Hiển thị các bài đăng có nhãn scada security. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn scada security. Hiển thị tất cả bài đăng

A Social Summary of SANS ICS Security Summit 2014

Since I went solo there's been less time for blogging but I hope to catch up a little with this mega post on the just-concluded, 9th annual SANS ICS Security Summit which took place in the Contemporary Hotel at Disney.

Where I can I'll include Twitter IDs, as for many of us, Twitter is how we stay abreast of what we find interesting and what we're thinking about in between real world meet-ups. (Note: I only include these when they're unique to the individual and not shared by a company or org.)

I won't cover all the talks because I didn't attend all of them, and I apologize to those presenters I don't cover here. Nor was I at "Game Night" (though I wish I was) which from what I heard later was a fantastic and grueling hack-fest that extended into the wee hours before champions finally emerged.


For those of us lucky to be at the hotel Sunday night, and to know what was going on, a four-act play called "Exposure to Closure" or "The Heist" penned by Ben Miller @electricfork was really something. With MC Tim Roxey @ScubaNuke providing intro's, transitions, and running commentary, all injected with equal parts wisdom and levity, and a cast of characters from the really-not-ready-for-prime time-SANSICS players, for me it was the highlight of the trip, even before the conference officially started.

The audience got to see, in four acts and sixteen scenes, the full sequence of an attack on a utility control center, the confusion, analysis and corporate squirming that ensues, and how it resolves relatively peacefully (in this case) in the end. Mark Fabro stole the show with a swift and spooky transformation from dweebish uber-geek to a credible threat to another actor's physical security.

Chris Sistrunk @chrissistrunk and Adam Crain @automatak kicked things off smartly as twin fuzzing brothers from different mothers providing an overview of the many flavors of fuzzing, and the DNP3 protocol and how it's being made more secure (less insecure).  At one point, Chris noted that with much of the initial badness having been attended to, "We're starting to look at the back yard and are finding it a bit overgrown. Some things are turning up there - like cars." They make a great instructor duo.

Then we had an analyst panel, moderated by John Pescatore @john_pescatore and including Bob Lockhart, Sid Snitkin and myself.  It seemed to go pretty well.

Eric Byres @tofinosecurity followed by thoroughly excoriating the concept of patching ICS systems and transitioned to a tour-de-force explanation of deep packet inspection (DPI) that, like a good Bugs Bunny cartoon, communicated on many levels.  Meaning: I think I understood most of it, but the more experienced folks around me seemed to get insights from it as well.

The presentation by Marc Ayala @ICS_SCADA and Eric Forner demonstrated an attack on a mini water pump which turned the stage momentarily into Sea World, serving as a warm-up act for Kyle Wilhoit's @lowcalspam real-world honey pot presentation the next day documenting how global bad guys pursued what they believed to be the control system of a far more substantial pump, constructed by Kyle, at a municipal water tower. We all learned a lot from these two presos.

Nadya Bartol @NadyaBartol presented on ICS supply chain security issues and by the time she was done, the scope and complexity of supply chain challenges to ICS became all-too-clear.  Ernie Hayden, sitting next to me, tried to lighten my mood by informing me that there are 127 BIOS vendors alone.

I missed the presentation on the new Global Industrial Cyber Security Professional (GISCP) certification, but in case you did too, I've put a link to it HERE.

The first presentation I made it to on day 2 was "Cybersecuring DoD Industrial Control Systems", during which Michael Chipley provided more content, pound for pound, than all of Monday's presenters combined. Each of his many slides was a universe in and of itself, and there were a multiverse of them. But that's the DoD we know and love, and Michael did a great job of plotting its progress, in which he plays no small part, from DITSCAP to DIACAP to the NIST CSF structure in which they're inserting, among other other things, the most up-to-date guidance on control system security.  As masterful conference MC & Chairman Michael Assante said afterwards, "leave it to DoD to build a model where elevators and anti-ballistic missile systems are in the same category."

