Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Perimeter

10/9/2018
04:45 PM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

Constructing the Future of ICS Cybersecurity

As industrial control systems are connected to the cloud and the IoT, experts discuss security challenges.

(ISC)² SECURITY CONGRESS – New Orleans – Technology is accelerating and industry is catching up. As industrial control systems (ICS) are connected to the Internet of Things and send data to the cloud, experts have begun to anticipate the security implications.

The IoT is growing and now it's moving into the industrial space, said Graham Speake, senior ICS manager at Accenture, during a presentation at (ISC)² Security Congress held this week in New Orleans. As it does, security pros have to think about securing the data their systems handle.

"Industry is always a bit slow," he explained, pointing to the oil and gas industry as an example. If you told those firms six to seven years ago that they would be sending data to the cloud, they would have been hesitant to believe you, said Speake. Now, "industry is catching up."

The number of devices is increasing 10% each year, he continued, and the world is expected to have 20+ billion devices by 2020. While many of these connected devices will be for personal use, a growing amount will be seen in industry, where machines are being connected to the cloud and more employees are using wearables, both for productivity and safety.

As an example, Speake described how a device worn by employees could track someone around a plant so people in the control rooms could monitor their location. If someone hasn't moved in a while, it could indicate they're having a problem. If there's an evacuation, such a system would help determine whether anyone is left in a dangerous situation.

"If you think about a large refinery, a large plant, it's even harder to work out who is there, who is left, and where they are," he said. Many industries – Speake points to the chemical sector as an example – are also increasingly turning to robotics as a means of improving efficiency.

However, the connectedness of ICS prompts important questions about security. In industry, for example, it's not unusual for components to have a lifetime of five to 30 years – far longer than average enterprise machines. Software updates are slow to deploy, and devices connected to the industrial IoT (IIoT) are connected to the same networks, leaving them exposed.

There is also the issue of few ICS security experts, explained Ben Miller, director of Dragos' threat operations center, in his presentation, "How to Respond to Industrial Intrusions."

"Not a lot of people are focused on ICS security," he said. "It's usually a process engineer tasked with security, or a security person assigned responsibility for control systems networks." Neither can be fully effective, he noted, as "it takes years to build up the [ICS security] skillset."

It's one of three key challenges industrial organizations face, Miller added. Another is the lack of visibility into ICS environments, and lack of understanding that you can't put IT tools in industrial environments and expect similar outcomes. The biggest hurdle, however, is threats.

We don't yet have a clear idea of the threat landscape in industrial environments, Miller said. Most of our knowledge is anecdotal; there is no large dataset for ICS threats. The lack of data makes security a challenge: you can't allocate resources if you don't know what's targeted.

Organizations have to reconcile their desire to operate in the cloud with their older systems, Speake emphasized, pointing to the history of insecurity within the industrial space.

Consider antivirus: "it works, but it's not going to stop everything," he noted. Same goes for firewalls. Companies often have a mentality "if we connect things to firewalls, we're secure," Speake said, but there are many problems with firewalls – "namely, whoever configures them."

Passwords are another example. In IT, admins advocate setting complex passwords and changing them often. Employees handling ICS often don't use passwords because they know who's on the floor handling machines and assume their systems are secure from outsiders.

There is also lack of product testing or security training among vendors, which prioritize speed.

"Vendors in the space, we were more interested in getting products out into the marketplace than trying to build security and build resiliency," he added. "The problem with vendors is, they don't train people in security." And while some are starting to, "it's a few years late," he noted.

Speake advised building security in from the start so systems are protected by default. This means testing devices and evaluating not only how robust communications are, but how secure they are. If you have to demand a certain level of security and threaten to switch vendors if it's not provided, he encouraged doing do.

Procurement documents should say "I want this level of security," he explained. "If you can't meet it, then come back to me when you can."

Related Content:

 

 

 

Black Hat Europe returns to London Dec 3-6 2018  with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions and service providers in the Business Hall. Click for information on the conference and to register.

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
plee560
100%
0%
plee560,
User Rank: Apprentice
10/12/2018 | 5:45:56 PM
The FAIR Institute conducted a case study on how to quantify ICS-related cyber risk

Demystifying ICS Cyber Risk with FAIR


https://www.fairinstitute.org/blog/case-study-demystifying-ics-cyber-risk-with-fair
COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/13/2020
Omdia Research Launches Page on Dark Reading
Tim Wilson, Editor in Chief, Dark Reading 7/9/2020
Russian Cyber Gang 'Cosmic Lynx' Focuses on Email Fraud
Kelly Sheridan, Staff Editor, Dark Reading,  7/7/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-11749
PUBLISHED: 2020-07-13
Pandora FMS 7.0 NG <= 746 suffers from Multiple XSS vulnerabilities in different browser views. A network administrator scanning a SNMP device can trigger a Cross Site Scripting (XSS), which can run arbitrary code to allow Remote Code Execution as root or apache2.
CVE-2020-5766
PUBLISHED: 2020-07-13
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in SRS Simple Hits Counter Plugin for WordPress 1.0.3 and 1.0.4 allows a remote, unauthenticated attacker to determine the value of database fields.
CVE-2020-15689
PUBLISHED: 2020-07-13
Appweb before 7.2.2 and 8.x before 8.1.0, when built with CGI support, mishandles an HTTP request with a Range header that lacks an exact range. This may result in a NULL pointer dereference and cause a denial of service.
CVE-2019-4591
PUBLISHED: 2020-07-13
IBM Maximo Asset Management 7.6.0 and 7.6.1 does not invalidate session after logout which could allow a local user to impersonate another user on the system. IBM X-Force ID: 167451.
CVE-2019-20907
PUBLISHED: 2020-07-13
In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.