15 ms·
Mysterious safety-tampering malware infects a second site
- mirimir 8y agoSo do they use any code from Stuxnet? That would be ironic.
- stebann 7y agoHaha, great point.
- peppershaker 8y agoAren’t these control systems airgapped ? So does that mean someone had to physically plant the malware?
- rtkwe 8y agoThey'll be somewhat networked at least together and if the operators want any convenience they'll be on a network with most other systems just so they can be monitored more easily.
- daniel-cussen 8y agoOr, when attacked, so they can watch it fall apart faster.
- blcarson 8y agoAt least they can watch it in real time from their ipad at home?
- mandevil 8y agoMost control systems are not airgapped, because most people don't think of themselves as targets of that level of attack. Stuxnet was targeting national security infrastructure, which is much more likely to be airgapped, but your local powerplant doesn't (at present) think of themselves as national security infrastructure, so they don't take the same level of precautions. Note: this only describes cases I'm familiar with, in the US. I bet that some countries with more experience on the receiving end of cyber-warfare (e.g. Ukraine) are better.
- deleted 8y ago[deleted]
- thesimp 8y agoThe airgap question comes up every time an industrial system is attacked. The thing is that these days all systems are connected via several layers to the outside world. Because a modern oil refinery is of no use if you cannot track what product is being made at that moment. And the people tracking the data are often in completely different locations or even different countries. The main line of defense is these days is "layers of an onion" network with (physical) controls such that data easily can get out to a higher layer but that it is very difficult to get in from a higher layer back down into a deeper layer. A completely airgapped network is not practical anymore because the alternative is even worse: nobody wants to have dozens or 100ths of operators, maintenance engineers and 3rd party contractors running around the facility with usb sticks because there is no network to move stuff around. If you have a network then you can control where the data comes into your network, who copies the data to where and what data is visible for which user.
- waste_monk 8y agoIt constantly horrifies me that they don't use data diodes for this systems like this. Let data flow one way from the secure industrial equipment out to the general use network for monitoring, but you'd still have to go to a machine on the secure side to make any changes.
- justwalt 8y agoThis seems to be the best solution by far.
- oilman 8y agoIn a lot of industrial sites software security is a joke. Embedded systems tend to use very old, well proven technology, which in itself isn't a problem, it fits the market well, but the side effect is that security isn't always properly considered as it wasn't a concern when the software/hardware was developed. I was involved in a project a few years ago delivering a series of monitoring systems running Windows XP to a brand new 700 million dollar oil rig. This was at the request of the client, they had software they needed that would only run on Windows XP. They had a fit when we had trouble sourcing Windows XP licenses. The expectation is that these systems will have a 20 - 30 year life. It used to be that keeping every air gapped was enough, but organizations want easier monitoring, so more systems are being networked in an ad-hoc way without a lot of thought about security. I expect we are going to see more things like this happening in the future until we start taking security in systems / embedded space more seriously. And even then there will be exploits of older systems for years afterwords since the replacement cycle is so long. I wonder what a secure embedded system even looks like when I think about it. The environment isn't suitable to the kind of continuous patching that is done in the web world, but exploits will be found and dependencies will need to be updated. How do you square keeping things up to date with stringent testing requirements in systems that can kill people. Many of these systems / plants are unique, there is only one plant like it in the world, so testing becomes very hard.
- losteric 8y agoHow are mechanical components tested against requirements in critical systems? What is the process for changing those components, like upgrading pipes to a fancy new composite? In my mind, we'll start treating silicon the same way... formal verification, rigorous real-world testing, trusted suppliers, and an expectation that change is slow, expensive, and risky.
- jonawesomegreen 8y agoSeems like there is a huge opportunity here for a startup that can navigate the industry and manage to solve some of these problems. There are huge players in the space, but from what I've seen they aren't solving these problems very effectively.
- sevensor 8y agoI once encountered a guy who was setting up systems so that you could control a water treatment plant from your ipad at home. His attitude was, "Modbus on one side, ethernet on the other, what could possibly go wrong?" Lots, I told him. A lot of things could go wrong.
- weaksauce 8y agohaving setup many control systems over the years I can confirm that the state of the art is that bad. it's amazing just how blazé they are about security. also, terrifying.
- dustindiamond 8y agoUnfortunately, my municipality of 2,200 users is planning to do this. Also, all water meters are being replaced so they can be read remotely without a human physically using an electronic meter reader.
- VectorLock 8y ago>Also, all water meters are being replaced so they can be read remotely without a human physically using an electronic meter reader. Those are extremely widespread already. And they're pretty open. I wouldn't personally be too worried about any potential exploits since they're simply broadcast only systems and the worst that could probably happen is your'd get a jacked up water bill.
- peteradio 8y agoDear Human, You have unpaid WATER BILL of -2147483648 dollars. Report immediately to INCINERATOR145 for processing. Please have a kindly day, ROBOTOVERLORD69420
- SkyPuncher 8y agoI don't really see water meters as being an issue. There aren't any control systems involved. Worst case you can tamper with the readings, but you can't actually cause damaging effects.
- ccnafr 8y agoHere's the direct link to the report: https://www.fireeye.com/blog/threat-research/2019/04/triton-actor-ttp-profile-custom-attack-tools-detections.html https://www.fireeye.com/blog/threat-research/2019/04/triton-... Article spends too much time FUDing "plant explosions" for my taste
- phkahler 8y ago>> Article spends too much time FUDing "plant explosions" for my taste Because hacking systems to cause explosions would be unheard of? https://www.telegraph.co.uk/news/worldnews/northamerica/usa/1455559/CIA-plot-led-to-huge-blast-in-Siberian-gas-pipeline.html https://www.telegraph.co.uk/news/worldnews/northamerica/usa/...
- chelmzy 8y agoHere's a Shodan search that will net you 5K+ fuel tank controls. https://www.shodan.io/search?query=inventory+port%3A%2210001%22 https://www.shodan.io/search?query=inventory+port%3A%2210001...
- dev_dull 8y agoWhere do you get “control” from that? Looks like a web page with a fuel level status from gas stations.
- chelmzy 8y agohttps://www.blackhat.com/docs/us-15/materials/us-15-Wilhoit-The-Little-Pump-Gauge-That-Could-Attacks-Against-Gas-Pump-Monitoring-Systems-wp.pdf https://www.blackhat.com/docs/us-15/materials/us-15-Wilhoit-... They take commands to change certain values.
- zaroth 8y agoAnd this is precisely why we can never consider nuclear power to be “safe”. It’s just not worth the risk exposure. The worst case failure modes must be expected to occur, and they must be economically and ecologically acceptable when they do. The idea that “this can theoretically happen but we promise it won’t” is simply not acceptable. Versus, “this is extremely unlikely to occur because of these numerous counter-measures, but when it does here’s what we do and what it will cost us.” If you can do the later analysis on a nuclear plant and come away satisfied, then build baby build.
- dev_dull 8y agoMany countries over the last 3 decades would disagree with this statement.
- tsukikage 8y agoNothing is perfectly safe. The interesting question is, is it safer than the alternatives?
- jakespracher 8y agoYeah I used to work at a nuclear plant. They intentionally use all analog systems currently for fear of this. Almost nothing digital in the whole plant