Home Blog Page 363

Power Plants: Cybersecurity Threats and Risks

Power Plant cybersecurity

Contributed By Glenn Hartfiel, Director, Opportune’s Process and Technology Practice

Power plant networks are under constant attack from Chinese, Russian and other unknown hackers across the world 24 hours a day and 365 days a year. A hacker’s goal is to breach critical infrastructure, such as a power plant’s external firewalls, to gain access to the internal networks and find a way into the control system environment.

Hackers typically use port scanners, password-guessing software and other readily available Internet tools to perform non-stop attacks against a power plant’s external environments. These tools look for and exploit any potential weaknesses that could be used to access internal networks.  Once inside, the hacker can continue to run tools against control networks to exploit any weaknesses that might allow them take control of plant control networks.

Social engineering attacks such as ransomware are used to trick a user into clicking an attachment (i.e., phishing schemes) in order to extract and encrypt data files. This enables a hacker to extort money and decrypt information. The more access a user has to a system environment the greater the damage that can be done. Limiting administrative privileges reduces these risks.

Control system data, operational data and sensitive financial data can be encrypted and only restored if backups are currently performed. Phishing attacks can also trick users into providing their username and passwords, which can then be used to login remotely to other systems. People tend to use the same passwords across many different sites with little to no variations. This can allow a hacker to gain access to many other systems using the same login credentials and passwords from a compromised account, including control systems, banking information and other applications.

Many power plants lack dedicated IT staff that can effectively identify and repel a cyber attack so user diligence is key to identifying problems. Without proper controls, it is only a matter of time before hackers gain access to targeted resources and establish control of the environment.

Lack of Proactive Risk Mitigation and System Updates

Historically, control systems have been physically separated – or “Air Gapped”. However,  these environments are now connected at various firewalled points as businesses increasingly rely on real-time plant data.  Firewalls can provide security needed to prevent access to control networks. However, misconfigurations are common and they are sometimes not tested, thus enabling security weaknesses. Control networks continue to move closer to the Internet and many are now running on Microsoft-operating systems, which can expose them to similar security vulnerabilities as office computer systems.

Lack of Updates and Risk Mitigation

Complex passwords, two-factor authentication and user awareness are all lines of defense that help mitigate a successful hack. Many power plants do not want passwords that change on a set interval and do not use complex options because they are difficult to remember. Passwords such as “Password”, “2018Texans” or other dictionary words only take a few minutes of hacking to gain access to a network.

More power plants are using virtual private network (VPN) connections for remote starting of power plants. VPNs move critical control networks closer to the Internet. which can provide the ability for someone to hack into the plant and start or stop operations.  If hackers figure out how to operate plant control systems, damage can be significant.

Security updates are critical to mitigating cyber hacking attacks by closing vulnerabilities that could provide access to system without having to provide login identification and passwords. Recent Cisco AnyConnect VPN software and Cisco Switch vulnerabilities have provided a great opportunity for network breaches or complete network failures if these issues are not patched up in a timely period.

Once a critical vulnerability has been identified, it is key that a technical team is deployed to make a fix.  Critical patches need to be identified and fixed as soon as possible. Oftentimes, clients do not have an active IT group that updates servers, firewalls and other devices when vulnerabilities arise. Computer systems require maintenance, backups and regular updates. Without these processes in place, power plants become an easy target for hackers looking for a thrill or a foreign government who may seek visibility by taking control of power plant environments.

 Cyber Attack by Chinese Actor – A Case Study

Opportune LLP was engaged by a client to review a power plant on concerns that their site may not be secure from external cyber attacks. During our review, it was found that China had hacked into the control system through a Microsoft Windows machine connected directly to the Internet without firewall protection.

The local IT resource lacked security experience and did not understand the risks of how the computer was at risk. The malicious activity was subsequently traced back to China to hack into the power plant control system. Consequently, the hacked machine was eventually rebuilt, patched and moved behind firewalls to fix the issue. It is not known what China’s intent was for hacking the asset. We suspect it could have been using these easy targets to figure out a way how to cause physical damage to a power plant with an intent to disrupt the power grid.

Multiple Layers of Defense Needed

“Defense in depth” refers to employing multiple layers of security that makes it more difficult for cyber hackers to gain access to sensitive plant control networks. These can include complex passwords, shorter password expiration policies, two-factor authentication, firewalls configured with the least privileged access and intrusion prevention systems (IPS).