I had a good lobby talk after that preso with Michael and Chris Blask @chrisblask. We were keying on how the I in ICS serves to exclude a big chunk of the systems and devices we all care about, and mused on whether the term would eventually transition to something more all-encompassing like Cyber Physical Systems (CPS), Internet of Things (IoT, though that's not quite right) or simply, control systems.

Then we had another panel session, this one on the framework of the moment, the NIST Cybersecurity Framework and its relationship to DOE's Risk Management Process guide and C2M2 family. The group included Ed Goff, Jason Christopher @jdchristopher and substituting for the snowed-in Samara Moore, Nadya Bartol. These three did a great job and now we all understand perfectly how these guidance documents fit together. Moderator Michael Assante pointed out, more than once, that Nadya's cogent and succinct statements qualified her for service in the Executive branch of government.

Air Force Lieutenant and famous writer Robert M. Lee @RobertMLee, author of the I-call-'em-like-I-see-'em 2013 article "The Failing of Air Force Cyber," and its companion piece SCADA and Me: a Book for Children and Managers, basically stole the show at this point. Not an expert, but rather a "lifelong learner," Rob reviewed the book's simple messages, and highlighted some of the more disturbing reactions to it, including:
  • A Pentagon General who told him "I keep your book on my desk and share it with management." Which led Rob to suggest to the SANS audience: "At some point in your career you must admit that YOU ARE MANAGEMENT." 
  • He also shared a one-star Amazon review along the lines of "I've been a nuclear engineer for 10 years and I got nothing out of this book."

Towards the end,  Rob said the book has been translated into multiple languages and then flashed the cover of SCADA y Yo: Un Libro Para Niños Y Directores. I'm not sure why that was so funny, but it sure was.

I mentioned Kyle's talk earlier, so that brings us to the penultimate preso, Stacy Cannady's overview of how OEM's can improve the integrity of their products despite the many threats they face, and vulnerabilities they can't help but include. It was very well done.

Of my own preso on Security Governance at utilities, all I can say is I wish it went more smoothly.  I should have known better, following a presentation on trusting and not trusting devices, that the slide-advancing pointer in my hand might turn against me.  I've got a solution though: I'm going to cut my slide count from 30 to 1, and who knows, maybe 1 is 1 too many these days.

I highly recommend you block off your calendar for the 10th annual version of this event next year. It's going to be on 1 April or thereabouts if I heard Mike right. This one was more educational and more fun than any conference I've been at in recent memory.

Andy @andybochman




ICS Electric Utility Attack Video and Aegis to the Rescue


SANS Securing the Human - ICS Attacker
The excellent security-mined people at the SANS Institute have produced an 8 minute video that walks you through a control systems attack.  The money they saved by using animation instead of Matt Damon or Morgan Freeman was put to good use as you'll see. For such an esoteric subject, this is a first rate video. For more info please visit the Securing the Human site at http://www.securingthehuman.org/

Meanwhile, to calm you down after the video gets your heart rate up, you should start learning about a new tool that's set for release at the upcoming SANS SCADA Summit. It's called Aegis and it's not an anti-ballistic missile system.  It's a testing tool to help ensure systems communicating with one of the most common SCADA and controls systems communications protocols, DNP3, are harder to attack.

You can ready more about Aegis here: http://www.automatak.com/aegis/

And more about the SANS ICS Summit here: http://www.sans.org/event/north-american-ics-scada-summit-2014

Sandia and Hayden on Cybersecurity Strategies for Microgrids

First off, thanks to friend and colleague Ernie Hayden for writing a microgrid security post following his mini-immersion in the topic last week.  You can read his write-up HERE.

In particular, want you to see something he linked to: SNL's Microgrid Cybersecurity Reference Architecture.  That's Sandia National Labs, btw, not Saturday Night Live; talented though he is, Jimmy Fallon is not a contributor to this piece.



Note: the microgrid concept described by Sandia is principally for energy security in DOD use cases, for emergency fall-back scenarios. Not necessarily for improving day-to-day operations or achieving efficiencies or cost savings, though you get some of those as part of this.

