Live data from Hacker News

Hackers destroy water pump via SCADA abuse

wired.com

21–30 of 42 posts

Re: Hackers destroy water pump via SCADA abuse

#21
post #18

Good. Malicious crackers, please destroy as many non-safety-critical water pumps as it takes for people to take security on these systems seriously. It seems most of the industrial controls industry is used to operating on a proprietary network, and when moving to IP their guess at security is "uh, firewall?".

I'm amazed that the concept of "air gap" isn't standard operating procedure at any utility.

so lets say that you don't have the budget to keep a fully trained staff of scada and network engineers on site, 24/7. and then there's a systems failure, and the choice is either "they debug it remotely and fix the problem within an hour" or "the staff drives 2-3 hours to the location where the airgapped systems are and then begins work".

now imagine the system is life-preserving or otherwise critical. those 2-3 hours could be hundreds of lives. wouldn't it be criminally irresponsible to not have the system as resilient as possible?

Re: Hackers destroy water pump via SCADA abuse

#22
Stanford EE Computer Systems Colloquium

Control System Cyber Security - State of the State

http://www.stanford.edu/class/ee380/Abstracts/111012.html

"Industrial control systems are used in electric power, water, pipelines, etc. These systems were designed for performance and safety considerations, not security. Traditional IT security technologies, policies, and testing may not apply to these systems. Moreover, there is currently no university with an interdisciplinary program accross multiple engineering disciplines to address control system cyber security. There have already been more than 200 actual control system cyber incidents to date, though most have not been identified as cyber. In the US alone, there have been 4 control system cyber incidents that have killed people, 3 major cyber-related electric outages, 2 nuclear plants shut down from full power, etc. With the advent of Stuxnet, cyber has been introduced as an offensive weapon. The purpose of this presentation is to provide a state-of-the-state view of control system cyber security."

The speaker gets quite a grilling from the academics.

Re: Hackers destroy water pump via SCADA abuse

#23
post #21
post #18

Earlier quoted context omitted.

I'm amazed that the concept of "air gap" isn't standard operating procedure at any utility.

so lets say that you don't have the budget to keep a fully trained staff of scada and network engineers on site, 24/7. and then there's a systems failure, and the choice is either "they debug it remotely and fix the problem within an hour" or "the staff drives 2-3 hours to the location where the airgapped systems are and then begins work". now imagine the system is life-preserving or otherwise critical. those 2-3 hou…

I would say any system whose failure quickly results in the loss of life should always have properly trained staff either on location or trivially close. Anything less than that would be, as you put it, criminally irresponsible, as is the idea of connecting such infrastructure to publicly accessible networks.

Re: Hackers destroy water pump via SCADA abuse

#24
post #21
post #18

Earlier quoted context omitted.

I'm amazed that the concept of "air gap" isn't standard operating procedure at any utility.

so lets say that you don't have the budget to keep a fully trained staff of scada and network engineers on site, 24/7. and then there's a systems failure, and the choice is either "they debug it remotely and fix the problem within an hour" or "the staff drives 2-3 hours to the location where the airgapped systems are and then begins work". now imagine the system is life-preserving or otherwise critical. those 2-3 hou…

That depends on how the cost-benefit analysis came out. You did do a cost-benefit analysis, right?

Personally, I would consider connecting critical infrastructure to the Internet without taking adequate security measures to be the criminally irresponsible thing. Of course, water pumps aren't really "critical infrastructure" in the same sense as, say, nuclear power plants. Hopefully their security is a little more reasonable.

