Yikes, get ready for a huge jump in oil pricing.
Why would oil prices jump? This isn’t an oil pipeline.
U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack
11–20 of 218 posts
Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack
#12So, two possible responses by the government to the current increase in these kinds of attacks: 1) blame the lack of computer security in our infrastructure, and work on improving that 2) blame cybercurrencies, and try to eliminate them Any bets on which one our government will choose?
Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack
#13So, two possible responses by the government to the current increase in these kinds of attacks: 1) blame the lack of computer security in our infrastructure, and work on improving that 2) blame cybercurrencies, and try to eliminate them Any bets on which one our government will choose?
Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack
#14Yikes, get ready for a huge jump in oil pricing.
https://www.nytimes.com/2021/05/08/us/cyberattack-colonial-p...
Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack
#15So, two possible responses by the government to the current increase in these kinds of attacks: 1) blame the lack of computer security in our infrastructure, and work on improving that 2) blame cybercurrencies, and try to eliminate them Any bets on which one our government will choose?
Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack
#16So, two possible responses by the government to the current increase in these kinds of attacks: 1) blame the lack of computer security in our infrastructure, and work on improving that 2) blame cybercurrencies, and try to eliminate them Any bets on which one our government will choose?
The U.S. government has been addressing computer security in infrastructure for a long time.
Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack
#17Let's see if 15+ years of security people getting after critical infrastructure asset owners like this has made any difference. At least they detected something and shut it down to control the response. They also know the costs to repair and replace things. I don't suspect the pipeline uses a federation of heterogeneous systems to operate its SCADA actuators, so I would speculate it is likely a single firmware vulner…
A shutdown is a huge deal and means they’re taking this extremely seriously.
Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack
#18Given Government inaction on climate change, could we begin to see motivated individuals or groups taking matters into their own hands and targeting fossil fuel infrastructure in this manner?
Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack
#19Re: U.S.'s Biggest Gasoline Pipeline Halted After Cyberattack
#20Let's see if 15+ years of security people getting after critical infrastructure asset owners like this has made any difference. At least they detected something and shut it down to control the response. They also know the costs to repair and replace things. I don't suspect the pipeline uses a federation of heterogeneous systems to operate its SCADA actuators, so I would speculate it is likely a single firmware vulner…
I work in control systems OT space. A lot of distributed control systems and scada systems interface with the business layer in some fashion to provide access to time series and event data and to allow for alerts via email/mobile. Some people do this properly with good network segmentation, firewalls, A/V and patching, etc (there are several standards that dictate best practice). That said, even when doing it properl…
To shutdown a pipeline, it's not a management console issue, hence why I'd speculate it's in the ICS devices themselves, which probably use uClinux toolchains on SoCs from one or two large vendors. I did some smart meter and ICS security work in the 00's, and there were a few vendors who would be strategic targets. The attack tools available now are unbelievably better, while the attack surface is pretty much the same due to the long lifecycles of ICS components, and considering today we've got cheap SDRs and gnuradio blocks for most wireless protocols, AVR tools, buspirate and the good/greatfet, ghidra/ida, and python for reverse engineering, the vulnerability research on this stuff moves way faster than the industry ability to respond.
If this is a serious attack, the only way to respond will be if they are very lucky, it's a worm and they can stand up a honeynet with spare gear to catch a sample and any good infosec firm can pull it apart. But if it's an active APT group, there's probably a political solution, as given what's possible, this would seem to be just a shot over the bow.