These augmented protective measures are important to deter hackers from computer systems. Complex passwords should always be required as they are a fundamental reason why accounts get hacked. Hackers load security programs with dictionary files and run variants by adding dates, prefixes and suffixes to create guessable password attacks. Some attacks can break passwords within minutes if passwords are not complex enough.

Two-factor authentication for remote access is one of the best security mechanisms for obtaining access to plant control environments along with something unique that is required to authenticate onto the control network environment. One-time passwords based on a hardware or software-based token generators also make password-guessing attacks more difficult for the attacker since these use one-time passwords based on complex algorithms.

Intrusion Prevention Systems

Cisco Firepower solutions (IPS) and similar tools can be an effective way to mitigate attacks from China, Russia or any location outside specific country regions based on known IP address ranges. Firewalls configured with these country IP blocks do not eliminate cybersecurity risk. Rather, they reduce it to a much smaller range of IPs that can make a connection to the firewall and prevent hacking attempts from the excluded locations.

Additional Firepower configurations can also block specific traffic types that can make hacking much more difficult. These configurations do not allow hackers infinite login and password guesses before a firewall blocks an attacker’s IP address.

 Physical Security

An easy way to gain access to a network is to walk in and physically plant a computer on the network that can be accessed remotely for hacking internal systems. Many companies spend copious amounts of money on firewalls, (IPS) and other mechanisms to prevent hackers from getting through firewalls, but do not focus on the internal network. An internal attack is harder to detect and is easier to carry out because these attacks do not go through the Internet and bypass the detection systems that focus on external attacks coming from the Internet.

Many clients we have worked with did not have adequate physical security in place that challenged people they did not know. This made it easy for intruders to gain access to the internal network. Once a computer is on the network, various free tools are run to find data that can be used to gain access to administrative accounts, which provide full access to a company’s computing environment. Users typically store passwords in unencrypted spreadsheets, which can act as a gateway for accessing the entire environment.

Avoiding Common Pitfalls: ‘If It’s Easy for Users, It’s Easy for Hackers’

User education is key to an effective security strategy. Users are the easiest way to breach all the best security processes installed at plant locations if simple passwords are used to log into plant systems. User IDs and passwords should follow best practices by requiring them to be complex and expire on a set interval.

Physical security measures should require badge access to sensitive areas, preventing access to sensitive areas for “guests” and educate users to not hold doors open for people (i.e., tailgating). Users need to be comfortable to question and challenge someone they do not know if they are unescorted.

An effective patch-testing strategy should be implemented to address security vulnerabilities. Address critical issues quickly and implement a schedule for dealing with other vulnerabilities within a set time interval. The longer a security issue goes unpatched the easier hackers can gain access to the environment.

Networks and computing environments require constant updating to mitigate risks of hackers targeting a network. Keeping up to date on exposures will help mitigate cyber attacks.

The opinions expressed within this article are the personal opinions of the author. The facts and opinions appearing in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Lockheed Martin extends partnership with Guardtime Federal

Lockheed Martin

Lockheed Martin, a security and aerospace company, recently announced that it has extended its partnership with cybersecurity firm Guardtime Federal to integrate enhanced cyber-related capabilities into its aircraft products and systems. The new contract will focus on strengthening the cybersecurity for information supply chain around operational aircraft network systems.

The two companies have been working together since 2015 and are now looking to get involved into more operationally oriented pilots to address data manipulation threats in the cyber physical systems. “Our collaboration with Guardtime Federal continues to yield fresh new approaches to solve the lingering challenges that more traditional technical solutions have not solved,” said Lockheed Martin Aeronautics Engineering and Technology Vice President Ron Bessire.

David Hamilton, president of Guardtime Federal, said, “At Guardtime Federal we continue to appreciate the support Lockheed Martin has provided to allow us to focus on Cyber Integrity. Our goal is to provide every Soldier, Sailor, Airman, and Marine the confidence that they can rely on the information they see and the equipment they operate without fear that it has been manipulated by an outside force. There is no overnight solution, but this is the objective of our work with Lockheed who shares our ‘Cyber Integrity First’ core value.”

Lockheed Martin is one of nine companies that worked with Britain in 2017 to strengthen their country’s cybersecurity structure. This Defense Cyber Protection Partnership looks to implement controls and share threat intelligence to increase the security of the defense supply chain.

