Over the last week or so I have been talking about how easy random stuxing of a control system could be. Yesterday Ralph Langner, the man responsible for identifying the man-in-the-middle component of the Stuxnet attack, demonstrated in his blog just how easy that attack could be. He provided us with just 4 lines of code for a Siemens PLC that would shut down the output of the PLC on a predetermined date.
This is, in effect, the bullet that an attacker would use to Stux a control system. Additional code could be hung on this bullet to make it more effective, but this could certainly disrupt manufacturing operations.
If this is the bullet, the attack still needs a method of getting it to the PLC. Ralph shares some thoughts on how that could be accomplished, but it is clear that little more than access to the network upon which the PLC resides is all that is required to deliver that bullet to the intended target.
Stuxing is moving just this much closer to reality.
Showing posts with label Stuxing. Show all posts
Showing posts with label Stuxing. Show all posts
Friday, July 22, 2011
Monday, July 18, 2011
The Risk of Random Stuxing
Last week I did a blog post where I discussed in some detail how a Stuxnet-like attack could be used to disrupt operations at a chemical facility. While I noted that this type of stuxing would not require as much process knowledge as the classic Stuxnet attack, it is still a fairly sophisticated attack mode (at least until stuxing tools become readily available). So, since the result of a simple stuxing attack is not usually spectacular or maybe even not readily recognizable as an attack, why would any one bother to execute such an attack? As with most types of cyber attacks there could be a number of different motivations in play.
Hacker Status
Let’s never forget the most basic motivation for a cyber attack, hacker status. It’s been years (okay, decades) since I personally knew a hacker, but it is apparent that one of the basic motivations for many (if not most) of them is simply the desire to be recognized by their peers to be the first, the fastest or what ever –st. As always, the more complex the challenge the more status is to be gained from achieving the goal.
With everyone in the cyber world talking about the size and complexity of the team that developed Stuxnet, there is obviously a substantial challenge to be the first individual to turn this complex attack into a hacker toolbox item. The identity of the first target really doesn’t make a difference, so it will probably a readily accessible target to be hit first. After that it will be a matter of ringing up successful attacks on increasingly difficult targets.
Even after the next level of complexity has been reached the stux attack will remain a measure of advancement in the hacker world particularly as advanced defenses against the attack mode are developed. We will continue to hear about successful attacks for years to come.
Financial Gain
As if the pure hacker threat wasn’t bad enough the problem of extortionists using this type of attack cannot be discounted. Since the affects that I outlined in my earlier blog are more financial than anything else, the random-stux attack mode certainly lends itself to criminal elements using this as a source of money. The criminal organization infects the system causes some batch upsets and then offers to turn-off the attack for a fee.
The economics of this type attack are very complex. The earlier in the attack development cycle described above that criminal elements can adapt the stux attack the more likely they are to make good money from it. Early in the attack cycle large organizations may be more likely to buy time, but as defenses become more available larger organizations are more likely to have the sophisticated cyber support necessary to employ those defenses and responses.
As the attack cycle progresses smaller facilities will be come the more likely targets because of the generally lower technical sophistication of in-house support personnel. The per attack financial return will be lower, but there will still be substantial profits possible because the lowering cost of conducting the attacks will make it easier to attack a larger number of facilities.
Terrorism
The lack of a spectacular result from a random-stux attack would seem to make it a poor attack mode for the typical terrorist organization. There are, however, two major exceptions to that truism; anarchist and hacktivist organizations may find this to be a very desirable attack mode.
Anarchists may find this to be an almost ideal tool in their fight against multi-national corporations. It would allow them to disrupt production and exact a financial impact on these organizations with minimal threat to the safety of employees and the surrounding community. It would allow them to conduct their attacks from the relative anonymity of the internet while still clearly marking their targets.
Recent years has seen the rise of the hacktivist organization. While many of these are clearly cyber anarchists we are seeing more of them taking up more conventional social and political causes. A recent article at SCMagazineUS.com noted that the hacktivist organization Anonymous has declared their intention to take on ‘Big Oil’ over the exploitation of the Alberta Oil Sands and to attack Monsanto over their ‘business practices’.
The combination of any of a number of different causes (animal rights, anti-abortion, global warming, racial/social purity, pollution prevention, environmental equality, and even labor disputes are all potential examples) with people that have the clear technical expertise necessary to develop this stux-attack mode may make a wide variety of hacktivist organization the most likely source of these attacks in the near future.
Hacker Status
Let’s never forget the most basic motivation for a cyber attack, hacker status. It’s been years (okay, decades) since I personally knew a hacker, but it is apparent that one of the basic motivations for many (if not most) of them is simply the desire to be recognized by their peers to be the first, the fastest or what ever –st. As always, the more complex the challenge the more status is to be gained from achieving the goal.
