Big Data. Big Decisions
InformationWeek
Special Coverage Series

Commentary

Mathew J. Schwartz

Mathew J. Schwartz



Next DIY Stuxnet Attack Should Worry Utilities

The recent water system hack in Illinois points to the dangers of insecure, Internet-connected industrial control systems. Environments like this can't ignore known security weaknesses anymore.

Safety: That's the first and last word for chemical manufacturing, gas refining, nuclear energy production, or any other environment that's managed using industrial control systems. Quite rightly, the mantra means physical safety. But as recent incidents illustrate, it often fails to include digital security, and that can have physical safety repercussions.

Case in point: A months-old hack of an Illinois utility's control system wasn't discovered until earlier this month, when a water pump that an attacker apparently set to repeatedly turn on and off finally burned out. The Department of Homeland Security, however, downplayed the implications of the attack. "At this time there is no credible corroborated data that indicates a risk to critical infrastructure entities or a threat to public safety," read a DHS statement.

More Insights

Webcasts

More >>

White Papers

More >>

Reports

More >>

But security experts beg to differ. "This is a big deal," industrial control system expert Joe Weiss told The Washington Post. "It was tracked to Russia. It has been in the system for at least two to three months. It has caused damage. We don't know how many other utilities are currently compromised."

While U.S. utilities have previously been spared from such attacks, the failure of a control system for any reason can be deadly. For example, in 2009, an automated control system installed at Russia's largest hydroelectric facility, the Sayano-Shushenskaya plant, failed to regulate a poorly maintained, 1,500-ton turbine, which ripped free from its moorings and shot 50 feet into the air, before crashing down and causing massive destruction and flooding inside the facility. Ultimately, 75 people died.

Alarmingly, the hack of the Illinois utility appears to have involved a negligently maintained industrial control system environment. How else to explain the hacker's ability to exploit phpMyAdmin, an open source MySQL front end that was connected to the utility's control system? At last count, the tool has had 105 known vulnerabilities, making it a prime candidate for never being brought anywhere near a control system environment.

Why aren't utilities treating information security with more respect? An April study from Ponemon--sponsored by security information and event management vendor Q1 Labs (which was purchased by IBM last month) found that utilities and energy companies spend about 10 times more on physical security than on information security.

The failure by DHS, the utilities that run the critical infrastructure, as well as control system manufacturers to own up to the broader implications of the Illinois utility exploit have led one hacker, who uses the handle "pr0f" and sports a Rumanian email address, to hack into a utility in South Houston, Texas. Thankfully, he simply published screen shots of the control system. "No damage was done to any of the machinery; I don't really like mindless vandalism. It's stupid and silly," he said in a Pastebin post. "On the other hand, so is connecting interfaces to your SCADA machinery to the Internet. I wouldn't even call this a hack, either, just to say. This required almost no skill and could be reproduced by a two-year old with a basic knowledge of Simatic."

If Siemens Simatic systems sound familiar, that's because they were exploited by Stuxnet. According to a recent DHS report, even members of Anonymous had tested Siemens Simatic control system software for potential weaknesses, although the agency rated the likelihood of the group actually attempting to exploit control systems as slim. But just as attackers or security researchers can easily search for websites or Internet-connected photocopiers with known vulnerabilities, so too can would-be industrial control system hackers search for Internet-connected systems with known bugs.

But this warning has been sounded before. Long before pr0f hacked South Houston or Stuxnet targeted Iranian nuclear refineries, security researchers were warning that exploiting the programmable logic controller (PLC) used in industrial control systems isn't very difficult. At the Black Hat conference in Las Vegas earlier this year, furthermore, security researcher Dillon Beresford of NSS Labs decided to see how difficult it might be to create his own version of Stuxnet. He found that with less than three weeks of work, and spending about $10,000 to replicate his target hardware environment, he was able to successfully exploit a Siemens Simatic S7 PLC.

His aim wasn't to create Stuxnet 2.0. "The real motivating factor was really to try and show the public that it's really not that complicated, these types of attacks, and that most people with enough time and resources could really pull this off," said Beresford. One big problem, he said, is that few if any PLCs use any type of effective access control system.

