Colonial Pipeline precisely does keep it's control network disconnected from the internet - the only thing that was ransomwared is their corporate network. They shut the pipelines down voluntarily to prevent further spread.
I built some of the SCADA and IT systems for Colonial Pipeline. Many industrial SCADA systems (nearly all) send data from their "OT" systems (PLC/DCS/SCADA) to their "IT" and business layers (Historians/Timeseries Databases, Dashboards, Power BI/etc). This almost always happens through a two-way link (think TCP/IP, HTTP). While the software should not allow data flow backwards, the hardware absolutely does. So how mu…
US passes emergency waiver over fuel pipeline cyber-attack
151–160 of 479 posts
Re: US passes emergency waiver over fuel pipeline cyber-attack
#152Earlier quoted context omitted.
Not to be rude but I'm pretty sure you need to check up on your stats. The Chinese do have the oceans. >Citing the Office of Naval Intelligence, a Congressional Research Service report from March notes that the People’s Liberation Army Navy, or PLAN, was slated to have 360 battle force ships by the end of 2020, dwarfing the U.S. fleet of 297 ships. [1]( https://www.navytimes.com/news/your-navy/2021/04/12/chinas-n...…
without significant aircraft carrier fleet i'm not sure china has dominant control of any seas, despite best efforts in south china seas [1]( https://en.wikipedia.org/wiki/Chinese_aircraft_carrier_progr... )
I am not sure what your point is. By number of ships, they are the biggest. I have no idea how important aircraft carrier fleet is.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#153Forgive my ignorance, but is it incredibly hard to determine the actual identities of the people behind this? I don’t know why a government wouldn’t simply assassinate culprits who were guilty of crimes at a level that would qualify as an act of war.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#154Earlier quoted context omitted.
Do you think Colonial identified some "physical world" risk, as in the possibility of a pressure overload or pipeline leak? I imagine that verifying the integrity of these SCADA systems is a very complex task, so I'm wondering if they've already identified a possible attack vector/entry point or if this was entirely preventative.
I have no idea. Shutting down preventatively would be smart, and they had good leadership in their IT space while I was there. Friendly people who could make the hard decisions quickly, weren't afraid to pick up the phones to call people, and supported the growth of struggling employees without letting shoddy work get approved. They were also good at managing large multi-year and nation-wide project campaigns - a rar…
Re: US passes emergency waiver over fuel pipeline cyber-attack
#155Earlier quoted context omitted.
Pretty sure china doesn't have the oceans - might want to check up on your stats.
Not to be rude but I'm pretty sure you need to check up on your stats. The Chinese do have the oceans. >Citing the Office of Naval Intelligence, a Congressional Research Service report from March notes that the People’s Liberation Army Navy, or PLAN, was slated to have 360 battle force ships by the end of 2020, dwarfing the U.S. fleet of 297 ships. [1]( https://www.navytimes.com/news/your-navy/2021/04/12/chinas-n...…
Re: US passes emergency waiver over fuel pipeline cyber-attack
#156It needs to be asked again, why are critical services on the Internet ? We all know why, companies are chasing profits at any cost, so hiring more people to monitor these systems as the did 40 years ago will lower the execs bonuses. The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your…
From TFA:
Digital Shadows thinks the Colonial Pipeline cyber-attack has come about due to the coronavirus pandemic - the rise of engineers remotely accessing control systems for the pipeline from home... believe DarkSide bought account login details relating to remote desktop software like TeamViewer and Microsoft Remote Desktop.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#157It needs to be asked again, why are critical services on the Internet ? We all know why, companies are chasing profits at any cost, so hiring more people to monitor these systems as the did 40 years ago will lower the execs bonuses. The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your…
> The US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your parent companies) are forfeited. Make it a crime to pay the ransom in a ransomware attack. Make it a crime to fail to report a ransomware attack in a timely manner. Ransomware attacks (and companies with poor security practices) wi…
Make it a crime for people to knowingly withhold information about such activities from the authorities.
Abuse of substances, trafficking, and associated criminality will go away.
But seriously...
> Make it a crime to pay the ransom in a ransomware attack.
Ok, so ... what should a company do? File a report with some government agency or with an insurance company and wait until the bureaucratic process maybe results in being able to pay the ransom to resume business operations? Punishing the victim of a crime? Really?
> Make it a crime to fail to report a ransomware attack in a timely manner.
Further punishing the victim of a crime? Really?
> Ransomware attacks (and companies with poor security practices) will go away.
lol
Re: US passes emergency waiver over fuel pipeline cyber-attack
#158Earlier quoted context omitted.
> US Gov should make it clear, if you are a critical service and if your service drops due to items being on the internet, for each occurances 10% of your total revenue (including your parent companies) are forfeited This sounds good in theory but suffers from the cobra effect [1]; you think you’re incentivising security. You’re actually pushing obscurity. Colonial preëmptively shut down its pipe to prevent physical…
I reckon air-gapped networks are a valid defense. If something needn't be connected, why let it? It mitigates so many threats.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#159Earlier quoted context omitted.
Do you think Colonial identified some "physical world" risk, as in the possibility of a pressure overload or pipeline leak? I imagine that verifying the integrity of these SCADA systems is a very complex task, so I'm wondering if they've already identified a possible attack vector/entry point or if this was entirely preventative.
I have no idea. Shutting down preventatively would be smart, and they had good leadership in their IT space while I was there. Friendly people who could make the hard decisions quickly, weren't afraid to pick up the phones to call people, and supported the growth of struggling employees without letting shoddy work get approved. They were also good at managing large multi-year and nation-wide project campaigns - a rar…
I'm quite surprised and comforted to hear that the leadership there is competent and knows how to manage people. I've heard from friends/acquaintances who have worked in the energy industry about how terribly things are put together on an IT front (PG&E being a prime culprit), so I was expecting the same here.
I really like your "data-diodes" concept. Interested to see if such a thing takes off especially as these attacks evolve.
Re: US passes emergency waiver over fuel pipeline cyber-attack
#160Earlier quoted context omitted.
I built some of the SCADA and IT systems for Colonial Pipeline. Many industrial SCADA systems (nearly all) send data from their "OT" systems (PLC/DCS/SCADA) to their "IT" and business layers (Historians/Timeseries Databases, Dashboards, Power BI/etc). This almost always happens through a two-way link (think TCP/IP, HTTP). While the software should not allow data flow backwards, the hardware absolutely does. So how mu…
I also wonder why nobody who has secure computing issues demands physical write-enable switches for ROM, rather than using software switches that are inevitably corrupted.
However, a write-only ROM system is possible as long as the ROM chips were reasonably affordable and a company could provide reasonable turnaround times for small modifications. That would move the target of vulnerability up the supply chain.
Some of the things which matter though are necessarily run-time variables like "is the valve commanded open or closed?" and "what are the tuning parameters for this PID control loop?". It's always theoretically possible for a buffer overflow/rowhammer/etc to flip the bit responsible for the valve's open/closed command. Even with an OS/Application stack burned into ROM. You still need RAM.
At least power cycling a readonly-storage device would remove any malicious RAM changes.