Wednesday, May 22, 2019

ICS under serious risk from a wormable Windows Vulnerability


The most recent patch from Windows, May 2019, [1] fixes around 80 different vulnerabilities, among of them is the CVE-2019-0708 which is, according to Microsoft “An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.”, meaning it can be wormable and get full control of the remote device, I repeat get control of the remote device by using the Remote Desktop Protocol (RDP) formerly known as Terminal Services.

It is well known that a particular vulnerability is critical when Microsoft decides to patch their unsupported Windows versions, it is the case now, and Microsoft released patches for Windows XP, Windows 7, Windows Server 2003 and Windows Server 2008.

Although we know there is a large amount of Windows 7, even Windows XP, devices in the wild, as well as Windows Server 2003 and 2008, a good portion of this are still working in Industrial Control Systems, either as HMIs or as part of the SCADA infrastructure. An interesting statistic is provided by CyberX Labs indicates that after analyzed traffic from 850 operational technology systems, which are used to manage factory production lines, gas monitoring, and other types of industrial operations. Researchers found that 53 percent of them run unsupported versions of Windows, many of which are likely affected by the just-patched vulnerability [2].

One of the reasons behind this decision is that Control Software Manufacturers decide to use the available Operative System (OS) in the development moment and tuned specific libraries or software packages in order to get the most of the OS. When patches are available is usual that manufacturers recommend customers to wait until testing is completed and the possible impact is assess and addressed. Once that happened, they decide to release the package to customers, what is interesting is that in order to minimize the possible impact of patches to the application, due to the reliability required to work in ICS environments, full patching of the OS could not be in the manufacturer scope. Some of the vulnerable systems can be found in Mission Critical Environments, which due to their critical tasks cannot be easily halted in order to be patched. Additional strategies to the patch to protect our organizations are blocking the TCP port 3389 in the Firewall [3].

It is important to understand the criticality of this issue, the exploitation of this vulnerability is not only related to data exfiltration, malicious actors could exploit this and cause a much larger impact affecting negatively our life standards, due to the potential impact to critical infrastructure [4]. Understanding the integration of IT protocols in ICS and its seamless integration into IT Environments, it is completely feasible to enforce the following IT strategies in the ICS Network:

Monitoring
Device monitoring is a well-known and widely used IT strategy in order to increase device visibility for Security practitioners in the enterprise. In the case of ICS, we could use the same strategy in order to define what is not “normal” in the environment and address it in the shortest time.

Network Monitoring
Network segmentation is widely used in order to create specific groups of devices and to isolate them for different reasons. In the particular case of ICS segmentation based on criticality could one solution. The scope of the devices to be isolated requires a deep analysis understanding the industry, its criticality and standards applied.

Establishing controls in ICS is critical to protect not only data, but operations related to the control process.

As usual, prevention, wise use of resources and budget, together with detailed processes and training for Security staff will always be the pillars where our security strategy could rest confident of being protected.


References

[1] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708
[2] https://arstechnica.com/information-technology/2019/05/microsoft-warns-wormable-windows-bug-could-lead-to-another-wannacry/
[3] https://www.securityweek.com/wormable-windows-rds-vulnerability-poses-serious-risk-ics
[4] https://www.nist.gov/cyberframework/critical-infrastructure-resources

Tuesday, February 26, 2019

Japanese Government to probe insecure IoT devices - Part 2



Japanese Government to probe insecure IoT devices - Part 2

The Japanese government released the technical details regarding the IoT probing devices. Here is an extract of the most important information.

Starting date: February 20, 2019.

Important Contents:

Scope of the probe:
  1. Devices that can be accessed from the Internet using IPv4 addresses assigned to the Japanese territory
  2. Easy to guess ID and password
  3. Devices without a password
  4. There are about 200 million devices that match the above mentioned scope
  5. Devices: routers, web cameras, sensors, etc.
The National Institute of Communications and Technology (NICT) is going to use an approximately a set of 100 IDs and Passwords for this investigation. Here are the samples published in the referred site [1].

Commonly used for Cyber attacks

ID Password
admin admin
admin1 admin1
root root
supervisor supervisor


Identical characters, consecutive numbers, etc.

