Showing posts with label Project Shine. Show all posts
Showing posts with label Project Shine. Show all posts

Tuesday, November 5, 2013

Reader Comment – 11-02-13 – Project Shine

On Saturday Jake Brodsky (a frequent commenter, an ICS manager, and a person with his fingers in lots of ICS security projects) left a comment on my blog post on the ICS-CERT Nordex Alert. Jake used my mention of the missed SHODAN angle for the vulnerability discovery as a spring board to mention Project Shine that he and Bob Radvanovsky have been working on. I’m glad he did because I have only mentioned this project in passing.

Project Shine (SHodan INtelligence Extraction) is an ongoing project that uses the SHODAN search engine to identify industrial control systems that are facing the internet. To date they have found well over 1,000,000 systems (that number was bandied about back in the middle of September and they are adding a couple of thousand new systems every week) that look like control systems.

Now this includes building environmental control system, security systems and the like, but there are enough industrial control systems involved to kill the idea that these systems are not connected to the internet. This point is emphatically made by Eric Byres in his blog post.

Now I am not going to get involved in a technical discussion of how these two are using SHODAN to discover potential ICS systems facing the internet. Dale Peterson’s podcast conversation with Bob does that well enough. But I do want to talk about some interesting implications that Bob and Jake have not talked about.

First off, you have to understand that Project Shine is not a professional job (though both Bob and Jake are certainly professionals). As I understand it it is being run out of the basement laboratory in Bob’s home. I don’t suspect that Bob’s basement is really very normal, but this is a project running on a private system with limited resources. Think of a super geeks version of Gibb’s basement boat building; professionally, even painstakingly, done in the spare time of a very busy team.

So what would a Project Shine executed by a professional organization with extensive time, resources and expertise (say the NSA? Or its Russian or Chinese or Israeli counterparts)  look like? Well it wouldn’t use a limited search engine like SHODAN. It would custom design a program using high-speed computational assets that geeks like Bob and Jake can only dream about. They would have a team of engineers and analysts working the project around the clock. And they would not be afraid to reach out and gently touch the systems so that they could determine exactly where and what they were.

Why would they do that? Let’s face it; if you want to be able to conduct cyber-war (and you have to because the other guy is) then you have to understand the battlefield and you have to have a target list. Remember, since WWII modern warfare has not been about destroying the other guy’s military (those are hard targets), it has been about destroying his will and ability to conduct war. You do that by targeting his critical infrastructure. And if you are really smart, you might consider weakening his CI well before you go to war.

If you don’t think that this is happening right now, then you haven’t been paying attention to the news. Now does this put cybersecurity for control systems into a different perspective? For most people (and certainly for politicians) probably not; if nothing has happened, then nothing will happen.


Except when it does happen, the Washington political establishment will make Chicken Little look like an over-sedated octogenarian. Just look at what happened when two buildings were destroyed and a couple of thousand people killed. What happens when we are really attacked?

Friday, December 28, 2012

ICS-CERT Publishes Last Monitor for 2012


Today the folks at ICS-CERT published their last Monthly Monitor for 2012. Actually still calling it a “Monthly” is just a little misleading because it covers the months of October, November and December.

ICS-CERT Responses


Once again we see another report of an ICS-CERT away team investigation. This time it concerns two SCADA engineering workstations that were infected with “sophisticated malware” via an infected USB drive. It’s a nice discussion of how to go about disinfecting an infected system without appropriate backups. Unfortunately (or fortunately depending on your point of view), it appears that the only thing ICS related was the primary use of the workstations. The name of the malware is not mentioned, but there was no real impact or infection of the SCADA system.

A briefer second piece describes the infection of some computers on the ‘control system network’ with some unidentified ‘crimeware’ again via an infected USB drive. Again, the location of the infection seems to be the only thing of ICS-CERT interest.

Of course, the routine use of USB drives in both cases served at the method of infection. That serves as an educational point, with the point being made that:

“ICS-CERT continues to emphasize that owners and operators of critical infrastructure should develop and implement baseline security policies for maintaining up-to-date antivirus definitions, managing system patching, and governing the use of removable media.” (Pg 2)

A second article provides a brief summary of the ICS-CERT operational responses to cyber incidents in FY 2012. They report a total of 198 cyber-incidents reported by industry. Again the only actual ICS related incident reported was the ‘hacked water system in Illinois’ that wasn’t hacked.

Other Information


There is an interesting discussion of the CVSS Score that is reported in each ICS-CERT Advisory. It explains what the score means and how it is determined.

There is also a nice description of Project Shine, a result of a SHODAN investigation initiated by by Bob Radvanovsky and Jake Brodsky. They reported over 460,000 IP addresses of SCADA systems that appeared to be internet facing. Efforts are being made to identify and contact the owners of the systems to warn them of their exposure. ICS-CERT is concentrating on those critical infrastructure systems identified.

There is also a brief discussion of the continuing ICS-CERT response to the apparent coordinated attack on oil and natural gas pipeline operators. Still no information about direct involvement of control systems, though this piece does note that many “of these incidents targeted information pertaining to the ICS/SCADA environment, including data that could facilitate remote access and unauthorized operations”. (pg 4) This has also led to an increased out-reach effort by ICS-CERT to explain the ICS vulnerabilities present in critical infrastructure.

There is also a nice summary of the vulnerabilities reported in ICS-CERT advisories over FY 2012. Of the 177 different vulnerabilities reported, the largest number (44) were buffer overflow vulnerabilities with input validation vulnerabilities placing a distant second (18 instances).

Finally there is a brief summary of the Industrial Control Systems Joint Working Group (ICSJWG) 2012 Fall Meeting.

Oh, one final note; as usual the Monitor closes out with a listing of recent coordinated disclosures and a list of researchers currently working with ICS-CERT on disclosures. While our friend Luigi is mentioned on the first list on two separate vulnerability notices, he doesn’t make the final ‘working with list’. Could be his new company formed to sell 0-day vulnerabilities puts him outside of the coordinated disclosure network.
 
/* Use this with templates/template-twocol.html */