Mexican banks put on alert for potential cyber attacks

Central bank of Mexico

In response to the recent cyber attacks on the banks, Mexico’s financial authorities advised local banks and financial institutions to strengthen their cybersecurity systems.

Mexico’s central bank, Finance Ministry and banking regulator said in a statement that the financial systems were working normally alert has been sent as a prevention measure. No reasons behind the alert were mentioned. However, Reuters quoted a financial official, who wished to stay anonymous, saying Mexican authorities detected a cyber threat looming on the banking system.

“This type of communication with financial entities will be part of the habitual operation of the system,” the financial authorities said in their Friday statement, referring to the multi-entity effort.

On May 21, 2018, the central bank of Mexico notified that Mexican banks have suffered massive breaches where hackers may have siphoned $15 million from different banks through fraudulent transfers. The bank declined to name the banks but informed that there are three banks, a broker and a credit union. It is still unclear how thieves managed to pull the money out in cash.

Alejandro Diaz de Leon, the Governor of Bank of Mexico informed that authorities were still deciphering the activities of cyber criminals and are investigating the matter. According to him, preliminary estimates suggest irregular transactions amounting to $15 million. Some of which hasn’t been withdrawn and can still be recovered.

India’s first cybersecurity and drone research center opens

cybersecurity pressure

The Indian state of Uttarakhand recently launched a cybersecurity and drone research center in Dehradun. Inaugurated by the Chief Minister of Uttarakhand, Trivendra Singh Rawat, the country’s first cybersecurity and drone application center will offer technical education to the local youth and police officials. The new facility is established with the support of National Technical Research Organisation (NTRO) and Uttarakhand Government.

“At the center, certificate courses on drone application and cyber security will also be conducted for students, which will help them land employment,” Rawat said. The center will also be useful in keeping an eye on disaster situations.

“Such high resolution (drone) cameras that have an easy access to inaccessible hilly terrain will also be able to locate dead bodies of those killed in natural calamities. Similarly, officials of different security agencies trained in cybersecurity could also keep an eye on the elements that misuse social media and also those involved in cybercrimes,” he added.

Earlier this year, the Indian state of Andhra Pradesh unveiled the Cyber Security Operations Center (CSOC) in the capital region of Amaravati. The center is aimed at averting threats looming over the region’s cyberspace. “The Center will combat cybersecurity threats and provide real-time intelligence sharing and threat analysis to all state government departments and entities,” N Chandrababu Naidu, Chief Minister of Andhra Pradesh, said in a statement. “At the heart of the security operations center (SOC), is a blended security analytics platform that ingests, correlates and analyses massive amounts of data. The state has also roped in Pricewaterhouse Coopers (PwC) as cybersecurity consultants to the Government in helping the state frame and adopt best-in-breed practices and frameworks in this domain.”

Georgia opens collaborative cybersecurity center

Georgia, Atlanta

Georgia’s $100-million collaborative cybersecurity center recently opened with a grand ceremony. It’s the single largest investment by a US state government in a cybersecurity facility to date. Located on Augusta University’s Riverfront Campus, the new cybersecurity center strengthens Georgia’s reputation as a cybersecurity force.

Spearheaded by Governor of Georgia, Nathan Deal, the new facility is a collaborative partnership that includes Augusta University, Augusta Technical College, the University System of Georgia’s research institutions, the City of Augusta, the Georgia Bureau of Investigation, and Georgia Department of Defense, and other private partners.

“There are times in life when opportunities present themselves. We’ve seized the opportunity to do something about cybersecurity,” Nathan Deal had said in a statement earlier this year. Only one of the two buildings in the facility is now operational. The operations in the other building would start by end of the year, according to a report.

In recent times, the cybersecurity market witnessed various inductions of cybersecurity centers globally. On June 26, 2018, the world’s first cyber innovation center, located in the Queen Elizabeth Olympic Park in London started operating. The £13.5 million London Office for Rapid Cybersecurity Advancement (LORCA) is funded by the government and will help in the development of technology for protecting the country against cyber threats.

The LORCA will be run by Plexal from its Here East headquarters and will support UK’s entrepreneurs to come up with innovative solutions to resolve cybersecurity challenges.  It’s estimated that the innovation center could also generate around 2000 job opportunities in the UK.