ID Password
admin 111111
root 123456
root 666666
root 54321
888888 888888

IP addresses to be used in the investigation

150.249.227.160-175

153.231.215.8-15

153.231.216.176-183

153.231.216.184-191

153.231.216.216-223

153.231.226.160-167

153.231.226.168 to 175

153.231.227.192 ~ 199

153.231.227.208-215

153.231.227.216-223

153.231.227.224-231

(96 total)

Communication:

In the case a device is identified, a communication will be sent to the ISP/owner of the IP.


References:

1. In Japanese https://notice.go.jp/
2. In Japanese https://www.nict.go.jp/info/topics/2019/02/13-2.html



Saturday, February 16, 2019

Japanese Government to probe insecure IoT devices



Japanese Government to probe insecure IoT devices


The Japanese government passed a law in which authorized to the National Institute of Communications and Technology (NICT) to use dictionary-alike attacks to IoT devices around the nation. Basically, default passwords list, overuse ones and easy to guess passwords will be used from February 2019 against internet-discoverable devices indistinctly of being public or private. The reason of this decision is to improve preparedness for different important events coming to Japan from this year:
  1. The new emperor coronation in April, which also will change the Era name in Japan from the current one Heisei to a new one that will be decided.
  2. The Rugby World Cup from September 2019, this is consider a rehearsal for the most important even next year.
  3. Tokyo Olympics in 2020, this is the main reason behind the decision of the government to take action this year finding weak passwords in IoT devices.

Additional concerns are coming from enterprises, the reason is simple, these activities could generate alerts in enterprise infrastructures depending on their configurations and monitoring level.
Therefore enterprises are concern; since the probing activity might use the same techniques and possible tools than potential malicious actors, moreover no technical details have been shared; therefore there is no way to correctly identify and whitelist (which could lead us to a very different discussion) the “suspicious” traffic, in this case attackers could use this probing activities in order to hide in plain sight. Security teams and SOCs are concern and expecting an increase of traffic.
This activity could prove itself useful, but at the same time bad actors could potentially take advantage. From behind all perimeter defenses, hopefully enterprises are ready and well organized for this, especially since they had 4 years to improve their infrastructure, process and human resources to face these activities.

References
  1. https://www.darkreading.com/attacks-breaches/japan-authorizes-iot-hacking/d/d-id/1333745
  2. https://threatpost.com/japan-insecure-iot-devices/141304/
  3. https://www.itpro.co.uk/policy-legislation/32848/japan-law-will-allow-government-to-hack-civilian-iot-devices




Tuesday, October 9, 2018

Increasing unsecured CIS levels




For edges, Industrial Controls were use in isolated modes, comparable to islands with an ocean between them, where there was a lack of transport media to establish communications between them.


After the boom of the Internet, senior managers wanted to have production statistics in almost real-time, which pushed the convergence of devices like: PLCs, DCSs or SCADAs and standard IT infrastructure, in order to communicate specific data to office buildings in sometimes remote areas, where those managers where located.

Most of the mayor players at that moment, decided to produce friendlier systems that could extract specific production information and located in a Database for the data to be accessible and able to be manipulated and formatted in specific “interesting” charts. In this young scenario the number of layers was limited to Sensor networks, control network, control management and couple of layers to be able to connect to the database.

Forwarding until our time, the above doesn’t look so much of a challenge anymore, but the different layers introduced above the control management, which in small terms represents a fully-fledged IT infrastructure, with all the pros and cons included, creates a much more complex environment in which the shared space between IT and ICS will become invisible in time.

In the case the IT area is correctly controlled and security controls are in place, the communication path to the lower ICS could be safe, but in real life that is not so common.

It is more common to find partially secure IT Networks with a much unclear level of Security in the ICS levels, giving a skillful attacker potential number of vulnerabilities to exploit that could lead to the discovery of the less Secure ICS network.

The damage? As many articles refer to, could be catastrophic not because of the security case itself, but more alarming, related to the physical damage that can be triggered if e.g. a power plant is compromised, a nuclear plant loses its basic control, main generators are damaged, etc. Those real-life consequences could have a bigger impact in an already defenseless population that won’t fully understand how to react.

Protecting IT infrastructure is already a challenging task, adding the ICS Security on top of that, and the tasks become not only more difficult but it will require different teams, IT Security, IT infrastructure, ICS Security, etc. to work together, which in some cases that itself is a human vulnerability.


