5 ms·
This is exactly what is done in practice. Critical systems (i.e. control room software and hardware) are air gapped and operate in a DMZ. The only real vector
by probablypower 7y ago
This is exactly what is done in practice. Critical systems (i.e. control room software and hardware) are air gapped and operate in a DMZ.
The only real vector one has into such a system (assuming you can't physically access it) is by attacking the 'inputs' to the SCADA network.
Attack vectors like stuxnet or petya require physical access to these systems (i.e. a usb key getting plugged into an operation terminal).
- bdamm 7y agoBut... airgapping doesn't stop damages from Aurora type of attacks. So even with top-level grid controls airgapped, if the attacker is at the switch for enough vulnerable lower-level consumers and can synchronize enough switches (car chargers, solar inverters, local substations, etc) the potential damages can still be very significant. As we saw in the Ukraine power grid attacks, you don't even need to go after critical systems. Quantity has its own quality, as the saying goes.
- AmericanChopper 7y ago> This is exactly what is done in practice. I think you’ve got this backwards. This is exactly what is done _in theory_. In practice many of these systems are not. When I was working as a consultant, I saw so many exposed SCADA systems.
- jacquesm 7y agoTypical SCADA system from the eighties will have an open port listening to UDP traffic, if you're really lucky without any kind of checksum where each bit in a packet will toggle a relay and reply with the state of all its input channels in an ACK packet. Given the state of these systems it is amazing that they are not compromised spectacularly every other day. Or maybe they are but it does not make the news. Plenty of this stuff is running on BASIC stamps and such (no kidding) used to network systems that are even older.
- Whatarethese 7y agoThere are also NERC compliance requirements that require USB ports be disabled at and OS or BIOS level.