An excerpt from the Executive Summary makes that concept clear:
The design of a microgrid control system needs to be more robust than that of a traditional industrial control system (ICS) for the following reasons:
  • The microgrid is used in emergency situations and may be critical to continuity of operations of an installation 
  • The microgrid must function during active attack by a capable adversary.
As such, the traditional design and implementation for an ICS may not be sufficient for implementing a robust and secure microgrid.
Of course, there are an increasing number of non-military microgrid use cases and a burgeoning technology and integration market that supports them. But my guess is all those civilian applications should go to school on how Sandia and the DOD are hardening theirs, and select from among those approaches security that's right for their own risk tolerance objectives.

Because Excercise is Good for US, GridEx II is Coming


In case you've been wondering what kind of shape our North American grid incident response and information sharing system is in, now's your chance to find out.  You can click HERE for more details on what's coming up and register to participate if you're an asset owner one of the other types of orgs that have an official role to play.
  • When: 13-14 November
  • Where: North America
  • Dress: Business Casual
While you're here, here are a few other items of possible interest:
  • You can read a decent GridEx II intro HERE, from the NYTimes
  • Findings and recommendations from the first GridEx begin on page 10 of the After Action Report
  • Click HERE for news on a recent disruptive control system cyber attack on a tunnel traffic system in Israel
Poster image courtesy of Crossfit.com

Wrap Up: The 13th Annual ICS Cybersecurity Conference

Another Industrial Control Systems Cybersecurity conference is behind us and, as usual, as documented by founder Joe Weiss, there were signs of a slow awakening to the importance of this topic, mixed with persistent inertia.

You can read highlights from first two days HERE, and Joe's final day summary HERE.

It was nice to hear that my friend (and very good guy) Johan Rambi from large utility Alliander (based in The Netherlands) was playing such an active role.  And this note below reminds everyone that ICS security is not only an energy or power sector problem.  As Joe tells it:
Jeffrey Smith from American Axle gave a great presentation about how they have secured (or very significantly improved security) in their factories world-wide. What I felt was so important is their focus was on productivity and worker safety. Security was simply a threat that needed to be addressed so they could operate safely and efficiently.
This is reminiscent of others who point to the two goals one finds most highly valued in a power co, reliability and safety, and urge the security community to tie physical and cybersecurity tightly to those domains from messaging and business case perspectives.

Security practices are funded and run not merely to check compliance boxes, but to give businesses and government orgs Confidentiality, Integrity, and Availability (CIA) for their systems, networks, apps and data ... so they can continue to pursue their missions with confidence and efficiency.

Or to call out a potential ICS-specific update to the perennial security triad the conference produced: adding O for Operational Controls.  For this very important and highly specialized domain, it might make sense to reverse the prioritized order of CIA and get the O in there too: AIOC.  Ayy-Awk.

Conference Alert: FIRST Energy Symposium - Energy Sector Incident Response


Sorry for the late announcement, but in the spirit of better late than never ...

In cooperation with ISC2, ICS-ISAC and EnergySec, the Forum of Incident Response and Security Teams (FIRST) brings you its first energy sector focused event.

As the FIRST folks put it:
This conference will bring together computer security incident response and security team professionals from all over the world and provide a forum for experts to promote, share, and discuss issues relating to developments in the field of Incident Response relating to the Energy Sector.
When: 28 + 29 October, 2013

Where: Lansdowne resort, Leesburg, VA (Not be be confused with Lansdowne Street in Boston)

To register: Click HERE (Save $100 using this code: Energy13)

BONUS: the agenda shows presentations by Jack Whitsitt and Chris Blask. If you don't know them, they are two of the more brilliant and idiosyncratic personalities in the business.  Worth the price of admission alone, IMHO.

Heads-Up: The 2013 ICS Cybersecurity Summit is Closing In


We talked about this conference and many of its concerns a few weeks ago at the EnergySec Summit, and among things, got a great presentation showing how one utility has built and gotten great value from its OT security test-bed.

There's going to be a talk on test-beds plus a bunch of other great presentations at the annual "Joe Weiss" summit, so if you have interest, and the ability to get there,  I highly recommend you do.