Monday, August 27, 2018

The knowledge gap



Industrial Control Network (ICS) Security is a relatively new field, in which there is a growing knowledge gap among its different actors, in one side we have usual Control Systems devices and interconnecting networks with all their own complexity and particular problems/challenges, and in the other side we have the Information Security area in which by its current state is having a growing skills shortage. Moreover, an additional level of complexity is added when different non-standardized networks are working together in an Ethernet based network architecture, which is the case of different types of sensors sending digital signals (or digitized analog signals) through usually proprietary industrial networks to control devices, such: PLC, DCS, etc and from this to much more complex and once again non-standard SCADA systems; from which management can take different kinds of  processed or unprocessed data through standard Network devices to a specific or wide audience depending on the company structure.

Having that amount of devices, non-standard industrial networks, standard network devices, and proprietary network protocols doesn't make any easier different security related processes as risk assessment, vulnerability management, patching, logging and monitoring, etc., moreover the result of a Cyber Security Incident in ICS could humans life, e.g. Stuxnet [1],  and other attacks [2].

In an additional note, Incident Response will be heavily impacted in the first triage due to the above unique characteristics ICS Security has.

Although there are efforts towards the creation of a much wider curriculum that could create professionals with knowledge in both areas, finding professionals with both skills set is a growing challenge.

From other point of view this allows professionals from both areas, Control Systems and Information Security, to work together to find solutions in their own areas, although that could represent an additional cost for companies/organizations.

Critical infrastructure companies and governments should get together in order to create a collaborative platform in which support can be given according to specific needs. This is being done in many countries, but the efforts should be rapidly followed by the rest of the world.

References:
1. https://en.wikipedia.org/wiki/Stuxnet
2. https://www.cbronline.com/cybersecurity/top-5-infrastructure-hacks/



Tuesday, July 24, 2018

Addressing the Cyber Security Talent Gap



Addressing the Cyber Security Talent Gap

In our current digital dependent society, where technology changes quickly and threats are ahead of the most common Security Controls, Security professionals play a fundamental role securing our most valuable asset, our data. Moreover, from the enterprise point of view, customer and company data represent the most valuable commodity requiring strict controls and well-defined policies.

In this regard, the shortage of Cyber Security professionals is not clear among the different actors in our business, some indicated that is between 1 to 3 million globally [1], others indicated more than 3 million [2], or 1.8 million [3], and all of them agree that the number is growing every year.

Something clear in those statistics is that the number of Security professionals required by the market is just increasing in time. Accepting the fact, what could be the possible solutions to this problem? Many are proposed, like: investing in early talent, creating your own talent pool proposed by CISCO [4] or the Hitachi approach [5], among others.

Currently, institutions like Homeland Security are providing free access educational tools to teachers and students, these tools can be easily integrated into a much wider spectrum courses, e.g. IT University Courses/Curriculum [6]. The latter represents a slight problem. Few Academic Institutions have Cyber Security/Information Security formal programs in their current offer. Moreover, IT professors with Cyber Security/Information Security specialization are few compared to other more popular courses/careers.

I think that specific changes have to happen in order to improve the talent that decides to go to a Cyber Security Career, some of them are:

  1. Encourage academic institutions to adopt material already available like the one provided by Homeland Security and include them in the Cyber Security curriculum, another valuable source of information is SANS which provides a series of videos in their Youtube channel that could be used as a reference.
  2. Slowly make efforts towards the image improvement of Cyber Security professionals, in which due to different characters portrayed in the TV or movies, make us look like people that could not interact with society and having serious communication problems with it, where in reality, Cyber Security is much more than technical knowledge alone, it requires a series of soft skills in order to correctly communicate and translate the different Security requirements to senior managers, either in Enterprise size companies smaller companies.
  3. Promote, either from the private or public sector or together, the participation of students in Cyber Security related events, like Hackathons. Those experiences could create interest among students to pursue a Cyber Security career.
  4. Enterprise size companies and big companies, which uses different specific Security tools to protect their infrastructure, could get talent from another IT areas interested into a career shift. The big advantage of this strategy is to collect multidisciplinary talent that could provide a different point of view regarding security strategies and policies, improving the general security posture of the company.

