE, when you're ready to get stirred up by all the recent reports.

Oh, and don't forget, the White House just acknowledged a significant attack (thanks Al Jazeera and others) and big US Banks have been getting hammered by large denial of services attacks the past few weeks as well. More on those HERE.

Looks like we all  better be working harder and smarter going forward.

Photo credit: Boston.com

Attacks on Energy Equipment Vendor like Attacks on Defense Contractor


In 2009 reports emerged that attackers had breached defense contractor systems and stolen data related to the F-35 Joint Strike Fighter. Not knowing what was seen and what was stolen, it means we may always have some uncertainty about how much adversaries know about this plane's combat capabilities and other secrets.

In 2011 we got news that the same contractor was attacked again, albeit this time, perhaps, with less success.

Now comes a network breach of a major critical infrastructure telemetry and control systems manufacturer and it sounds like they may have lost some of the design specs and software at the heart of one of their most important and widely deployed systems.

Systems used by electric utilities, gas utilities and some of the largest oil companies in the world.

How much the company itself knows or will come to know about the scope of the loss may never be known. But as with the F-35 above, current and future users of its equipment, now have a new dose of uncertainty they're going to have to (risk) manage somehow.

In a perfect world, of course the best approach is to prevent these breaches in the first place. But at least they detected them and can initiate  forensics and emergency response plans.

You can read various accounts here:
As well as a Telvent press release announcing a new approach to securing itself and its systems.

Photo credit: Horia Varlan @ Flickr.com

Keep an Eye on This: Saudi Aramco Cyber Attack

31 Aug 2012 update:

Now another one: Qatar-based RasGas seems to have been hit by the same type of attack as Saudi Aramco last week.  No operational impact, but IT systems likely took a pounding.  Link HERE

-------------------------------

16 Aug 2012 10:30 am ET update:

This just in - good news as it seems Saudi Aramco is reporting no operational impact.

------------------------------

Hat tip to my friend, north-of-the-border cyber guru Darth Thanos for his tweet on this. I don't usually post breaking news because that's not my job, and a fuller, more helpful picture usually emerges after a few days or weeks. But this one merits your early attention I believe.

The largest oil and gas company in the world has been attacked, has had its networks disrupted, and may have lost significant data too. Don't know about impact on operations, and don't wont to say more until we learn more.

Michael Assante Holds Forth on Cybersecurity Leadership


You've seen him here before, but for those not familar, his quals, in reverse chronological order:
Great background, right? Though he lives in the Northwest, he's pretty visible in DC as a frequent testifier on national security issues related to cybersecurity and critical infrastructure.

Here's an excerpt from a just published Q&A session I was lucky enough to engage him in. When asked:

 "... What can the energy & utilities industry learn and leverage from these other critical infrastructure industries?" Mike responded:
It is more the norm than the exception to find executive-level cybersecurity leadership in banking and telecommunications today. Years ago, both industries realized that protecting their networks, systems and data from attackers was a strategic imperative. And some industries have even gone so far as to police themselves with their own security standards. Now it’s time for electric utilities and other energy companies to elevate cyber resilience in their business planning and investment decisions.
You bet it is.

The interview is not too long ... only 4 questions, but I highly recommend you view his well-informed responses to all of them, which you can see RIGHT HERE.

Image credit: NewsMilitary.com