• No results found

CONTROL SYSTEM CYBER SECURITY

N/A
N/A
Protected

Academic year: 2021

Share "CONTROL SYSTEM CYBER SECURITY"

Copied!
43
0
0

Loading.... (view fulltext now)

Full text

(1)

CONTROL SYSTEM CYBER SECURITY

What can Operators do to keep their control system safe

Presented by:

Bart Nelissen Proud of Our Past… Building the Future

(2)

Introduction

Control System Components

Statistics

Myths

Threats

Examples

Recommendations

(3)

Bart Nelissen

MPE Engineering

Cyber Security

NIST

Public Safety Canada

US Department of Homeland Security

Cyber Warfare

(4)
(5)
(6)

Over 50 new Cyber Security Threats reported… DAILY

Over 80% of vulnerabilities involved outdated software

Water & Wastewater is one of the hardest hit sectors – 122% increase in attacks in one year

Over 50% of companies realize the need for more resources for OT / ICS Cyber Security

15% of companies are increasing operator awareness training

99% of firewall breaches are result of misconfiguration

Based on Claroty BiAnnual ICS Risk & Vulnerability Report and 2019 Kaspersky ICS report

(7)

Based on 2021 ISA GCA International Society of Automation Global Cybersecurity Alliance) report

(8)

Isolation from the internet keeps the control system safe

IF implemented and maintained, air gap is effective

Not practical

Restricts alarm callouts from SCADA

Restricts remote access

Restricts report generation

Restricts technology advancement

Memory sticks – Major risk !

Myths based on 2021 ISA GCA International Society of Automation Global Cybersecurity Alliance) report

(9)

Hackers don’t understand ICS components, networks and communication

96% of applications use open-source components

Modern control systems use common IT infrastructure

EtherNet

Remote Access ; Remote Desktop Protocol (RDP), Secure Socket Layer (SSL), etc.

(10)

The ICS network will be protected by our firewall

Need to be configured properly (rules)

Requires monitoring and maintenance

Firewall is only as good as the device itself

Firewalls do not protect against allowed protocols or access (e.g. open ports)

(11)

Serial Communication provide immunity from Cyber Attacks

Serial communication is known to hackers

Many serial communication links are over EtherNet or use converters

No protection from inside hacks

(12)

Hackers are only after financial gains, not ICS

Based on Canadian Centre for Cyber Security

(13)
(14)

Internal Threats

Internal unrestricted access

Deliberate or undeliberate

External Threats

Disruption

Damage

Human Error

Incorrect configuration

(15)

Ransomware

Malicious software

Infects a computer

Restricts access

Ransom paid will unlock access

(16)

Denial of Service

Floods traffic

Makes computer unavailable

Distributed Denial of Service

Hits several computers

(17)

Man in the Middle

“Eavesdropping attack”

Attacker inserts themselves in between 2 parties

Steals and / or filters data

(18)

Zero Day Exploit

Attack on known vulnerability

Identified by vendor

Patch not deployed yet

(19)

Phishing

Faking a reputable source

Steal data

Install malware

Most known to steal credit card info

What is a hacker’s favorite season ?

Phishing season

(20)
(21)

Oldsmar, FL WTP

February 2021

14,000 Residents

Compromised Remote Access

Windows 7 and TeamViewer

Poor user credential requirements

Poor architecture

(22)

Stuxnet

2010 – “world’s first digital weapon”

Malware - USB drives

Estimated 5 years to develop

Target Siemens STEP7 PLCs

Override setpoints in PLC & values on HMI

Nuclear Power Plant centrifuge damage; close to 1000 / 20% of Iran’s centrifuges

(23)

Kansas WTP

March 2019

1,500 households

Poor User Credentials – ex-employee

Unauthorized access – files removed related to disinfect cycle

(24)

San Francisco Bay WTP

January 2021

Poor User Credentials

Poor Architecture

Boston Water and Sewer Commission 2020

Harrisburg, PA WTP 2006

Camrosa, CA WTP 2020

No details disclosed

(25)

Based on real world experience by Bart…

(26)

Back up

Applications

Data

Second backup Off Site

Office

Cloud

(27)

User Credentials

Keep current – only active users

Integrate with IT / HR if possible

Unique per user

(28)

Unique Passwords

Do not allow multiple users the same password

Set criteria

Remove default passwords of equipment

(29)

‘Backdoors’

Access that’s typically undocumented

operations

maintenance

Close backdoors

Investigate

(30)

Anti-Virus Software

Ensure software is supported

By organization

For all software

For architecture (ICS)

Is proven

Updates frequently

(31)

Updates and Patches

Schedule regular updates

Critical Updates immediately

Supported updates and patches only – for all software

Test updates and patches

Test environment

Production environment

(32)

Secure Physical Access

Lock gates

Doors

Log out of PCs

Inactivity timeout

Consider cameras

(33)

Firewalls

Device to block unauthorized access

Network or device

Configure firewalls

Maintain firewalls

(34)

Whitelisting

Opposite of Blacklisting

All traffic is accepted

Requires unique access to be blocked

All traffic is denied by default

Only allow authorized access

Requires maintenance

(35)

Monitor Network Activity

Detects strange behaviour

Detects unauthorized access

Detects new devices on network

Set up rules to alarm

Alarm require action

(36)

Secure Remote Access

Modern technology

Not TeamViewer

VPN (Virtual Private Network)

SSL (Secure Socket Layer)

(37)
(38)

External devices

USB sticks / thumb drives / external hard drives

Laptops

Vendors

Scan

(39)

Training

ICS: Operators

Recognize

Intrusion Detection

Action response

(40)

Tender Documents

Remove Specifics

IP Addresses

Server names

(41)

ICS / SCADA use

Process control only

No internet

No report

No e-mail

No games

(42)

Establish ICS Cyber Security Policy

Incorporate all recommendations

Incorporate IT practises

User credentials

Tie to HR

Violation

Use experts

(43)

Bart Nelissen

MPE Engineering [email protected] 250-268-5008

References

Related documents