Sunday, March 27, 2016

Securing the Critical Infrastructure Enterprise

When we first discussed security as a critical component of Enterprise Architecture, it was in the context of the cyber attacks on the personal and financial information that hurts individuals and business brands, ultimately  translating into billions of dollars lost. This reflection however, even goes farther beyond this context, with larger losses, and presents the biggest scale of cyber security threats. 

Cyber Attack Vectors

On March 4, 2007, the Idaho National Laboratory demonstrated the so-called Aurora vulnerability, to show how an attack which gains access to a controller, can cause physical damage to components to critical infrastructure like the power grid. Although the Aurora exploit is essentially an electrical (physical) event, the current use of networked software controlled technologies allows the exploit to be caused by a cyber attack.  This Aurora type of attack should not be confused with the 2009 cyberattack on top silicon valley companies similarly called "Operation Aurora". Indeed in 2014, there was that confusion which inadvertently led to DHS records folks to release classified information on the 2007 Aurora Idaho experiments. But that is a completely different story.

Fast forward to December 23, 2015, when a significant portion of western Ukraine lost power for nearly 6 hours. ICS-CERT (US DHS) reports that power outages were caused by remote synchronized cyber intrusions at three regional electric power distribution companies (all from Oblenergo). Experts attribute the cyberattack to the Russian 'Sandworm' hacker group, enabled through email spear phishing and malware (BlackEnergy) as an initial access vector to acquire legitimate credentials. Extensive mapping of the system may have been done prior to actual attack, enabling shut down of the systems. Indications showed execution of the KillDisk malware towards the end, which erases selected files on target systems and corrupts the master boot record, rendering systems inoperable. The attack disabled company phone systems, blocking customer outage reports; disconnected backup power supplies, delaying recovery and restore procedures.   

Impact:  Close to 50%  of its 538,000 customers: Prykarpattya Oblenergo, reported 27 of its substations went dead, 103 cities were "completely blacked out," and another 186 cities were left partially in the dark. 

Cascade Effects:  Observers have placed a plausible assumption that this is a Russian retaliation for the anti-Russian attacks on the power grid supplies to the recently annexed Crimea (by Russia in 2014).  Interestingly, the Ukrainians may have been saved by the fact that their country relies on old technology and is still not as fully wired as many western nations. Oblenergo eventually switched to manual controls and dispatched teams around the region to manually flip switches back "on," ending the outage within a few hours. In retrospect, the attack may have been merely a signal warning. But  the crash adequately illustrated the potential damages to grid-dependent physical infrastructures, loss of economic production, environmental damages, theft and chaos, as well as significant deaths and casualties. Ultimately, the exploit shows that the power grid itself is a critical attack vector -- a conduit to disable other critical infrastructures, expose the state to more attacks, lead to a possible kinetic cyberwar, and dangerously heightened escalations of political conflicts in the region. This was the first time that a known Aurora type exploit was actually executed -- and executed by a nation-state.

More details at: https://ics-cert.us-cert.gov/alerts/IR-ALERT-H-16-056-01

Critical Infrastructure Sectors

The Department of Homeland Security has designated 16 critical infrastructure sectors and defines these as enterprises whose assets, systems, and networks, whether physical or virtual, are considered so vital to the United States that their incapacitation or destruction would have a debilitating effect on national security, economic stability, national public health or safety.  These includes key industry players in the following sectors:  1.) Chemical  2.) Commercial Facilities 3.) Communications 4.) Critical Manufacturing  5.) Dams  6.) Defense Industrial Base  7.) Emergency Services  8.) Energy  9.) Financial Services  10.) Food and Agriculture  11.) Government Facilities  12.) Healthcare and Public Health  13.) Nuclear Reactors, Materials, and Waste  14.) Transportation Systems  15.) Water and wastwater  16.) Information Technology. 

The Information Technology Sector includes those functions which produce and provide hardware, software, systems and services which in tandem and collaboration with the Communications Sector,  develops and operates the vital backbones of  the Internet. As the world and industries continue to form their dependencies on computer technologies and the internet, the IT infrastructure has become a significant part of critical infrastructure security. 

More details at: https://www.dhs.gov/critical-infrastructure-sectors

Enterprise Architecture Framework for Critical Infrastructure Enterprises

Given these discussions, it is clear that a Cyber Security Architecture for Critical Infrastructure should be a significant component of the enterprise architecture framework, if the discipline wants to maintain its relevance as a strategic tool.  Risk management and cyber security must be essential EA components  in order to emphasize and prioritize the development and management of a risk-based integration of compliance controls and technologies, aligned and balanced with business-driven requirements. As newer technologies are introduced to build business capabilities, the security assessment of these technologies need to be in place across the enterprise, to check for security gaps in their adoption policies, vetting procedures, and deployment practice. A Security Framework would enable a prioritized, flexible, repeatable, performance-based, cost-effective approach, ensuring effective deployment of information security measures and controls, in order to help owners and operators of critical infrastructure identify, assess, and manage cyber risk.

