Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Look, But Don't Touch: One Key to Better ICS Security
Newest First  |  Oldest First  |  Threaded View
User Rank: Apprentice
7/2/2017 | 1:05:19 AM
Look, But Don't Touch: One Key to Better ICS Security
As a doctor, if you don't trust your temperature and blood pressure readings, you cannot make a diagnosis.

Currently, many people equate network anomaly detection (malware) to cyber security. Moreover, many people associate network anomalies to physical process anomalies. However because of the lack of authenticated, secured process sensing (e.g., pressure, level, flow, temperature, voltage, current, radiation, etc.), it is not possible to correlate physical process anomalies (e.g., changes in boiler temperature, pipe pressure, tank level, voltage, etc.) to network anomaly detection (e.g., malware, network packet compromise, etc.). Since network monitoring programs can only interrogate network packets, any changes to process sensing before they become packets can NOT be detected by network monitoring solutions. The lack of correlating network anomalies to process anomalies has led to self-inflicted denial-of-service disruptions.

The solution to this glaring gap in control system cyber security due to insecure process sensing is to detect changes in process sensing BEFORE the sensor information goes through the serial-to-Ethernet converters. Issues caused by the compromise of the sensors before the serial-to-Ethernet converters would NOT be identified through network monitoring. This is important as it is possible to compromise the sensor output before the serial-to-Ethernet converters particularly as these converters have been hacked in the U.S. and Ukraine to deliver the Black Energy malware.

Possible impacts of compromised sensor data include the inability to reach a setpoint (e.g., safety valves or protective relays not opening damaging equipment), inadvertently reaching a setpoint (e.g., plant shutdowns or electric outages), providing misleading information to the HMI (e.g., having the operator take the wrong actions), or compromising controllers or actuators, etc. June 13, 2017, I gave a presentation on "The Implications of the Ukrainian Cyber Attacks to Nuclear Plants" to the American Nuclear Society in San Francisco which explicitly addressed these issues.

I believe that having an informed decision as to when to shut down a physical process occurs when you have a view of the actual process via the raw process sensing. This is because the raw process sensing will indicate a process change regardless if the change is from unintentional or malicious reasons. Moreover, viewing the raw process is independent of network cyber considerations. Given how sophisticated hackers are able to bypass cyber security protections such as CrashOverride, viewing the raw process becomes even more important.

 Joe Weiss

I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Current Issue
Creating an Effective Incident Response Plan
Security teams are realizing their organizations will experience a cyber incident at some point. An effective incident response plan that takes into account their specific requirements and has been tested is critical. This issue of Tech Insights also includes: -a look at the newly signed cyber-incident law, -how organizations can apply behavioral psychology to incident response, -and an overview of the Open Cybersecurity Schema Framework.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2022-11-28
Velneo vClient on its 28.1.3 version, could allow an attacker with knowledge of the victims's username and hashed password to spoof the victim's id against the server.
PUBLISHED: 2022-11-28
Poultry Farm Management System v1.0 contains a SQL injection vulnerability via the del parameter at /Redcock-Farm/farm/category.php.
PUBLISHED: 2022-11-28
An issue in the component MSI.TerminalServer.exe of MSI Center v1.0.41.0 allows attackers to escalate privileges via a crafted TCP packet.
PUBLISHED: 2022-11-28
The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. This issue has been corrected in version 0.4.9. There are no workarounds other than upgrading to a fixed version.
PUBLISHED: 2022-11-28
Discourse is an open-source discussion platform. Prior to version 2.9.0.beta13, users can post chat messages of an unlimited length, which can cause a denial of service for other users when posting huge amounts of text. Users should upgrade to version 2.9.0.beta13, where a limit has been introduced....