System Integration & Control Systems Design


Tofino Security White Paper ISA-99

July 2012 System Integration & Control Systems Design

Anyone integrating automation technologies these days is well aware of the pressure on the operators of industrial plants to increase productivity, reduce costs and share information in real-time across multiple industrial and enterprise systems. Adding to these business pressures is the growing fear of cyber attack as the world has become aware that the Stuxnet worm was specifically designed to disrupt an industrial process. Operators and engineers are under pressure to isolate automation systems, while at the same time management is asking for greater interconnectedness.

How can you help your company or clients deal with the conflicting requirements of more integration and more isolation? This white paper explains how the ‘zone and conduit’ model included in the ANSI/ISA-99 security standards provides a framework for helping deal with network security threats that arise from both the ‘push for productivity’ and the fear of the next ‘Son-of-Stuxnet’ worm.

Why the ‘Push for Productivity’ has degraded control network security

As corporate networks have converged with industrial control system (ICS) networks, there have been many integration projects where proprietary networks were replaced with commercial-off-the-shelf equipment using Ethernet-TCP/IP technology.

This shift in technology has greatly increased the complexity and ‘interconnectedness’ of control systems. As a result, they now have many of the same vulnerabilities that have plagued enterprise networks. In addition, the controllers in these networks are now subjected to new threat sources that they were never designed to handle.

The result has been a significant increase in the number of plant disruptions and shut-downs due to cyber security issues in the control networks.

The Repository for Industrial Security Incidents (RISI) is the world’s largest database of security incidents in control and scada systems. An analysis of the data from 1982 to 2010 found that the type of incidents affecting control systems breaks down as follows:

* 50% of incidents were accidental in nature.

* 30% of incidents were due to malware.

* 11% of incidents were due to external attackers.

* 9% of incidents were due to internal attackers.

In our study of the incidents included in the RISI database, we see problems arising from three common sources:

Proliferation of ‘soft’ targets

Supervisory control and data acquisition (scada) and ICS devices such as PLCs, DCS controllers, IEDs, and RTUs were designed with a focus on reliability and real-time I/O, not robust and secure networking. Many ICS devices will crash if they receive malformed network traffic or even high loads of correctly-formed data. Also, Windows PCs in these networks that run for months at a time without security patches or antivirus updates, are ever susceptible to new, or even outdated, malware.

Multiple points of entry

Even without a direct connection to the Internet, modern control systems are accessed by numerous external sources. All of them are potential sources of infection or attack and include:

* Remote maintenance and diagnostics connections.

* Historian and manufacturing execution systems (MES) servers shared with business users.

* Remote access modems.

* Serial connections.

* Wireless systems.

* Mobile laptops.

* USB devices.

* Data files (such as PDF documents or PLC project files).

These pathways are underestimated and poorly documented by the owners and operators of industrial systems. As the Stuxnet worm showed us in 2010, these pathways can be readily exploited by malware and other disruptive elements. Stuxnet used at least eight different propagation mechanisms, including USB drives, PLC project files and print servers to work its way into the victim’s control system.

Poor internal network segmentation

Control networks are now more complex than ever before, consisting of hundreds or even thousands of individual devices. Unfortunately the design of many of these networks has remained ‘flat’ with virtually no segmentation. As a result, problems that originate in one part of the network can quickly spread to other areas.

To learn the methods of ANSI/ISA-99 Zone and Conduit Security Model framework for network security improvements through integrated design, implementation, monitoring and continuous improvement, visit http://instrumentation.co.za/+C16783



Credit(s)



Share this article:
Share via emailShare via LinkedInPrint this page

Further reading:

Windows tablets for hazardous areas
Extech Safety Systems IS & Ex
i.safe Mobile has expanded its intrinsically safe product range with the launch of the IS945.x series rugged Windows tablets, designed for use in hazardous and demanding industrial environments.

Read more...
Major digital transformation project for Isuzu Motors
System Integration & Control Systems Design
Isuzu Motors South Africa, in partnership with NoMuda and S4 Integration, has kicked off a major two-year digital transformation project to modernise its production environment.

Read more...
Modernising Vertical Filter Press Machines with Future-Focused Control Systems
System Integration & Control Systems Design
Project and Industry Pressure Filter Specialists approached us to modernise vertical filter press machines for the Minerals and Metals industry. The goal was to improve reliability, reduce downtime, ...

Read more...
Windows tablets for Zone 1/21, Zone 2/22 and mining
Extech Safety Systems IS & Ex
Extech is expanding its portfolio with the Windows-based tablets IS945.1, IS945.2, and IS945.M1. For the first time, EX certification is combined with full Windows compatibility, without compromising on software or security.

Read more...
Project & industry
System Integration & Control Systems Design
Project and Industry This project involved delivering a complete electrical, instrumentation, and automation solution for a new OEM drum-twister machine, replacing an ageing unit in a major cabling production ...

Read more...
It’s a risky business not to challenge standard language
System Integration & Control Systems Design
On the surface, contracts all look alike. Once you’ve seen one, you’ve seen them all, or so it seems. Maybe so, but hidden within the standard language can be language that shifts the other party’s risk to you.

Read more...
Containerised Electrical & Control System Powers Paste Plant in Botswana
System Integration & Control Systems Design
Delivering a complete, containerized solution for a mine’s paste plant in Botswana, this project stands as a model of modern EC&I execution — integrating electrical, control, and automation systems into ...

Read more...
Control system upgrade: Smelting
SAM Systems Automation & Management System Integration & Control Systems Design
Systems Automation & Management recently completed a major control system upgrade in the smelting industry. The project was delivered on budget and achieved a positive ROI for the client.

Read more...
Gottwald drives upgrade: Ports and harbours
Abacus Automation System Integration & Control Systems Design
In the ports and harbours sector, Abacus Automation completed a significant modernisation of a Gottwald crane, improving both operational reliability and serviceability.

Read more...
Mining industry upgrade: From ageing systems to maximum capacity
System Integration & Control Systems Design
Iritron recently undertook a major upgrade in the mining sector, focusing on washing and screening plants, jigs, thickeners, tailings, water systems, conveyors and reclaimers.

Read more...









While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd | All Rights Reserved