Hackers and Ethics

profilenilesh tamrakar
CSCI397F20-Assignment7-ntamrakar.docx

ASSIGNMENT 7 (W11):

SELECTING & IMPLEMENTING SECURITY CONTROL FOR ICS – PART 1

Name

Nilesh Tamrakar

Email

[email protected]

Course Number

CSCI 397.01W

Course Time

Tuesday: 1630 – 1900 h

Semester

Fall 2020

Submission

Assignment 7

Due Date

November 9, 2020

Instructor

Joel Langill

Email

[email protected]

Phone

+1 (920) 594-0321

Office Hours

Monday: 1630 – 1900 h

Thursday: 1630 – 1900 h

By Appointment

The assignment for this week is consists of you completing the following:

· Ensure that you have selected a topic under the “Term Paper Topic Selection” activity under the Term Paper section of the course

· Review the “Term Paper Requirements” activity “Contents and Structure” chapter under the Term Paper section of the course

· Complete the outline as directed in this Assignment Submittal on the following pages

Please be sure and complete the cover page with your name as it appears on your university identification card, your corresponding email address, and whether you are attending the Commerce or RELLIS campus course prior to submission. Do not forget to submit your work when you have completed this assignment.

(Note: problems may to occur if using Google Chrome as a browser where it tries to open links in Google Docs. The "Docs PDF/PowerPoint Viewer (by Google)" extension must be disabled or removed.)

The term research paper and associated presentation should be logically divided into sections that follow sound research paper style and address each of the areas defined by the “Term Paper Requirements”. You are free to organization the paper and presentation as appropriate, however a template has been provided for both the paper and presentation to help start the initial paper structure.

This Assignment 7 requires that you provide the high-level organization and key factual items that will form the basis of the paper. Please supply as indicated below. Information presented should be summarized and demonstrate that the foundation for completion of the paper by the required Due Date has been collected and is understood.

The topics presented in this Assignment are provided to assist in data collection, and do not necessarily need to be covered in the paper in their entirety.

Company Overview

Company Name: Advantech Co.,Ltd

Company Headquarters:Taipei, Taiwan

Major Geographical Regions Served: Asia, but has global market for providing service

System Name: Advantech WebAccess/SCADA

System First Released: 2001

Sales Website URL: https://buy.advantech.com/

Service and Support Website URL: https://www2.advantech.com/ags/

https://www.advantech.com/contact

System Overview Brochure URL: https://advcloudfiles.advantech.com/ecatalog/2016/06131641.pdf

System Overview

Please attach a System Overview graphic (copy/paste from brochure):

Names and Functions of Key System Components:

A - loT Application Software Firmware

- Easily expandable and incorporates additional interfacing methods and application methods that assists system integrators in vertical market.

- Data retrieval to visualization through a cross-platform GUI

- Backup to a web-based server

- Comprehensive intelligent system integration, and system level solution

b- Data Visualization and Mobile Application

- Data analysis and processing tools for transforming information into business insight

C -Web-based cross-platform Dashboard

- support of multiple operating system and video management integration

D - WebAccess App

- remote monitoring and control

- alarm push notification

- multi-language support

- Supports iOS 10 and android OS 5 and above

e- WISE-PaaS/SaaS Composer

· True 3D Visualization Tool with Real Time Monitoring

· Reconstructs the on-site environment with 100% customization ability and simple intuitive 3D modeling application

· Updates critical data in a visually intuitive display

· On-premise version bundled with SCADA based on SCADA data sources

Names of System Communication Networks:

NFV Infrastructure-NFVI- Intel select solution for next gen 5G networks

What vendor-supplied security components are available?

The vendor-supplied security components are:

· SecureBootTM security package offers customizable protection for software and hardware

· TPM Suite security package aims at markets where boot-time verification must be provided. Secures loT security and the game environment against copying and tampering, and also providing platform authentication and access control security

· Embedded security solution

· Endpoint security 10- Blacklisting technology

· McAfee embedded security- Whitelisting technology

Does the vendor offer any other systems as part of their portfolio? If so, please provide system names.

Yes, the vendor offers other systems as part of their portfolio and they are

· WebAccess/CNC

· WebAccess/HMA

· a lot.SRP- Solution-Ready Packages(SRP)

· Industry 4.0 – Smart Manufacturing

· Auto Part Manufacture- Advantech’s auto part test and measurement solution

· WISE-PaaS Alliance for Industrial loT- Enalbles loT & Industry 4.0 with Advantech WebAccess

Communications and Protocols

Describe the primary protocols and methods used between the key system asset types. This must address communication to/from field-connected controllers, communication to/from human-machine interfaces, and communication to/from historical data repositories as a minimum.