Here are the basics:
Dates: 21-24 October 2013 
Venue: Conference location: GTRI Conference Center, 250 14th Street NW, Atlanta, GA 30318 
LINK for more info and to register 
LINK to register
Photo credit: Jomi Thomas Mani @ Flickr.com

Several Scenes from EnergySec Summit 2013

Click for much Gibber ... I mean, bigger
Was in Denver not far from flooded Boulder last week at the 9th annual EnergySec Summit ... my first.  I'm sure we'll be seeing more articles and posts from EnergySec scribes and some of the other 150 or so attendees soon, but wanted to get my observations out.

I missed a number of presentations due to a mid day arrival on Wednesday and missed a few others to field a few intermittent phone calls, but got to hear most of them (my apologies to speakers not covered below).

First off, Patrick Miller and Steve Parker, EnergySec Presidents past and present, were both outstanding ringmasters and herders of wandering speakers.


Great to see Jack @sintixerr, @SharlaArtz, @LisaNCW Carrington and nearly see @Slad3G Griffin. And the amazing Tweetwall (center screen in picture above) facilitated audience participation, both in the room and globally, scrolling thoughtful 140 character contributions and snarky, succinct broadsides on the unsuspecting speakers! Hashtag for a replay of sorts is #ESS13.

Here's a summary of the talks I caught:
  • Andrew Plato (Anitian) on his Rapid Risk Assessment approach, with special and humorous emphasis urging native security speakers to learn and use business language (maybe RosettaStone or Duolingo can help them with this)
  • Julie Soutuyo (Tennessee Valley Authority) shared her experiences helping make TVA, faced with an onslaught of real-world cyber threats while having to address both FISMA and NERC CIP compliance regs, a more resilient organization
  • Russell Thomas (George Mason University) aka @MrMeritology took us through a Texas Heat Wave movie plot of his own creation to illustrate how a balanced scorecard risk management framework could save the day. Look for it in theaters in 2015!
  • Michael Toecker (Digital Bond) aka @mtoecker provoked the crowd with a great talk on bridging the divide between control systems operators and cyber security pro's, and had us ready to see his concepts on a mock up of an actual operator display. Sadly, he said that will have to wait to next time.  Meanwhile, as SpongeBob would say,  you're free to use your IMAGINATION
  • Chris Sistrunk (Entergy) aka @chrissistrunk, an unabashed squirrel lover, showcased his extraordinary SCADA test lab, described how he built it, the many benefits it confers upon his coworkers at Entergy, and gave practical advice on how folks in the audience could jumpstart their own labs projects
  • Jacob Kitchel (Industrial Defender) walked us through a DevOps approach to improving IT operations in control systems environments. He listed many helpful tools along the way, and made mention of ID's tools near the end. Not entirely security related ... and like Chris's before it, the audience seemed to eat it up.
  • Gib Sorebo (SAIC) gave by far the most business oriented talk, focusing on what security practitioners in the audience need to know to better communicate security risks and requirements to their senior leadership, board members, and shareholders. He also described mature governance structures and business-risk based cybersecurity strategies
  • Nadya Bartol (Utility Telecom Council) walked us through an exploration of the mesmerizing complexities of ICS supply chain security and shed some light on emerging tool that may help utilities get a handle on this challenge: IEC 62443 2-4
  • Spencer McIntyre (SecureState) - two key terms in this one for me: Zigbee, the low power networking standard used in AMI smart meters, and its evil twin: KillerBee, a "practice Zigbee exploitation framework". Good discussion on the current state and some of the continuing security issues with smart meters
Lastly, following University of Houston professor, Dr. Art Conklin's energetic opening, I moderated a Town Hall-style discussion on "Workforce Development in the ICS Workplace." We hit a lot of different notes over the course of several hours, and jointly investigated questions on how to build a robust pipeline of skilled operational security (OT) Security practitioners for utilities.  I'll leave you with this image from my preso, which attempts to depict the current cultural and language divide one finds in many utilities. Just so you know, some of us are working hard to finish these bridges!