Private and public institutions need to work together to find a common ground to solve this talent gap problem since its jeopardize our information in general spite of being private or public.


References
[1] https://gblogs.cisco.com/ch-tech/closing-the-cyber-security-talent-gap/?doing_wp_cron=1530863459.5774390697479248046875
[2] https://www.darkreading.com/careers-and-people/bridging-the-cybersecurity-talent-gap/a/d-id/1331858
[3] https://www.scmagazineuk.com/skills-security-fighting-shortage-closing-gap/article/1473363
[4] https://gblogs.cisco.com/ch-tech/closing-the-cyber-security-talent-gap/
[5] https://www.hitachi-systems-security.com/blog/talent-shortage-in-cybersecurity/
[6] https://www.dhs.gov/education-cybersecurity-careers

Thursday, June 14, 2018

Welcome to my blog!

Embed from Getty Images


Welcome to my blog!

Hello, I am Dennis Ludena, I am a electronic Engineer with specialization in Control systems from Peru and I am a Ph.D. holder in the area of Information Security from Japan.

This blog its meant to keep you update with the latest Industrial Control Security news, comments and trends worldwide, in a comprehensive but easy to understand manner. Industrial Control Security is a relatively new topic which is the intersection of two big specialization areas such: Control Systems and Information Security.

Due to its novelty, professionals in both areas were not able to cope with the rapid increments of solutions from both sides. In one side we have Control Systems that, due to business requirements, needed to share plant data using the internet, and in the other side we have Information Security that it is mostly focused in the classic PC-based model threat detection and analysis.

Threats like Stuxnet and experiments like the Aurora Generator Test conducted by the Department of Homeland Security in 2007, in which a generator was hacked and disable due to overload to demonstrate how a cyber attack could destroy physical components of the electric grid; gave the alarm to increase security controls in any Smart Grid related or critical infrastructure [1, 2].

During the last decade different controls were put in place in order to protect this critical infrastructure, but, as the same as Information Security, talent is scarce in the market jeopardizing efforts and the development of new detection techniques.

Hope you will find this blog useful for your purposes.

Enjoy!!!

[1] The Aurora experiment Link

[2] Stuxnet Link


¡Bienvenido a mi Blog!

Hola, mi nombre es Dennis Ludeña, soy Ing. Electrónico con especialización en Sistemas de Control de Perú y tengo un Doctorado en Seguridad de la Información de Japón.

La razón de este blog es de mantenerte actualizado con las últimas noticias relacionadas con el área de Seguridad de Sistemas de Control, comentarios y tendencias alrededor del mundo, de una manera exhaustiva pero fácil de entender. La Seguridad en Sistemas de Control es un tema relativamente nuevo que es la intersección de dos grandes áreas especializadas como lo son: Sistemas de Control y Seguridad de la Información.

Debido a su naturaleza reciente, profesionales en ambas áreas no pudieron hacer frente a los rápidos incrementos de soluciones de ambas áreas. Por un lado tenemos los Sistemas de Control que, debido a requerimientos corporativos, necesitan compartir la información de planta usando la internet, y en el otro lado tenemos a la Seguridad de la Información la que está principalmente enfocada en un modelo clásico de detección y análisis de amenazas basado en PCs.

Amenazas como Stuxnet y experimentos como la Prueba de Generador Aurora realizado por el Departamento de Seguridad Nacional en el 2007, en el cual un generado fue hackeado e inutilizado por sobrecarga para demostrar con un ataque Cibernético puede destruir componentes físicos de la red eléctrica, dio la alarma para poder incrementar los controles en cualquier Sistema de Red Inteligente o infraestructura crítica [1, 2].

Durante la última década diferentes controles fueron puestos en marcha para proteger esta infraestructura crítica, pero, como sucede en Seguridad de la Información, el talento es escaso en el mercado poniendo en peligro los esfuerzos y el desarrollo de nuevas técnicas de detección.

Espero encuentres este blog útil para tu propósito.

¡¡¡Disfrútalo!!!

[1] El experimento Aurora Enlace
[2] Stuxnet Enlace



The importance of Information Security in our lives – Part 6

  6. In our relaxing time In these moments even our relaxing time is related to the use of a PC or to an streaming service, we should be mor...