Archive for March, 2004
DHS Research Project!!!
I’m thrilled to announce Digital Bond has received a research grant from DHS to pursue our investigation of Intrusion Detection and Security Monitoring of SCADA Networks. It is a Phase I Small Business Innovation Research (SBIR) contract from the Homeland Security Advanced Research Project Agency (HSARPA).
Loyal readers of this blog know this [...]
Author: Dale Peterson
Posted: March 28th, 2004 under Uncategorized.
Comments: none
Different Security Levels For Different Industries?
I was talking with Holly Beum of Interface Technologies about the Control Center Protection Profile, and she raised a simple question. Do all process control industries require this high-level of security? The short answer is of course not. Here is Holly’s attempt at starting a security level matrix.
High:
Product Controlled: Critical Infrastructure, [...]
Author: Dale Peterson
Posted: March 22nd, 2004 under Uncategorized.
Comments: none
Engineers Come Home Again
I had the honor last week to speak at the first Regional IT Security Summit put on by Jamaica’s Central IT Office (CITO). Over 250 IT professionals gathered from throughout the Caribbean, and it was a very impressive event.
My keynote topic was Securing The Critical Infrastructure From Cyber Attacks. This is a common [...]
Author: Dale Peterson
Posted: March 22nd, 2004 under Uncategorized.
Comments: none
IT Dept., Operations, and the Florida Elections
Digital Bond is in Broward County Florida – – right in the heart of all the 2000 chads. After the 2000 fiasco, the county purchased computer based voting systems. The clerks who had been working with paper and pencil for decades, literally, were given three hours of training on the systems and were [...]
Author: Dale Peterson
Posted: March 16th, 2004 under Uncategorized.
Comments: none
New Comments on PCSRF System Protection Profile (SPP)
We recently reviewed the functional requirements for the SPP. These comments may give you a better understanding on what requirements are available in the Common Criteria and how they are selected. This link will take you to the comments.
Remember the SPP is an ambitious project to lead to system certification which includes products, [...]
Author: Dale Peterson
Posted: March 16th, 2004 under Uncategorized.
Comments: none
Host Based IDS
I’m curious if anyone in the SCADA world is using or has tried host based IDS on a control server. Send me an e-mail, peterson@digitalbond.com, and let me know.
We are very wary of host based IDS. First, it has all the potential problems of impacting performance similar to what we saw with [...]
Author: Dale Peterson
Posted: March 15th, 2004 under Uncategorized.
Comments: none
1st Set of Questions for Control Center PP
Tired of trying to read Common Criteria lingo? Well, we have now made your life easy.
- a simple 10-minute questionaire on important issues in the Control Center Protection Profile
- a Control Center Protection Profile Made Easy presentation
- a FAQ on the Protection Profile
All of these links can also be found on our Control Center Protection [...]
Author: Dale Peterson
Posted: March 2nd, 2004 under Uncategorized.
Comments: none