The primary protocols and methods used between the key system by Advantech WebAccess/SCADA are OPC UA, Mod OPC DA,Ethernet/IP, DNP3, SNMP, Modbus, BACnet, DDE server and various database such as SQL Server, Oracle, MySQL and Microsoft Access Database

The system communicates to/from field-connected controllers through Ethernet/ip(or RS-232,RS-422 orRS-485 as a backup) using packet version of the Modbus RTU protocol. TCP/IP connection are acceptable

For its human-machine interfaces(HMI) it uses RS-232/422/485(DB9 Female), RS-422/485 (5-pin plug connector), RS-232(Com1:pin5;7;8) Ethernet(RJ45)-10/100 BaseT( for N2AE model), I/O’s USB client,host, Micro-SD Slot

Are any of these protocols proprietary? If so, please describe.

I think all the protocols used by Advantech are Industrial communication protocols like Modbus so that the devices and services can communicate with the system manufactured by other vendors. Use of proprietary protocols is a traditional approach and Advantech is trying to modernize their system. Some primary communication between devices take place in Advantech’s proprietary protocols which I am still investigating, but they too are using protocol gateway to communicate with other non-vendor devices.

Industry Sectors using this System

Please provide the primary markets the system is targeted. You can either use U.S. defined Critical Infrastructure and Key Resources (CIKR), or Standard Industry Classification (SIC) for industry identification.

(hint: https://en.wikipedia.org/wiki/Standard_Industrial_Classification)

The markets the system is targeted to are in SIC classification

7370

Services-Computer Programming, Data Processing, Etc.

7371

Services-Computer Programming Services

7372

Services-Prepackaged Software

7373

Services-Computer Integrated Systems Design

7374

Services-Computer Processing & Data Preparation

7377

Services-Computer Rental & Leasing

7380

Services-Miscellaneous Business Services

5045

Wholesale-Computers & Peripheral Equipment & Software

5734

Retail-Computer & Computer Software Stores

3826

Laboratory Analytical Instruments

8200

Services-Educational Services

2000-3999

Manufacturing

1311

Crude Petroleum & Natural Gas

3670

Electronic Components & Accessories

Vulnerabilities Disclosed for this System

Please provide any vulnerabilities that have been publicly disclosed that target the system under consideration. Include source, year, and disclosure reference identifier.

(hint: useful links are provided under the Week 8 Vulnerability and Exploit References provided on the Moodle LMS)

CVE-2018-17910-CVSS score- 9.3

Publish Date : 2018-10-29

https://us-cert.cisa.gov/ics/advisories/ICSA-18-298-02

CVE-2017-16720

The exploit for CVE-2017-16720 was released in March

https://www.helpnetsecurity.com/2018/09/11/cve-2017-16720/#:~:text=A%20vulnerability%20in%20Advantech%20WebAccess,administrator%20privileges%20on%20vulnerable%20systems.

CVE-2018-15704

Publish Date : 2018-10-22

https://www.tenable.com/security/research/tra-2018-33

Were publicly available exploit packages made available that target the identified vulnerabilities?

(hint: useful links are provided under the Week 8 Vulnerability and Exploit References provided on the Moodle LMS)

Yes, exploit packages were made available that target the identified vulnerabilities, and cometimes multiple packages had to be deployed in order to remedy the vulnerability like for CVE-2017-16720 they released 8.3, then 8.3.1 and again 8.3.2. Each one of the vulnerability were swiftly fixed by providing correct exploit packages, or are in progress of doing so.

Impact and Consequences to Industry Sectors Served (Risk Identification)

For the top 2-3 vulnerabilities discussed above, please provide a brief scenario (1-2 sentences) of how the successful exploitation of the vulnerability would impact the operating of the system and how it delivered its essential services to the industry it is deployed.

CVE-2018-17910-CVSS

The successful exploitation of the vulnerability would impact the operating of the system by the application failing to properly validate the length of user-supplied data, causing a buffer overflow condition that allows for arbitrary remote code execution.

CVE-2017-16720

This vulnerability allows for remote command execution via the Remote Procedure Call (RPC) protocol over TCP port 4592. By utilizing malicious Distributed Computing Environment / Remote Procedure Calls (DCERPC), the webvrpcs.exe service will pass command line instructions to the host

CVE-2018-15704

vulnerable to a stack buffer overflow vulnerability. A remote authenticated attacker could potentially exploit this vulnerability by sending a crafted HTTP request to broadweb/system/opcImg.asp and take control from there.

Mitigation (Risk Reduction)

Though NOT required for this Assignment, please be prepared in the term paper to discuss the vendor’s recommendations to mitigating the risk introduced from these vulnerabilities, and AT LEAST one compensating control that could be used to reduce risk in the absence of applying the vendor’s recommended corrective action. Attention should focus on minimizing the severity of the Consequence/Impact and not that of the vulnerability alone in isolation.

Do not forget to submit your work when you have completed this assignment.

CSCI 397.01W | CSCI 397.61W © 2012-2020 ICSCSI LLC

Fundamentals of Industrial Control System Cyber Security Page A7-1 of 9

Fall 2020 CSCI 397 F20 - Assignment 7.docx