Cyber Attack Vectors
On March 4, 2007, the Idaho
National Laboratory demonstrated the so-called Aurora vulnerability, to show
how an attack which gains access to a controller, can cause physical damage to
components to critical infrastructure like the power grid. Although the Aurora
exploit is essentially an electrical (physical) event, the current use of
networked software controlled technologies allows the exploit to be caused by a cyber attack. This Aurora type of attack should not be
confused with the 2009 cyberattack on top silicon valley companies similarly
called "Operation Aurora". Indeed in 2014, there was that confusion which inadvertently led to DHS records folks to release classified information on the
2007 Aurora Idaho experiments. But that is a completely different story.
Fast forward to December 23,
2015, when a significant portion of western Ukraine lost power for
nearly 6 hours. ICS-CERT (US DHS) reports that power outages were caused by
remote synchronized cyber intrusions at three regional electric power
distribution companies (all from Oblenergo). Experts attribute the cyberattack
to the Russian 'Sandworm' hacker group, enabled through email spear phishing
and malware (BlackEnergy) as an initial access vector to acquire legitimate
credentials. Extensive mapping of the system may have been done prior to actual
attack, enabling shut down of the systems. Indications showed execution of the
KillDisk malware towards the end, which erases selected files on target systems
and corrupts the master boot record, rendering systems inoperable. The attack
disabled company phone systems, blocking customer outage reports; disconnected
backup power supplies, delaying recovery and restore procedures.
Impact: Close to 50% of its 538,000 customers: Prykarpattya Oblenergo, reported 27 of its
substations went dead, 103 cities were "completely blacked out," and
another 186 cities were left partially in the dark.
Cascade Effects: Observers have placed a plausible
assumption that this is a Russian retaliation for the anti-Russian attacks on
the power grid supplies to the recently annexed Crimea (by Russia in 2014). Interestingly,
the Ukrainians may have been saved by the fact that their country relies
on old technology and is still not as fully wired as many western nations. Oblenergo eventually switched to manual
controls and dispatched teams around the region to manually flip switches back
"on," ending the outage within a few hours. In retrospect, the
attack may have been merely a signal warning. But the crash adequately illustrated the potential
damages to grid-dependent physical infrastructures, loss of economic production,
environmental damages, theft and chaos, as well as significant deaths and casualties.
Ultimately, the exploit shows that the power grid itself is a critical attack
vector -- a conduit to disable other critical infrastructures, expose the state
to more attacks, lead to a possible kinetic cyberwar, and dangerously
heightened escalations of political conflicts in the region. This was the first
time that a known Aurora type exploit was actually executed -- and executed by
a nation-state.
More details at: https://ics-cert.us-cert.gov/alerts/IR-ALERT-H-16-056-01
Critical Infrastructure Sectors
The Department of Homeland
Security has designated 16 critical infrastructure sectors and defines these as
enterprises whose assets, systems, and networks, whether physical or virtual,
are considered so vital to the United States that their incapacitation or
destruction would have a debilitating effect on national security, economic stability, national public health or safety. These includes key industry players in the
following sectors: 1.) Chemical 2.) Commercial Facilities 3.) Communications 4.)
Critical Manufacturing 5.) Dams 6.) Defense Industrial Base 7.) Emergency Services 8.) Energy
9.) Financial Services 10.) Food
and Agriculture 11.) Government
Facilities 12.) Healthcare and Public
Health 13.) Nuclear Reactors, Materials,
and Waste 14.) Transportation
Systems 15.) Water and wastwater 16.) Information Technology.
The Information Technology Sector
includes those functions which produce and provide hardware, software, systems
and services which in tandem and collaboration with the Communications
Sector, develops and operates the vital
backbones of the Internet. As the world
and industries continue to form their dependencies on computer technologies and
the internet, the IT infrastructure has become a significant part of critical
infrastructure security.
More
details at: https://www.dhs.gov/critical-infrastructure-sectors
Enterprise Architecture Framework for Critical
Infrastructure Enterprises
Given these discussions, it is clear that a Cyber Security
Architecture for Critical Infrastructure should be a significant component of the
enterprise architecture framework, if the discipline wants to maintain its relevance
as a strategic tool. Risk management and
cyber security must be essential EA components
in order to emphasize and prioritize the development and management of a
risk-based integration of compliance controls and technologies, aligned and balanced
with business-driven requirements. As newer technologies are introduced to
build business capabilities, the security assessment of these technologies need
to be in place across the enterprise, to check for security gaps in their adoption policies, vetting procedures, and deployment practice. A Security Framework would enable a prioritized, flexible, repeatable, performance-based, cost-effective approach, ensuring effective deployment of information security measures and controls, in order to help owners and operators of critical infrastructure identify, assess, and manage cyber risk.
