S4_Call
AAA  AAA 

Waterfall and One Way Security

A small number of vendors are promoting unidirectional network security devices, most notably Waterfall Security Solutions from Israel. [FD: Waterfall has advertised on digitalbond.com] To their credit Waterfall has doggedly pursued the control system security space and has some good content on using their product in control systems. And based on the number of questions [...]

Late Summer Reading: NISTIR 7628

How many of you have downloaded NISTIR 7628: Smart Grid Cyber Security Strategy and Requirements, saw it was 305 pages and put it aside? Maybe you even waded into the first ten to twenty pages and read a lot of general statements and gave up. Well if you have some time before the summer is [...]

Friday News and Notes

The field of auto hacking continues to grow, and we have our first auto hacking tool – called CarShark of course. The challenge is in intercepting the signals more than hacking the systems in the car. The question is why would an adversary want to do this? Where is the profit or gain? Besides doing [...]

We Will Never Be Perfect

Some of the post Stuxnet discussion, and even much before it, has the premise that we need to improve security so this type of attack can never be successful. That if we just all do the right things control systems will be impenetrable. When we see unpatched systems, hard coded passwords, cleartext authentication, unauthenticated firmware [...]

Legislative Outlook for Control System Security Registration

Patrick Coyle writes the Chemical Facility Security News blog and tweets @pjcoyle. His blog is my go to resource for all things chemical security, and Patrick also does the hard work of tracking all of the control system security legislation. Patrick was kind enough to write up a blog entry on what you should be [...]

EnergySec Agenda / Bandolier Class

EnergySec puts on a great electric sector control system security event every year, and it is a bargain at $150. The agenda is now out for this year’s event in Denver, Sept 21 and 22.
Looking at the agenda the highlight for me are presentations from James Arlen, Dave Lewis and Patrick Miller. These three always [...]

Friday News and Notes

A lot of noise this week, but only two items for the News and Notes.

NERC asked all members to provide information on the number of Critical Assets they have today under CIP, and how many they would have under the draft CIP-002-4. The draft version is much more detailed on what is and isn’t a [...]

Siemens Roller Coaster Response to Stuxnet

The Siemens response to Stuxnet has been like a roller coaster. It started diving low with limited information and bit of blame shifting as most organizations facing a vulnerability for the first time do. [Siemens is huge and obviously other parts of Siemens are well versed in handling vulnerability incidents, but I'm unaware of this [...]

What Do VxWorks Vulns Mean?

HD Moore recently published a blog entry highlighting some serious vulnerabilities in VxWorks – – an operating system used by a number of field devices in SCADA and DCS. What does and doesn’t this mean?

This has little or no impact on the security of control system field devices. Not because they could not be vulnerable [...]

Bandolier Training Class after EnergySec

We are teaching our half day training class on Auditing Control System Security Configuration With Nessus and Bandolier — this time on Sept 22nd in Denver after EnergySec. In this course you learn how to use Bandolier, customize the Bandolier Security Audit Files, and use other Nessus credentialed checks for both security and NERC CIP [...]