Showing posts with label critical infrastructure news. Show all posts
Showing posts with label critical infrastructure news. Show all posts

Tuesday, February 16, 2016

January news roundup: Ukraine power grid cyberattack illuminates risk to critical infrastructure

It’s no surprise the cyberattack on Ukraine’s power grid dominated industrial control system (ICS) cybersecurity news in January. Following the news of the power outages and subsequent discovery of malware and other signs of a purposeful network intrusion, cybersecurity experts, DHS and others have revealed alarming instances of cyberattacks, increasing vulnerabilities and lack of adequate cyberdefenses at industrial and nuclear sites, dams and other critical infrastructure. Perhaps the Ukraine attack is the wake up call the industry needs to escalate its investment in cybersecurity protections, such as Unidirectional Security Gateways. In the meantime, learn more in our roundup of these stories below.

With all security eyes on the Ukraine’s Prykarpattyaoblenergo utility, SANS ICS concluded hackers likely caused the outage by remotely switching breakers, after installing malware that prevented technicians from detecting the intrusion. The key takeaway is that malware may have enabled the attack, but it was hackers’ remote access to critical operational networks that resulted in the outage. 

While presenting at the S4x16 conference in Miami, Marty Edwards, head of the DHS ICS-CERT, cited increased Internet connectivity and associated vulnerabilities as the main reason behind the rise in cyberattacks on ICS networks. Others aren’t convinced, believing the recent Ukraine power grid attack has prompted authorities to look for signs of intrusion that may not necessarily be intentionally harmful events. From our perspective, any external intrusion – or even attempted intrusion – of ICSs is potentially harmful and should be taken seriously. Further, there is no doubt whatsoever that connecting critical infrastructure directly to the Internet or indirectly to Internet-accessible networks creates significant vulnerabilities.

According to a distressing report by the Nuclear Threat Initiative, 20 nations have no apparent government regulations requiring minimal protection of nuclear power plants or atomic stockpiles against cyberattacks. The U.S. and many other countries have adopted strong security postures including physical security measures, removable device controls, and Unidirectional Security Gateways. This is standard practice in many jurisdictions and is something that should become standard worldwide for nuclear facilities.

In this article, industry experts, Paul Feldman, director of Midcontinent ISO, and Dan Hill, board member for the New York ISO, explore the new threats to our power systems. They point out that cybercriminal sophistication has outpaced the resulting regulations and urge the Federal Energy Regulatory Commission (FERC) and the North American Electric Reliability Corporation (NERC) to establish industry regulations that reflect the current threat landscape. Hill and Feldman point out that adequate, modern ICS security is very different from doing the minimum to be in compliance and recommend the use of unidirectional security gateways to eliminate the threat of remote-control and other network attacks from business networks and from the Internet.

Rob Joyce, chief of the NSA’s Tailored Access Operations unit, shook up the SCADA security community when he stated, “SCADA security is something that keeps me up at night.” Referring to the thousands of ICSs, such as power plants and other critical infrastructure, that are connected to the Internet without proper protections in place, Joyce singled out heating and cooling systems as examples that nation-state hackers can use to infiltrate control systems. He knows this to be true since these same systems are used as points of ingress by his own team. As alarming as this seems, it’s the reality we face as more and more industrial control systems are connected to the Internet.

To learn more about the risks facing industrial control security networks, visit our resources page.

Friday, January 22, 2016

Electric sector security leaders Paul Feldman and Dan Hill recommend unidirectional gateways

Paul Feldman, director of Midcontinent ISO, and Dan Hill, board member for the New York ISO, recently published “Cybersecurity: IT vs. OT, and the Pursuit of Best Practices” in the January 2016 edition of Electricity Policy. The article reviews the state of control system security in the power grid and makes recommendations to improve security. A central recommendation in the article is that “it’s time for transmission and distribution companies to install unidirectional gateways between their SCADA/OT networks and their business networks.” At Waterfall Security, we are steadfast in maintaining that increased use of unidirectional security gateways will measurably improve the security and the reliability of the Bulk Electric System. It is rewarding to see these experts agree.

In their article, Hill and Feldman review ongoing efforts by the Federal Energy Regulatory Commission (FERC) and the North American Electric Reliability Corporation (NERC) to have industry regulations reflect the current threat landscape.  The authors point out that cybercriminal sophistication has outpaced the resulting regulations, and observe that:

“(A) special methodology to bridge IT and OT/ICS systems is now required in all nuclear plants,” the two authors wrote. “That methodology employs a hardware-based unidirectional gateway … to move data from the OT/ICS network to the IT/business network on a real-time basis.”

The article goes on to explain that using a unidirectional security gateway eliminates the threat of network attacks moving from an IT network into an industrial control system (ICS) network.

“Firewalls are also becoming more sophisticated and more complicated to manage,” the authors write. They continue, pointing out that “It’s an arms race between the firewall providers and attackers. Separate from the arms race, but related to whether the good guys or the bad guys can develop sophisticated software faster, there is also the bug issue. Firewalls are enabled by software, and software often contains bugs.” Firewalls are simply not adequate to deflect modern attacks on industrial control systems.


Hill and Feldman point out that adequate, modern ICS security is very different from doing the minimum to avoid a fine.  Unidirectional security gateways eliminate the threat of remote-control and other network attacks from business networks and from the Internet. Eliminating these threats entirely is far more effective than continuing a cat-and-mouse battle with attackers.