The NIST Resources
The NIST is the forefront
security standards body in the U.S. and globally collaborates closely with
ISO. The NIST-800 series provides ample
references and frameworks that both public and private organizations can use to
implement security architecture for the enterprise.
The mission of NIST's Computer Security Division is to improve
information systems security via programs with the following goals:
The NIST site has a rich set of literature resources to assist
on the following topics:
More details at: http://www.nist.gov/itl/csd/
Resilience As a Capability
DHS defines "resilience" as the ability to adapt to
changing conditions in order to withstand and rapidly recover from disruption due to
emergencies from all hazards including cyber attacks. The development of resilience
should include systems hardening, adaptive capabilities, readiness of
facilities, and availability of contingency funds and supplies for business
continuity and recovery operations. Resilience is operationalized by using
systems-thinking within a framework based on the following principles: 1.)
Adaptiveness to changing conditions using enhanced collaboration and
coordination protocols. 2.) Better adoption of resilient systems with dynamic
real-time situational awareness capabilities. 3.) Modernize systems to address
industrial control system (ICS) component vulnerabilities. 4.)
Rapid response assurance via preparedness programs that place significance on wide
participation and public-private partnerships, particularly with other owners
and operators of critical infrastructure and key resources. 5.) Improve incident response and reporting
capabilities via enhanced sharing protocols for information on cyber threats,
exploits, vectors, mitigations, and lessons learned. 6.) Support
and participate in large-scale real-world simulations to assess emergency
communications. 7.) Support the adoption of national common industry standards,
practices, policies, with compliance to legislative/regulatory
provisions. 8.) Strengthen the cyber ecosystem via global networks,
international collaborative communities and public-private partnerships to
include research institutions and academia.
More details at: https://www.dhs.gov/sites/default/files/publications/qhsr/2014-QHSR.pdf
Conclusion
The attack vectors for cyber exploits can be blocked with better
technologies and practices. While more so for critical infrastructure
enterprises, regular business organizations should also establish solid
security architectures because any enterprise connected to the internet, by
default, becomes a potential conduit for attack vectors ultimately trailed
towards critical infrastructure. This was sharply illustrated by how Stuxnet
was spread.
The ICS Context Industrial Control Systems
A multilayer defense-in-depth
architecture, protecting SCADA and PLC's (Programmable Logic Controllers) Source: Security hardware for
industrial networking, http://www.iebmedia.com/
The Siemens Simatic S7-300 PLC,
Target of the Stuxnet Attack of 2010.
Source: PBS video,
Cyberwar Threat,
http://www.pbs.org/wgbh/nova/military/cyberwar-threat.html
What EA can do to help. An effective and highly valuable EA initiative would be to help launch training, awareness, and education of
organizations which include, for starters, sound patch management and practical
security operations e.g. scanner updates, trojans in attachments, etc.
Moreover, while we revisit the set of presentation materials and toolkits that
we have been inspecting from the Gartner sets, we will need to assess and update
many of the EA discussions to ensure that we include a methodology for
addressing the security gaps in our IT capabilities, and make security and
resilience capabilities a development goal and part of the EA roadmaps that we
provide.
The value proposition of Enterprise Architecture would have a gaping hole if Risk Management is not a key element in its discipline -- it is one vulnerability of the EA discipline itself that must be addressed.
The value proposition of Enterprise Architecture would have a gaping hole if Risk Management is not a key element in its discipline -- it is one vulnerability of the EA discipline itself that must be addressed.
Your case for making risk management an integral part of EA’s overall responsibilities should hopefully meet with resounding acceptance, along with your advice on how EA can help in this area. My current company has fallen victim to three separate ransomware attacks in the past year. They have all been extremely disruptive, with long system outages while IT restores affected systems from backups. We have not yet paid any ransom, but I know one of our outages was so harmful (because we did not have proper backups) that we came very close to caving in. Some simple root-cause analysis shows that lower-level infrastructure staff were making decisions on critical matters like going with a cheaper firewall that doesn’t offer deep packet inspection. We believe we could have avoided these attacks if we had deep packet inspection on our firewall. I further believe we would have never pinched pennies on the firewall decision if there was influence and oversight from an internal organization looking out for the best interests of the entire enterprise, something like an EA organization. Thanks for a very educational posting.
ReplyDeleteWhen I was reading your very well written article around the Security topic, first thing that came to mind was the recent security issue that Target corporation had to face. So when thinking about the losses, I feel many of the customers still don't trust Target enough to shop at their stores. So when looking at the losses, it can go to any extent and organizations have to be really careful.
ReplyDelete