Got to go now ... Next year's in Austin!

Training Alert: SANS SCADA Security Training


By now you know the drill:
  • When: 16-20 September
  • Where: Las Vegas, NV
  • What: A hands-on SCADA Security course with over 20 exercises and labs that are performed on a portable SCADA lab that contains over 15 different PLCs, RTUs, RF, and telemetry devices. It was designed to bridge the skills sets of Control System Engineers, Technicians, and IT Security professionals
Click HERE to learn more and register.

And use this code to save some dough when you do: SANSICS_SGSB5

Photo credit: zekedawg00 @ Flickr.com

Super Cyber Security Reading: 2Q ICS-CERT Monitor

Unfortunately, the Energy Sector wins this competition over last 12 months

There are few publications you can read that will tell you more about the current state of cyber awareness and attacks on critical infrastructure orgs and systems than this than the Monitor.


Before we go much further, laypersons, get ready for some advanced acronym unpacking.

Published quarterly by the US Department of Homeland Security (DHS), the Industrial Control Systems (ICS) Computer Emergency Response Team (CERT), this 15 page document gives you the latest findings and trends.

There's a lot of goodness is the 2Q issues, but I'm going to show you just a couple paragraphs and call out some key words in bold that'll give you a feel for the overall messages it contains.  Let's see how this works:
Most recently, ICS-CERT has assisted critical infrastructure entities in the energy and critical manufacturing sectors with response to cyber intrusion attempts and compromises related to an emerging cyber threat actor. These incidents have involved common exploitation techniques and readily available tools that have been deployed successfully against many companies to compromise networks.
OK, so far so good. You can see that attackers are succeeding without having to work too hard. Now this with a bit more in bold:
In the first half of fiscal year 2013, ICS-CERT has deployed five (5) onsite teams compared to six (6) in all of fiscal year 2012. Three of the onsites were in the energy sector and two were in the critical manufacturing sector. All of the onsite incident response engagements involved sophisticated threat actors who had successfully compromised and gained access to business networks
While onsite, ICS-CERT analysts examined networks and artifacts to determine if ICS networks were also compromised. Unfortunately, in many cases that analysis was inconclusive because of limited or non-existent logging and forensics data from the ICS network
While cyber security threats to ICS and other systems can feel overwhelming at times, it's important to note that utilities and other user organizations can do a lot to improve their posture, without either breaking the bank or having to hire dozens of Einsteins. ICS-CERT is a great resource, one that I'd hope you can use as much as possible, proactively vs. reactively.

--------------------------

URL for Monitor report

http://ics-cert.us-cert.gov/sites/default/files/ICS-CERT_Monitor_April-June2013.pdf

ICS Lab for Grid Security Research, Training and Demonstrations

In case you're not already tuned into this community, but might want to be, I submit for your review the contents of an email I received yesterday.  It goes like this:
Greetings ICS-ISAC Members and partners! 
The ICS-ISAC and MS-ISAC are partnering with several key Members to create an ICS Security Lab as a shared asset for research, training and demonstrations. Physically hosted in Livermore, CA by Robot Garden the Lab is now in Phase One of procuring equipment and establishing the virtual capabilities that Members can have access to. 
If you are interested in participating in this activity or have equipment that would be of benefit to this endeavor please send a note to ICS-ISAC Chair Chris Blask at chris@ics-isac.org
There is also a LinkedIn group for collaboration at http://www.linkedin.com/groups?home=&gid=4932821&trk=anet_ug_hm&goback=%2Emyg

Acronym Legend:

ICS-ISAC = Industrial Control Systems Information Sharing and Analysis Center

MS-ISAC = Multi-State Information Sharing and Analysis Center


That's all I got.

NatGas Cybersecurity getting a lot more Visibility


Thanks to colleague H. Chantz for spotting this article and sending this way.