The NIST Resources

The NIST  is the forefront security standards body in the U.S. and globally collaborates closely with ISO.  The NIST-800 series provides ample references and frameworks that both public and private organizations can use to implement security architecture for the enterprise.

The mission of NIST's Computer Security Division is to improve information systems security via programs with the following goals:

The NIST site has a rich set of literature resources to assist on the following topics:


More details at:  http://www.nist.gov/itl/csd/

Resilience As a Capability

DHS defines "resilience" as the ability to adapt to changing conditions in order to withstand and rapidly recover from disruption due to emergencies from all hazards including cyber attacks. The development of resilience should include systems hardening, adaptive capabilities, readiness of facilities, and availability of contingency funds and supplies for business continuity and recovery operations. Resilience is operationalized by using systems-thinking within a framework based on the following principles: 1.) Adaptiveness to changing conditions using enhanced collaboration and coordination protocols. 2.) Better adoption of resilient systems with dynamic real-time situational awareness capabilities. 3.) Modernize systems to address industrial control system (ICS) component vulnerabilities.   4.) Rapid response assurance via preparedness programs that place significance on wide participation and public-private partnerships, particularly with other owners and operators of critical infrastructure and key resources.   5.) Improve incident response and reporting capabilities via enhanced sharing protocols for information on cyber threats, exploits, vectors, mitigations, and lessons learned.  6.)  Support and participate in large-scale real-world simulations to assess emergency communications. 7.) Support the adoption of national common industry standards, practices, policies, with compliance to legislative/regulatory provisions. 8.) Strengthen the cyber ecosystem via global networks, international collaborative communities and public-private partnerships to include research institutions and academia.

More details at: https://www.dhs.gov/sites/default/files/publications/qhsr/2014-QHSR.pdf

Conclusion

The attack vectors for cyber exploits can be blocked with better technologies and practices. While more so for critical infrastructure enterprises, regular business organizations should also establish solid security architectures because any enterprise connected to the internet, by default, becomes a potential conduit for attack vectors ultimately trailed towards critical infrastructure. This was sharply illustrated by how Stuxnet was spread.


The ICS Context Industrial Control Systems
A multilayer defense-in-depth architecture, protecting SCADA and PLC's (Programmable Logic Controllers)   Source: Security hardware for industrial networking,  http://www.iebmedia.com/


The Siemens Simatic S7-300 PLC,  Target of the Stuxnet Attack of 2010.

The sophisticated vector was specifically targeted not only for the Siemens PLC, but for that PLC in a specific environment configuration - the Iranian Nuclear Plant.

Source:  PBS video, Cyberwar Threat,
http://www.pbs.org/wgbh/nova/military/cyberwar-threat.html

What EA can do to help.   An effective and highly valuable EA initiative would be to help launch training, awareness, and education of organizations which include, for starters, sound patch management and practical security operations e.g. scanner updates, trojans in attachments, etc.  Moreover, while we revisit the set of presentation materials and toolkits that we have been inspecting from the Gartner sets, we will need to assess and update many of the EA discussions to ensure that we include a methodology for addressing the security gaps in our IT capabilities, and make security and resilience capabilities a development goal and part of the EA roadmaps that we provide.

The value proposition of Enterprise Architecture would have a gaping hole if Risk Management is not a key element in its discipline -- it is one vulnerability of the EA discipline itself that must be addressed.



2 comments:

  1. Your case for making risk management an integral part of EA’s overall responsibilities should hopefully meet with resounding acceptance, along with your advice on how EA can help in this area. My current company has fallen victim to three separate ransomware attacks in the past year. They have all been extremely disruptive, with long system outages while IT restores affected systems from backups. We have not yet paid any ransom, but I know one of our outages was so harmful (because we did not have proper backups) that we came very close to caving in. Some simple root-cause analysis shows that lower-level infrastructure staff were making decisions on critical matters like going with a cheaper firewall that doesn’t offer deep packet inspection. We believe we could have avoided these attacks if we had deep packet inspection on our firewall. I further believe we would have never pinched pennies on the firewall decision if there was influence and oversight from an internal organization looking out for the best interests of the entire enterprise, something like an EA organization. Thanks for a very educational posting.

    ReplyDelete
  2. When I was reading your very well written article around the Security topic, first thing that came to mind was the recent security issue that Target corporation had to face. So when thinking about the losses, I feel many of the customers still don't trust Target enough to shop at their stores. So when looking at the losses, it can go to any extent and organizations have to be really careful.

    ReplyDelete