With everyone in the cyber world talking about the size and complexity of the team that developed Stuxnet, there is obviously a substantial challenge to be the first individual to turn this complex attack into a hacker toolbox item. The identity of the first target really doesn’t make a difference, so it will probably a readily accessible target to be hit first. After that it will be a matter of ringing up successful attacks on increasingly difficult targets.
Even after the next level of complexity has been reached the stux attack will remain a measure of advancement in the hacker world particularly as advanced defenses against the attack mode are developed. We will continue to hear about successful attacks for years to come.
Financial Gain
As if the pure hacker threat wasn’t bad enough the problem of extortionists using this type of attack cannot be discounted. Since the affects that I outlined in my earlier blog are more financial than anything else, the random-stux attack mode certainly lends itself to criminal elements using this as a source of money. The criminal organization infects the system causes some batch upsets and then offers to turn-off the attack for a fee.
The economics of this type attack are very complex. The earlier in the attack development cycle described above that criminal elements can adapt the stux attack the more likely they are to make good money from it. Early in the attack cycle large organizations may be more likely to buy time, but as defenses become more available larger organizations are more likely to have the sophisticated cyber support necessary to employ those defenses and responses.
As the attack cycle progresses smaller facilities will be come the more likely targets because of the generally lower technical sophistication of in-house support personnel. The per attack financial return will be lower, but there will still be substantial profits possible because the lowering cost of conducting the attacks will make it easier to attack a larger number of facilities.
Terrorism
The lack of a spectacular result from a random-stux attack would seem to make it a poor attack mode for the typical terrorist organization. There are, however, two major exceptions to that truism; anarchist and hacktivist organizations may find this to be a very desirable attack mode.
Anarchists may find this to be an almost ideal tool in their fight against multi-national corporations. It would allow them to disrupt production and exact a financial impact on these organizations with minimal threat to the safety of employees and the surrounding community. It would allow them to conduct their attacks from the relative anonymity of the internet while still clearly marking their targets.
Recent years has seen the rise of the hacktivist organization. While many of these are clearly cyber anarchists we are seeing more of them taking up more conventional social and political causes. A recent article at SCMagazineUS.com noted that the hacktivist organization Anonymous has declared their intention to take on ‘Big Oil’ over the exploitation of the Alberta Oil Sands and to attack Monsanto over their ‘business practices’.
The combination of any of a number of different causes (animal rights, anti-abortion, global warming, racial/social purity, pollution prevention, environmental equality, and even labor disputes are all potential examples) with people that have the clear technical expertise necessary to develop this stux-attack mode may make a wide variety of hacktivist organization the most likely source of these attacks in the near future.
Thursday, July 14, 2011
ICS Attacks as Process Problem
There is an interesting post over at Digital Bond's SCADA Security blog about a subject that I have been discussing since Ralph Langner started describing the operation of the Stuxnet malware. Dale looks at an issue recently raised by Michael Toecker; should the search for a root cause of unexplained process problems include a look at possible ICS attacks?
Data Historians and Root Cause Analysis
As a process chemist in a specialty chemical manufacturing facility for many years, I have spent a great deal of time looking at various process upsets to determine the root cause so that the facility could correct those problems before subsequent batches were run. Process upsets normally lead to off-spec material being produced, a very large cost for any manufacturing facility. In many chemical facilities process upsets could lead to catastrophic consequences. So, root cause analysis is very important.
The addition of process historians to control systems made the root cause analysis task of chemical engineers and process chemists much easier. Chemical manufacturing processes are very complex and are influenced by a wide variety of factors; temperatures, pressure, heat transfer, the ratio of reactants, and even the rate at which raw materials are added to the process can play critical roles in the modern chemical manufacturing process. Detailed tracking of all of these variables (and more) and identifying which ones are most critical at various places in the process was not possible before the advent of data historians. The high productivity and quality of products made in modern chemical plants can be directly traced to the detailed use of process historians.
The ability to use data historians to track process variables and conduct root cause analysis for process upsets is closely dependent on the quality of the information being exported to these systems. This is one of the reasons that the maintenance folks in a modern chemical manufacturing facility spend so much time doing testing and calibration of sensors. But, this still assumes that what the sensor detects is accurately reported and recorded in the control system.
Compromised Control Systems
The point that Toecker was trying to make, and Dale was highlighting, was that because of the advent of Stuxnet, process people are now going to have to question whether their system had been stuxed (sounds better than ‘attacked by a Stuxnet like malware) if they start to see process equipment failing in unexpected frequencies and failure modes. Since this is what happened in the much publicized Stuxnet attack one would hope that this would be something that control systems engineers would consider when confronted with unusual equipment failures.