As has been the case quite a bit this year, once again we are in the realm of SCADA/Control System security. William Rush of the Gas Technology Institute states it plainly, if somewhat dramatically:
Anyone can blow up a gas pipeline with dynamite. But with this stolen information, if I wanted to blow up not one, but 1,000 compressor stations, I could,” he adds. “I could put the attack vectors in place, let them sit there for years, and set them all off at the same time. I don’t have to worry about getting people physically in place to do the job, I just pull the trigger with one mouse click.
There are no NERC CIPs for the gas industry, but with 25-30% of US electric power and a whole lot of home heating coming from gas, it's time to get moving on better securing this infrastructure.

Pipeline operators, now alerted to the fact that sensitive access control information to important subsystems is in the hands of folks outside the industry (and outside the country it seems), need to get moving. And I'm sure they will, but it's a BIG job.

The whole Christian Science Monitor article is HERE.

Photo credit: War News Updates

Recommended Reading: Industrial Safety and Security Source

3/8/13 Flash update - SGSB reader and contributor Ernie H suggests you visit Joel Langill's www.scadahacker.com site as well to further enrich your budding control systems security knowledge.
--------------------------------

As I've mentioned a few times before, this year I'm working on getting my OT security chops up to speed, and that means getting a lot more familiar with the way SCADA and ICS systems work when they're functioning properly, to better appreciate how they can be exploited when reached by those with impure thoughts and nefarious motives.

To that end I reach out to folks who seem to know more about this part of the world than I do (sadly, a group that must number in the hundreds of millions). I'm not always successful, but when I am, am happy to share my success so you can advance your own understanding, if necessar, as well.


So after a great intro talk, I asked Greg Hale to send me a few words about his site. Not all the articles are my cup of tea, but the fact that they span multiple industries and sometimes discuss security and safety is.

Here's a brief intro for you:
Launched in April 2010, Industrial Safety and Security Source (www.isssource.com) is a web-based information provider devoted solely to keeping manufacturers current on safety, cyber and physical security news, products, features, applications and trends.  
Our mission: To be the one-stop web resource that provides safety and security information to manufacturers that will help them find the right solution to improve the way they do business. Industrial Safety and Security Source is a web site offering news, features, analysis, research, blogs and opinions on safety and security issues within the manufacturing automation market. 
Editor and Founder Gregory Hale has over 30 years in the publishing industry covering manufacturing automation ... and is the co-author of the book, Automation Made Easy: Everything You Wanted to Know About Automation – and Need to Ask.
OK, have at it.

Conference Alert: European Smart Grid Cyber and SCADA Security


The European wing of our global grid security tribe is gathering soon in London. Some great speakers and plenty of utility participation at this one.

Recommend you check it out - here are the basic deets:
  • When: March 11 & 12
  • Where: The Copthorne Tara Hotel, Scarsdale Place, Kensington, London, W8 5SR
  • For more info and registration, click HERE
SGSB point of contact: Jamison Nesbitt, jnesbitt@smi-online.co.uk

Photo credit: Magnet Magazine

The Cybersecurity Crew at Distributech 2013

First off, let me say that for those travelling to San Diego from northern or northeastern USA, or northern Europe or Russia for instance, this conference is worth it simply as a respite from persistent cold temps and dreary midwinter landscapes.

Now this may sound a bit gossipy, but so far, in terms of our small community of energy sector cyber security practitioners, I've already meet up with some old acquaintances and and have met for the first time, face to face, others.

Met up with Liza, Darren, Slade, and has a great talk over dinner with Ernie. Though with Darren it was really just eye contact because by the time my IBM theater preso on security breaches with Steve Dougherty was done, Darren had, Jason Bourne-like, vanished into crowd.

Will get to travel more widely through the exhibit hall today and will craft a more security content-laden post later today or tomorrow, I promise.  Cheers, Andy

Security Double Dutch: Shodan Points out Critical Infrastructure Gaps in the Netherlands


Hat tip to friend and colleague Steve D for shooting this my way.
Security researcher Oscar Koeroo, working for the Dutch nuclear physics institute NIKHEF, found out that national infrastructural systems were listed on Shodan, (a database of cyber security vulnerabilities) and could be easily accessed remotely. Those systems, controlling pumping stations and sluices, are vital for the water management of a large part of the Netherlands. Because a large part of the country lies below sea-level, those systems keep the Dutch feet dry!
I've been to the Netherlands several times and saw the country in the news a lot recently when UberStorm Sandy raised concerns that New York City should perhaps get similar types of protective systems. I can assure you that this is about much more than a preference for dry feet.

