Archive for 'SCADA Architecture'
Beta Release: SCADA IDS Preprocessors
We are pleased to announce the beta release of some Quickdraw software components today. Quickdraw is a Digital Bond research project funded by the US Department of Homeland Security (DHS). This beta release is the first three SCADA IDS preprocessors that were the crux of the Quickdraw project. They are:
DNP3
Ethernet Industrial Protocol (EtherNet/IP and [...]
Author: Daniel Peck
Posted: June 25th, 2009 under DNP3, EtherNet/IP, IDS / IPS, Modbus TCP, Quickdraw, SCADA IDS.
Comments: none
Virtualization a Reality in Control Systems
We have been blogging about the benefits of virtualization in control systems, see the blog posts here. Asset owners have been reluctant to embrace virtualization until it was blessed by the vendor, and this is understandable. A few vendors have been working on virtualization support, and the highlight for me at the AREVA User Group [...]
Author: Dale Peterson
Posted: June 12th, 2009 under SCADA Architecture, VM.
Comments: 1
Malware, Viruses, and Attackers hopping networks
Many of us in the Control System community feel pretty secure in the belief that our critical networks are not directly connected to the internet, and as such are insulated from attack. Apparently (and as oft has been stated) this is not sufficient protection, if the control systems communicates with a network that does have [...]
Author: Kevin Lackey
Posted: April 24th, 2009 under Firewall / Perimeter, SCADA Architecture.
Comments: 2
Web Browser Attacks
At S4 2009, Daniel and Kevin taught a security class. Kevin demonstrated web attacks emanating from a browser client directed toward a server. The flip side of web server hacking uses a web server to attack the client system. The Pwn2Own contest is a good example of the type of damage that can be done [...]
Author: Charles Perine
Posted: April 15th, 2009 under Big Picture, SCADA Architecture.
Comments: none
Conficker beFUDdlement
I’ll start off by saying don’t believe all the FUD that’s been going around, we all know how many members of the media area when they get hold of a story, especially one that can have a date in the future to speculate on.
That said, there are definitely some interesting things going on with the [...]
Author: Daniel Peck
Posted: April 1st, 2009 under Anti-Virus, Authentication, Firewall / Perimeter, Security Tools.
Comments: 5
Time to Revisit Dial-up Security
For those who were counting on war dialing being hacker passé, you may want to think again. A new tool (WarVOX) was made public this week that, using VOIP services, is able to scan a 10,000 number exchange in eight hours or less. It might be time to check those modem lines for “emergency” support [...]
Author: Jason Holcomb
Posted: March 5th, 2009 under Field Communication, Remote Access, Security Tools.
Comments: 2
No Budget Security Ideas: Part 1
I’ve talked to a few people recently who have control system security responsibility but are on a very tight or non-existent budget. Some things, like the network taps that we discussed recently, do have significant cost but there are many basic security steps that can be taken with little or no capital expense. We’ll identify [...]
Author: Jason Holcomb
Posted: February 11th, 2009 under Firewall / Perimeter, Security Tools.
Comments: 2
Tapping Control System Networks
Richard Bejtlich asks the question “Why Network Taps?” over at the TaoSecurity blog this week. I’m a huge fan of network taps for IDS, general monitoring and troubleshooting. It’s hard to beat the visibility a tap provides at your network entry and exit points. Bejtlich spells out several reasons why taps are a good idea [...]
Author: Jason Holcomb
Posted: January 28th, 2009 under Field Communication, Firewall / Perimeter, IDS / IPS.
Comments: 1
Patching Beyond Microsoft
Oracle released 41 security patches this week for a variety of their products. Ten of the patches were for the Oracle database – – that by the way is used in many SCADA and DCS servers.
We have seen great progress with vendors testing and certifying Microsoft patches on a timely basis. We have some progress [...]
Author: Dale Peterson
Posted: January 15th, 2009 under SCADA Architecture.
Comments: 2
‘Functional’ Programming Paradigm & Control System Security
The gist of discussion on my earlier blog on the “Relative Security of the ARM vs. x86 architectures” can be summarized in two bullets.
1. It is interesting that at least theoretically, a proper Harvard Architecture based chip might provide a better foundation for building a secure control system than a von Neumann based chip architecture.
2. [...]
Author: Martin Solum
Posted: January 8th, 2009 under SCADA Architecture.
Comments: none