DEFINITION: Stux: Verb. To attack an electronic control system in such a way as to remotely change the output of one or more pieces of production equipment while making the equipment appear to be functioning properly by simultaneously spoofing the control system data.
I have been maintaining for almost a year now that this is not the real problem of Stuxnet. The deliberate destruction of process equipment is certainly possible (which even the Iranians have admitted), but it does require a significant understanding of the particular equipment and its failure modes. This means that the development of an attack on any particular facility will require detailed malware tweaking that will be time consuming and require a relatively high-level of expertise. This is certainly possible and will almost as certainly be seen in the near future, but the instances will be relatively few and far between.
A much easier way to attack a modern manufacturing facility will be to randomly stux the system. This would cause random changes in the manufacturing process while hiding those changes from the process control team. Some of the changes would have no significant effect. A larger number would cause process problems that would result in increased production times or off-spec products, both very costly. A small number of situations would result in serious safety problems like chemical releases, over-pressure vessel failures, or fires.
I am much more concerned with this type of attack. Randomly stuxing a manufacturing facility would be much harder to detect in the normal process of root cause analysis. Random problems would have to be real high-frequency for even the most suspicious process control engineer to start to question if the facility had been stuxed. Such out-side-the-box thinking would not be found at most facilities because of a standard focus on solving each problem in turn and ignoring a more holistic approach.
Data Historians and Root Cause Analysis
As a process chemist in a specialty chemical manufacturing facility for many years, I have spent a great deal of time looking at various process upsets to determine the root cause so that the facility could correct those problems before subsequent batches were run. Process upsets normally lead to off-spec material being produced, a very large cost for any manufacturing facility. In many chemical facilities process upsets could lead to catastrophic consequences. So, root cause analysis is very important.
The addition of process historians to control systems made the root cause analysis task of chemical engineers and process chemists much easier. Chemical manufacturing processes are very complex and are influenced by a wide variety of factors; temperatures, pressure, heat transfer, the ratio of reactants, and even the rate at which raw materials are added to the process can play critical roles in the modern chemical manufacturing process. Detailed tracking of all of these variables (and more) and identifying which ones are most critical at various places in the process was not possible before the advent of data historians. The high productivity and quality of products made in modern chemical plants can be directly traced to the detailed use of process historians.
The ability to use data historians to track process variables and conduct root cause analysis for process upsets is closely dependent on the quality of the information being exported to these systems. This is one of the reasons that the maintenance folks in a modern chemical manufacturing facility spend so much time doing testing and calibration of sensors. But, this still assumes that what the sensor detects is accurately reported and recorded in the control system.
Compromised Control Systems
The point that Toecker was trying to make, and Dale was highlighting, was that because of the advent of Stuxnet, process people are now going to have to question whether their system had been stuxed (sounds better than ‘attacked by a Stuxnet like malware) if they start to see process equipment failing in unexpected frequencies and failure modes. Since this is what happened in the much publicized Stuxnet attack one would hope that this would be something that control systems engineers would consider when confronted with unusual equipment failures.
DEFINITION: Stux: Verb. To attack an electronic control system in such a way as to remotely change the output of one or more pieces of production equipment while making the equipment appear to be functioning properly by simultaneously spoofing the control system data.
I have been maintaining for almost a year now that this is not the real problem of Stuxnet. The deliberate destruction of process equipment is certainly possible (which even the Iranians have admitted), but it does require a significant understanding of the particular equipment and its failure modes. This means that the development of an attack on any particular facility will require detailed malware tweaking that will be time consuming and require a relatively high-level of expertise. This is certainly possible and will almost as certainly be seen in the near future, but the instances will be relatively few and far between.
A much easier way to attack a modern manufacturing facility will be to randomly stux the system. This would cause random changes in the manufacturing process while hiding those changes from the process control team. Some of the changes would have no significant effect. A larger number would cause process problems that would result in increased production times or off-spec products, both very costly. A small number of situations would result in serious safety problems like chemical releases, over-pressure vessel failures, or fires.
I am much more concerned with this type of attack. Randomly stuxing a manufacturing facility would be much harder to detect in the normal process of root cause analysis. Random problems would have to be real high-frequency for even the most suspicious process control engineer to start to question if the facility had been stuxed. Such out-side-the-box thinking would not be found at most facilities because of a standard focus on solving each problem in turn and ignoring a more holistic approach.
Subscribe to:
Posts (Atom)