Read on to find out how control system search engine Shodan once again reveals what systems are directly connected to the Internet. Warning, it paints a full picture, but it's not a pretty picture, and hopefully you won't find systems in your charge popping up in the findings window!

Here's the complete article from Tofino, replete with lurid details of password mismanagement, accusations, denials and counter-accusations, and that sort of thing. Best keep a Heineken or two handy.

Photo credit: nrc.nl

So Much New SCADA Goodness ... So Few Words on Security


Hat tip to EnergySec's Patrick Miller for finding and tweeting this article so I could find it. Please note before you read this post that it's not intended to be critical of the article it cites. I think it's great and if I didn't have to think about security it would feel like pure, unadulterated progress to me.

The article, "Web-based SCADA Gathers More Fans" which appeared recently in Automation World, describes many excellent new capabilities that are arriving in the SCADA world, many of which are related to new higher bandwidth communications between substations and other remote assets, often based on web technologies. As Honeywell engineer Gerry Browne says:
A few years ago, field equipment would have only a serial port. Today, the same equipment might have its own Web server and methods that expose all its operating parameters. Remote data is now available immediately, allowing users to make better decisions.

What's not to like about that? Examples are drawn from oil and gas and water operations, but the applicability to electric sector use cases, including geographically dispersed substations and renewable generation is clear. Here are a few of the accounts.


Motivations/Benefits
In some cases, a technician would have to book a flight and spend as long as six hours traveling to the site. As a result, updates and service could easily turn into a 3-6 day project, not counting the lead time for booking the flight.
...
Another pain point alleviated by the new architecture is the ability to replicate objects and make global changes. Changing a pop-up screen for the old system, for example, required a programmer to go to every pop-up to make the alteration. Now that pop-ups are global, the programmer need only change one. Every identical screen updates automatically, which can reduce a four-hour job to just five minutes.
...
Rather than sitting in a control room, the operators of these systems are typically in the field, often driving hundreds of miles a day in their pickup trucks. To keep tabs on the system, they access the HMI with a laptop or handheld device just as if they were in a conventional control room. This real-time access allows them to observe any part of the system continuously, day or night, without having to physically go there and look. It also can track pump usage for preventive maintenance and monitor flow rates for legal disputes over water rights.
Tell me if you were one of these workers, or a manager of same, you wouldn't be jumping with joy over these improvements. Of course, you're reading these notes on the Smart Grid Security Blog, so you may be wondering if anyone is going to mention the security considerations in any of this. I give you credit for your insight. Tell you what, let's let the article go first.

Security
Greg Jones, a SCADA and data systems engineer, says the main challenge to safe remote access is establishing procedural controls such that the staff is aware of when changes are being made and what those changes are. Any change that can affect the functioning of facilities or machinery poses a risk to operations and safety. So, there should be only one person in control of a particular part of a SCADA system at any point in time.
OK, that was it, and here we go. First of all, I don't find any fault in Jones' comments. But everything about the information in the article, from the word Web in the title, to the description of how one can "replicate objects and make global changes," to Jones' comment that "the main challenge to safe remote access is establishing procedural controls such that the staff is aware of when changes are being made and what those changes are," gives me the willies. 

There are just too many ways to mis-configure these systems, and way too much potential for human error, to feel that these great functional leaps forward are not at the same time large cybersecurity steps backward. Time will tell and perhaps there are already crack security boutiques working solutions to these challenges. Please tell me if I've got this wrong. I'm often wrong. I'd like to be wrong.

