Security Monitoring & Intrusion Detection
Yesterday I gave a presentation to about 200 SCADA users at the Telvent User Group Conference. It always is a pleasure to talk to and learn from actual end users of these systems. My presentation focused on adapting security monitoring and intrusion detection for process control networks.
Why monitor the cyber security of your SCADA network? For the same reason you have cameras, security guards, and alarms monitor your physical security – - to identify and stop intrusions. Classic IT security monitoring includes realtime log review for firewalls and servers and network based intrusion detection systems (NIDS). These NIDS will identify attacks such as hacker scanning, worms, denial of service attacks, and other published vulnerabilities and attacks.
Security monitoring requires a team of highly skilled IT security experts and sophisticated correlation software. Most organizations find it much more cost effective to outsource this monitoring to a third party managed security service provider (MSSP). We are frequently updating our analysis of MSSP offerings, and the good news is there are a number of great solutions available. Cyber security monitoring is happening today in leading edge critical infrastructure organizations, and the results are impressive.
So what is different with SCADA networks? Two things.
First, the SCADA application logs have a wealth of information to be added to the solution. These logs include entries for elevation of privileges, database and display changes, bringing sensors on and off line, failed login attempts, and much more. The MSSPs need to understand these logs and incorporate the security events into their processes and correlation software.
Second, the NIDS need to identify attacks related to the process control protocols such as Modbus. We have an active research project working on this issue, and we should be issuing some additional information and sample code in the next six months. Contact me, peterson@digitalbond.com, if you are interested in participating.
Author: Dale Peterson
Posted: October 1st, 2003 under IDS / IPS.
Comments: 1
Comments
Comment from Hassan
Time: March 21, 2007, 12:33 pm
Greetings!
It seems like we are working on the same type of things. I am integrating the same skills and tools that we use on the IT side of the house to provide protection in the SCADA environment. I’d like to know what kind of systems and logs that I need to request from the SCADA folks. If the systems that hold the bulk of the SCADA info are standard IT systems, then you are right… I just need access to it. Your help would be appreciated.
Thanks
Write a comment