Scottish experts team up with Censis to evaluate cybersecurity risks to IoT devices

IoT devices

The experts from Edinburgh Napier University and US electronics manufacturer Keysight Technologies are working on a new project to assess the vulnerabilities of Internet of Things (IoT) devices to cyber attacks. The 12-month project maintained by the Innovation Centre for Sensor and Imaging Systems (Censis) will use data analytics to create an outline for manufacturers to estimate the risks associated with different IoT devices.

The new cybersecurity drive is supervised by Professor Bill Buchanan from Edinburgh Napier. “The biggest thing holding back the development of the IoT is security – specifically, concerns about the vulnerabilities of devices, the ease of hacking them, and the consequences of such hacks. In health care, for example, IoT could transform the way we monitor health and manage conditions like asthma. Only if we can improve confidence in IoT security can we realize the potential of smart technology.” Buchanan said in a statement.

A recent survey revealed that many manufacturers slow to adopt the internet of things. The 2018 Manufacturing Report from professional services firm Sikich found that fewer than 10 percent of those surveyed currently use internet of things technologies. Further, 30 percent said they have no clear understanding of the internet of things.

The report also revealed warning signs for manufacturers when it comes to protecting their data and intellectual property. Though more than three-fourths of respondents said they had not experienced a cybersecurity incident in the last 12-18 months, only 19 percent of respondents say they are “very ready” to address cybersecurity risk. Sixty-three percent of respondents believe they are only “somewhat ready.”

 

Few minutes with Larry Sobers

Contributed by Renee Small

Like many of today’s cyber security professionals, Larry Sobers began his career outside of information security as a PC tech and then a Windows systems admin. Encounters with a computer virus put Larry on his present path to security leader.

Early in his career, Larry was able to custom-build a 486 computer system, which he then put to use connecting with AOL so he could download games to share with friends. As it turned out, one of the games he downloaded had a Stoned.Monkey boot sector virus contained in it, so his system began acting strangely, to the point that he could no longer access his CD-ROM drive.

To solve this concern, Larry replaced his hardware, then re-installed his operating system, and while his PC initially seemed to operate normally, it again began acting up. Larry then did his research, asking amongst his friends as well as searching online, before installing an anti-virus program, which revealed the culprit to be a copy of a variation of the Stoned.Monkey virus.

Larry was able to remove the virus from his computer and from his diskettes, but the incident troubled him. He thus continued to research ways on how protect his PC, and also applied the lesson learned in his work, where he and his manager began checking the company’s network with open-source tools; and it was from there that Larry began his career in information security.

“My goal is always to build a cohesive, high-performing team,” Larry says of his objective when heading up security departments. To this end, Larry hires, in addition to people with security experience, people who have had no experience with information security, which can sometimes raise concerns with team members. “I have occasionally faced challenges from other members on my hiring team as there is sometimes concern about bringing in personnel with a lack of Information Security experience.  However, my philosophy is that the overall team concept allows for a strong candidate who brings in key soft skills like documenting, process, and communication skills that may be missing on the team to be the right fit regardless of their specific Info-Sec experience,” he notes.

Although he uses such traditional methods as LinkedIn, networking, word of mouth and local cyber security forums to search for possible candidates for his team, Larry also uses creative methods to find these candidates. One of the more creative methods he has used was a “hiring blitz,” where Larry worked with multiple hiring managers to interview several candidates for multiple roles within a half-day period. “The blitz works well when you have several roles to fill,” is his assessment of this method.

Larry admits that retention is a challenge, and some of the methods he uses to retain people is by providing flexible work arrangements, planning team-building activities around such activities as video games and puzzle solving, and ensuring that those new to cyber security are mentored. He even conducted a reading club where participants read Clifford Stoll’s Cuckoo’s Nest, which Larry considers a “must read” for those new to cyber security.

Renee Small is the CEO of Cyber Human Capital and author of the Amazon #1 best-selling book, Magnetic Hiring: Your Company’s Secret Weapon to Attracting Top Cyber Security Talent. Download a free copy at www.magnetichiring.com/book. 

Putin calls for collaboration from all nations to fight cyber threats

Putin

While speaking at a cybersecurity conference in Moscow recently, the Russian President Vladimir Putin stressed upon the importance of mutual collaboration from all nations to defend from cyber threats.