John Pollet of Red Tiger Security--also speaking at Black Hat--agreed with Beresford's assessment, noting that while the Siemens Simatic requires a password before it will execute remotely sent commands, many control systems lack even that level of protection. That's perhaps not surprising, since many PLCs were designed before the Internet was ever adopted. "Some of the systems that we conduct assessments on are older than me," he said. "PLCs that have been running oil-cleaning facilities for over 30 years, they rarely break."

But besides lacking passwords, none of the systems have simple network management protocol (SNMP) either, meaning there's nary a digital paper trail. "You can chuck forensics out the door," said Pollet. As a result, and as the incidents in Illinois and Russia illustrate, the first sign of software failure--due to an attack or otherwise--may not be until something physical fails. Does anyone think that's safe?

Sensitive customer and business data is scattered in hidden corners of your infrastructure. Find and protect it before it winds up in the wrong hands. Also in the new issue of Dark Reading: The practical side of data defense. Download the issue now. (Free registration required.)



Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

BYTE encourages readers to engage in spirited, healthy debate, including taking us to task. However, BYTE moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. BYTE further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.

Follow InformationWeek

By The Numbers

What Are Your Primary Concerns About Using Big Data Software?

Base: 417 respondents at organizations using or planning to deploy data analytics, BI or statistical analysis software
Data: InformationWeek 2013 Analytics, Business Intelligence and Information Management Survey of 541 business technology professionals, October 2012

What Do You Think?

What's your attitude about SQL analysis on top of Hadoop?
We want fast, standard SQL analysis capabilities on Hadoop ASAP
Hadoop is for unstructured data; SQL is for relational databases
We'll give SQL on Hadoop a try, but relational DBs will remain the mainstay
Given strong SQL support on Hadoop, we'd nix the data warehouse
We're not interested in Hadoop
No opinion



Related Content

From Our Sponsor

Five Big Data Challenges and How to Overcome Them with Visual Analytics

Five Big Data Challenges and How to Overcome Them with Visual Analytics

Business leaders often need a visual snapshot of data to quickly grasp and use it. This paper identifies five challenges in presenting data and how visual analytics can resolve them. Solutions are suggested to overcome the challenges of: speed, data clarity, data quality, displaying meaningful results, and dealing with outliers.

Game-Changing Analytics: How IT Executives Can Use Analytics to Create Innovation and Business Success

Game-Changing Analytics: How IT Executives Can Use Analytics to Create Innovation and Business Success

Today's competitive advantage requires a deeper understanding of your business, your market and your customers. As an IT executive, you can drive that knowledge transformation. In this white paper, learn how to make decisions as a strategic business leader and three steps to begin an analytics initiative within your enterprise.

Data Visualization Techniques: From Basics to Big Data with SAS Visual Analytics

Data Visualization Techniques: From Basics to Big Data with SAS Visual Analytics

High-performance data visualization turns sophisticated analyses into meaningful graphics, leading to faster and smarter decision making. In this white paper, learn how visual analytics can transform big data, with additional features such as real-time functionality, mobile compatibility, robust applications for technical groups and accessibility for nontechnical users.

Big Data: Lessons from the Leaders

Big Data: Lessons from the Leaders

Financial performance, competitive advantage, operational efficiency, strategic decision making - every business goal can extract value from big data, and the time for doubt or inaction has long passed. In this Economist Intelligence Unit report, in-depth interviews with data pioneers reveal the link between the effective use of big data and the bottom line among other results.

Decision-Driven Data Management: A Strategy for Better Decisions with Better Data

Decision-Driven Data Management: A Strategy for Better Decisions with Better Data

Which came first, the data or the decision? This white paper makes the case for having a decision in mind, then tailoring big data's volume, variety and velocity to achieve business results such as overcoming customer dissatisfaction or creating well-informed strategies in real time.

Informationweek Reports

Research: The Big Data Management Challenge

Research: The Big Data Management Challenge

The challenge of big data is real, but most organizations don't differentiate 'big data' from traditional data, and nearly 90% of respondents to our survey use conventional databases as the primary means of handling data. We'll help you understand what constitutes big data (it's not just size) and the numerous management challenges it poses.