Photo By: Carroll Electric

Thoughts on the Explosive MI6 OT Breach in Skyfall


Have you seen the new 007 movie yet, the third of the series that features Daniel Craig as Bond? Called Skyfall, one of its key plot drivers occurs when the evil mastermind blows up part of British spy headquarters, MI6, in London, with a handful of deft key strokes. By the way, OT in the title of this post = Operational Technology, as differentiated from business information technology or IT.

Stuxnet this is not, but it is clearly depicted as a cyber attack on physical assets, and others who have weighed in on the plausibility/authenticity of this depiction (see HERE and HERE) cannot help but point to Stuxnet as the real world proof of concept.

To free up more time for mayhem, Javier Bardem's well played psychopath might have started with Shodan, the online search engine that helps both good guys and charismatic bad guys quickly locate internet-connected control systems.

The SimplySecurity site provides some good context for all of this:
Between 2005 and early 2010, when Stuxnet was first discovered, analysts observed just nine confirmed ICS or SCADA vulnerabilities. That figure suddenly spiked to 64 vulnerabilities in 2011, while an additional 98 were highlighted in the first eight months of 2012. What's more, 50 of the exploits discovered between 2011 and September 2012 were freely published across cybercriminal forums. As report authors noted, these security loopholes could compromise everything from public transit systems and water supplies to gas pipelines and nuclear power plants. And with more than 40 percent of the observed ICS/SCADA systems containing components that face the open Internet, film fiction could quickly become regrettable reality. Just this month, Chevron became the first U.S. company to admit that its systems had been infected by a mutation of the Stuxnet virus.
Chances are, evil geniuses will have better luck targeting SCADA and control systems in water or gas utilities where cyber security has been given less attention than the British equivalent of the CIA. And should they target environmental control systems in government buildings, it's possible but unlikely that they can cause explosions that will kill multiple persons and create fireballs that will blow the walls off (as above).

Nevertheless, the risks and potential harms involved with operational technology (OT) cybersecurity are substantial, and merit everyone's prompt and continued attention ... right after the next martini, that is.

Photo credit: Business Insider

Conference Alert: Smart Grid & Control Systems Security for Europe


Sometimes I don't give enough lead time, here's a case where maybe I'm giving you too much lead time. Anyway, you know how time flies when you're having fun, so 5 short months from now, you might want to be here:

  • What: 3rd European Smart Grid and SCADA Security Forum
  • Where: The Copthorne Tara Hotel, London
  • When: 11-12 March 2013
  • Web: For more info and to register, click HERE

Good ICS-CERT Guidance for You, Electric Utility Security Pro

Hat tip to Jeff M aka Mr. NISTIR. Surely you've seen reports in the press and, depending who you are, maybe through more official channels, that companies in every sector are under persistent cyber assault these days. The DHS and other US Federal agencies are working overtime (sometimes literally, sometimes figuratively) to keep up.

With our own sector in mind, DHS recently published ICS-CERT Technical Information Paper ICS-TIP-12-146-01A: Targeted Cyber Intrusion Detection and Mitigation Strategies. I think you'll find this material very helpful, no matter what level of technical depth you possess.



They take just ten pages and keep it manageable by not getting too ambitious or detailed:
The guidance is in the form of “what” should be done and “why” it is important. The “how” of implementation is the responsibility of each organization and is dependent on individual needs, network topology, and operational requirements.
Nice done. And then there's this, which future generations of security professionals and risk managers will likely find silly, but that many, even in 2012, still need to hear. But wait, let's go to a sports analogy first: imagine a defensive line in American football playing with blindfolds. Or how about one in military mode: how much would you pay a defense contractor for a missile defense system without sensors to detect incoming hostile missiles? 

OK enough delay; here's the passage I've been trying to get to:
The need for intrusion detection capabilities cannot be overstated. The ability to detect and identify the source and analyze the extent of a compromise is crucial to rapid incident response, minimizing loss, mitigating exploited weaknesses, and restoring services. Early detection of an incident can limit or even prevent possible damage to control systems and reduces the level of effort required to contain, eradicate, and restore affected systems
There's plenty of good guidance that applies equally well to IT and OT systems, and some that's for OT only. Recommend you give the full piece a read; I think you'll like what you see.