“Cyber threats have reached such a scale that they could only be neutralized by combined efforts of the entire international community,” Putin said. “We have repeatedly seen that some nations’ egoism, their attempts to act squarely to their own advantages, hurt the global information stability,” he added without specifying.

Addressing the event, Putin described Russia’s association with European nations for the protection of personal data rules as a positive move toward international cooperation. He specified that there is an increase in the number of cyber attacks on Russia in the first half of 2018 compared to the same in 2017.

Putin also stated that they are developing an automated system that enables enhanced communication between businesses and law enforcement agencies to strengthen cybersecurity. However, the Russian president didn’t speak on the accusations that Russian hackers have intruded in the U.S. 2016 presidential elections.

Earlier, the Russian government experienced similar allegations from other countries. On November 13, 2017, Britain’s Prime Minister, Theresa May had said that Russia was “weaponizing information” and meddling in elections to undermine the international order. Sending a stark warning to Russia, May said “We know what you are doing. And you will not succeed. Because you underestimate the resilience of our democracies, the enduring attraction of free and open societies, and the commitment of Western nations to the alliances that bind us.”

The United Kingdom’s National Cyber Security Center (NCSC) chief Ciaran Martin confirmed that Russian hackers targeted the country’s telecommunications systems, media, and energy networks in the past.

IBM inks $740 million deal with Australian Government to offer data security services

IBM

IBM recently inked $740 million deal with the Australian Government. The five-year extensive deal allows IBM to offer artificial intelligence (AI), cybersecurity, cloud services, quantum computing and blockchain research services to the Australian government.

The contract will see services such as automation and blockchain provided to federal departments including defense and home affairs, IBM’s Asia Pacific head, Harriet Green, said in an interview. The “youth of the technology” and the employment of Australians to support and help the implementation would be hallmarks of the new partnership, she said.

The Australian government stated the fresh contract is proposed to bring automation, digitalization, and positioning of IBM investigation teams to further the use of artificial intelligence, quantum computing and blockchain technology in the government services.

“It shows trust and belief in our ability to transform and provide world-leading capabilities, leveraging our investments locally in AI, the blockchain, quantum, and cloud. We look forward to helping the Australian Government to re-define the digital experience,” said David La Rose IBM’s Managing Director of Australia & New Zealand.

The largest computing firm holds numerous contracts with government organizations globally. On September 7, 2017, the U.S. Army’s Logistics Support Activity (LOGSA) awarded IBM a contract to continue providing cloud services, software development, and cognitive computing, constituting the technical infrastructure for one of the U.S. federal government’s biggest logistics systems.

The 33-month, $135 million contract represents a successful re-compete of work that LOGSA signed with IBM in September 2012. Under that managed services agreement, the Army pays only for cloud services that it actually consumes. The efficiencies created by this arrangement have enabled the Army to avoid about $15 million per year in operational costs.

Washington Metro cybersecurity audit reveals rising vulnerabilities in transit system

Washington Metro

A cybersecurity audit performed on Metro in Washington highlighted that the agency remains vulnerable to attacks that might endanger the security system. The audit report was submitted to Metro’s board of directors in late last month, but the key facts are being kept secret due to the risk from scammers.

“By its nature, such an audit in the wrong hands could expose vulnerabilities and thereby undermine our shared goal of making (Metro’s) IT environment even more secure,” Metro Inspector General Geoffrey A. Cherrington said in a statement. “For that reason, we have made an exception to our standard practice of posting audits to our website, and this one will be withheld from release.”

The report specifically mentioned the Metro’s incident response measures and whether the security experts in the agency know how to detect and respond to a cyber attack. In a response to the report, the Metro officials announced that they’re focussing on the security improvements in the entire transport system.

There are various incidents of cyber attacks on transport system earlier. On October 24, 2017, Ukraine’s Odessa airport and metro system in Kiev was targeted by a malware called “BadRabbit” and prompted state-run Computer Emergency Response Team (CERT) to ask transport networks to be on alert. However, the country’s banking services remained unaffected.

Kiev metro system reported that its payment system was attacked while Odessa airport said it had to delay some flights, as it beefed up its security arrangements. Ukraine suspects that its neighbor Russia is behind these cyberattacks and is planning to draft a national strategy to overcome such attacks and to keep major institutions and companies safe.