Friday, January 15, 2016

December news roundup: Aging infrastructure and foreign hackers mark the end of 2015

December’s cybersecurity news further illustrated the reality that foreign state hackers are targeting U.S. critical infrastructure. Of greater concern is the fact that much of our infrastructure security is inadequate to protect against a targeted attack. With outdated security and the growing adoption of the Industrial Internet of Things (IIoT), power grids, dams and other critical infrastructure are at increased risk of a successful network intrusion. Will recent legislation provide the protections needed to improve cybersecurity for critical infrastructure, or is it too little, too late? Read on to learn more about the news and events that capped 2015 and set the tone for the New Year.

Cyber protection a priority for GPS (The Hill, Dec. 4, 2015)
To most, GPS is a useful technology that helps us navigate unfamiliar roads, but GPS has become the backbone of our virtual infrastructure. It is widely used in military operations and controls and provides critical timing functions to ensure control over our power infrastructure. And, according to USAF Col. Brian Searcy (ret.), our global positioning system is a prime target for cybercriminals or nation state adversaries.

The House unanimously passed a bill to provide state and local governments with federal resources to fight cybercrime. The bill would direct the Department of Homeland Security’s (DHS) cyber hub — known as the National Cybersecurity and Communications Integration Center (NCCIC) — to provide state and local governments with technical training and strategic guidance to help bolster their cyber defenses. The bill is now awaiting a vote in the Senate.

RSA president, Amit Yoran, shared his insights and outlook for the security landscape in 2016. Of note, Yoran believes a critical breach of an ICS network is increasingly likely to occur in 2016. As we at Waterfall have cautioned for years, many ICS security systems are inadequate to prevent against targeted cyberattacks. And now as IIoT, remote access and automated workflows gain adoption within these critical networks, they are growing increasingly vulnerable to outside attacks. And, as Yoran notes, the potential impact of bringing down a power facility or water treatment plant is an attractive proposition for those who wish to do us harm.

The results of a year-long investigation by the Associated Press, underscore the very real concerns security experts have been warning about for years: foreign hackers are targeting U.S. critical infrastructures, with some success. According to the AP report, about a dozen times in the last decade, sophisticated foreign hackers have gained enough remote access to control power grid operations networks.

According to a former official the hack of Bowman Avenue Dam near Rye Brook, New York in 2013, was a test by Iranian hackers who managed to get control of the dam’s floodgates. News of the attack highlights a growing concern among security experts about the susceptibility of infrastructure operated by outdated or retrofit technology. Until owners of critical infrastructure commit to upgrading their security posture, they will remain vulnerable to these foreign state hacker groups.
From our perspective, any legislation that moves cybersecurity preparedness forward for all industrial control networks is a good thing, but its success depends on complete support from the private sector, including privately owned critical infrastructure. Thus far, the response on the part of many executives has the cybersecurity experts at Waterfall concerned, particularly given the recent evidence that current IT-based security has been repeatedly compromised. At Waterfall, we remain dedicated to educating the market on these vulnerabilities and the dire need for hardware enforced unidirectional gateways.


To learn more about the risks facing industrial control security networks, visit our resources page.

Wednesday, December 9, 2015

November news roundup: Why the energy sector is at the heart of cybersecurity discussions

In the wake of the ISIS-perpetrated Paris attacks and cyber threats against the U.K., government agencies are stepping up cybersecurity in a bid to detect and defend their critical infrastructure against a cyberattack by ISIS or other hacker groups. At the top of that list is the energy sector. Cybersecurity leaders from several countries have stated their concerns about a cyberattack against the power grid, refineries and oil or gas pipelines, and many of these infrastructures show serious vulnerabilities. For more on these and other stories that captured our attention last month, see our news roundup below. 

Marty Edwards, head of the U.S. Industrial Control Systems Cyber Emergency Response Team (ICS-CERT), recently spoke with Control Design about security vulnerabilities with IIoT. From unsecured Ethernet on system processors to using store-bought DSL routers to remotely monitor system remote facilities to BYOD, vulnerabilities are rampant. Edwards advises control systems designers to carefully weigh the advantages of connectivity against the potential risks.

Mixing ERP and production systems: Oil industry at risk, say infosec bods (TheRegister, Nov. 18, 2015) Security researchers from ERPScan described at Black Hat Europe how to hack into SAP systems and launch attacks at and take over industrial control systems in the oil and gas sector. “…insecure setups might be exploited to interfere with operational processes and lead to disruptions in production or even sabotage.” This is possible because there is a connection between the control system network and the ERP system through a firewall.

Michel Coulombe, director the Canadian Security Intelligence Service (CSIS), revealed his view that a cyberattack by ISIS or other extremist groups on the country's "critical infrastructure" is "a major threat;” however, others point to major gaps in Canada’s cybersecurity strategy, specifically related o critical infrastructure, such as pipelines.

According to a new report by the Government Accountability Office (GAO), of the 15 critical infrastructures examined, 12 were overseen by agencies without proper cybersecurity metrics or formal methods to essential to protect networks from cyberattacks. These findings may add fuel to the argument that critical infrastructure industries should be required to share cybersecurity data with the government.

The Defense Advanced Research Projects Agency (DARPA) announced the development of a new system designed to support the nation’s electric grid defenses. Called Rapid Attack Detection, Isolation and Characterization (RADICS), the system will detect and automatically respond to cyberattacks on U.S. critical infrastructure. Exact details of what the RADICS system will entail were not disclosed, but the agency will hold a Proposers Day on Dec. 14 to detail it further.


If we’ve learned nothing else in this business, it’s that cyber capabilities evolve slowly. Motive, however, can change in an instant. For organizations like ISIS, motive is in strong supply and the cyberattack capabilities necessary to wreak real havoc can be bought. We cannot sit idle while ISIS or other groups plot against our most critical infrastructures. Our very way of life depends on them.

For more on how our better-than-firewalls unidirectional gateway technology can improve critical infrastructure security, visit our resources page.