Re: Hackers destroy water pump via SCADA abuse

#25
post #13
post #12

This seems like an exciting decade we are about to enter where hackers can mess with actual physical infrastructure. Sooner or later somebody is going to do something really destructive with that power. Fortunately it shouldn't be that hard to secure the systems. At the very least use a two factor authentication system, if possible the same way gmail does since it is pretty simple, or just store the passwords in a bi…

Exactly what good does "two factor authentication" do when every verb in the protocol was designed with the assumption that the protocol would only ever be addressed with an authorized client? These things are insecure by design, insecure in implementation, and insecure at deployment. Don't trivialize the problem; it's immense. Maybe password theft was involved this time, but that's a trivial detail. I don't feel lik…

Is the controller really the place for putting in security measures? I would have assumed that they reside on a private internal network and it's the software layer on top ( ie, a bacnet gateway or whatever) that needs to be fixed

Re: Hackers destroy water pump via SCADA abuse

#27
post #13
post #12

This seems like an exciting decade we are about to enter where hackers can mess with actual physical infrastructure. Sooner or later somebody is going to do something really destructive with that power. Fortunately it shouldn't be that hard to secure the systems. At the very least use a two factor authentication system, if possible the same way gmail does since it is pretty simple, or just store the passwords in a bi…

Exactly what good does "two factor authentication" do when every verb in the protocol was designed with the assumption that the protocol would only ever be addressed with an authorized client? These things are insecure by design, insecure in implementation, and insecure at deployment. Don't trivialize the problem; it's immense. Maybe password theft was involved this time, but that's a trivial detail. I don't feel lik…

Last time I saw a system like this, it had two distinct networks, one for the controllers and one for the computers that controlled them. I would imagine nobody would allow any direct external access to the controller network.

Re: Hackers destroy water pump via SCADA abuse

#28
post #24
post #21

Earlier quoted context omitted.

so lets say that you don't have the budget to keep a fully trained staff of scada and network engineers on site, 24/7. and then there's a systems failure, and the choice is either "they debug it remotely and fix the problem within an hour" or "the staff drives 2-3 hours to the location where the airgapped systems are and then begins work". now imagine the system is life-preserving or otherwise critical. those 2-3 hou…

That depends on how the cost-benefit analysis came out. You did do a cost-benefit analysis, right? Personally, I would consider connecting critical infrastructure to the Internet without taking adequate security measures to be the criminally irresponsible thing. Of course, water pumps aren't really "critical infrastructure" in the same sense as, say, nuclear power plants. Hopefully their security is a little more rea…

Cost-benefit what?

I work for one of the largest municipal electric utilities in North America. We are a monopoly and do not set our own rates. There is no such thing as "cost-benefit" for us. We spend as much money as we need to get the reliability our regulator demands, and then our rates are set accordingly for us to recover those costs.

Re: Hackers destroy water pump via SCADA abuse

#29
post #23
post #21

Earlier quoted context omitted.

so lets say that you don't have the budget to keep a fully trained staff of scada and network engineers on site, 24/7. and then there's a systems failure, and the choice is either "they debug it remotely and fix the problem within an hour" or "the staff drives 2-3 hours to the location where the airgapped systems are and then begins work". now imagine the system is life-preserving or otherwise critical. those 2-3 hou…

I would say any system whose failure quickly results in the loss of life should always have properly trained staff either on location or trivially close. Anything less than that would be, as you put it, criminally irresponsible, as is the idea of connecting such infrastructure to publicly accessible networks.

I don't think you'd like what your power bill would look like if your distribution company had to have staff trivially close to all of its infrastructure, 24/7. I work at a utility and all (yes, all) of our stations and substations are unmanned.

To have a crew on site at every station, 24/7, you'd be looking at nearly 1,000 employees at $65-90k, assuming 8-hour shifts.

Re: Hackers destroy water pump via SCADA abuse

#30

Good. Malicious crackers, please destroy as many non-safety-critical water pumps as it takes for people to take security on these systems seriously. It seems most of the industrial controls industry is used to operating on a proprietary network, and when moving to IP their guess at security is "uh, firewall?".

Maybe, but for my parents (i.e. non-tech folks) the solution would be more likely "put more police on the internet to catch those criminals".
Post reply on HN