Hackers and Ethics
ASSIGNMENT 7 (W11):
SELECTING & IMPLEMENTING SECURITY CONTROL FOR ICS – PART 1
|
Name |
Nilesh Tamrakar |
|
| |
|
Course Number |
CSCI 397.01W |
|
Course Time |
Tuesday: 1630 – 1900 h |
|
Semester |
Fall 2020 |
|
Submission |
Assignment 7 |
|
Due Date |
November 9, 2020 |
|
Instructor |
Joel Langill |
|
| |
|
Phone |
+1 (920) 594-0321 |
|
Office Hours |
Monday: 1630 – 1900 h Thursday: 1630 – 1900 h By Appointment |
The assignment for this week is consists of you completing the following:
· Ensure that you have selected a topic under the “Term Paper Topic Selection” activity under the Term Paper section of the course
· Review the “Term Paper Requirements” activity “Contents and Structure” chapter under the Term Paper section of the course
· Complete the outline as directed in this Assignment Submittal on the following pages
Please be sure and complete the cover page with your name as it appears on your university identification card, your corresponding email address, and whether you are attending the Commerce or RELLIS campus course prior to submission. Do not forget to submit your work when you have completed this assignment.
(Note: problems may to occur if using Google Chrome as a browser where it tries to open links in Google Docs. The "Docs PDF/PowerPoint Viewer (by Google)" extension must be disabled or removed.)
The term research paper and associated presentation should be logically divided into sections that follow sound research paper style and address each of the areas defined by the “Term Paper Requirements”. You are free to organization the paper and presentation as appropriate, however a template has been provided for both the paper and presentation to help start the initial paper structure.
This Assignment 7 requires that you provide the high-level organization and key factual items that will form the basis of the paper. Please supply as indicated below. Information presented should be summarized and demonstrate that the foundation for completion of the paper by the required Due Date has been collected and is understood.
The topics presented in this Assignment are provided to assist in data collection, and do not necessarily need to be covered in the paper in their entirety.
Company Overview
Company Name: Advantech Co.,Ltd
Company Headquarters:Taipei, Taiwan
Major Geographical Regions Served: Asia, but has global market for providing service
System Name: Advantech WebAccess/SCADA
System First Released: 2001
Sales Website URL: https://buy.advantech.com/
Service and Support Website URL: https://www2.advantech.com/ags/
https://www.advantech.com/contact
System Overview Brochure URL: https://advcloudfiles.advantech.com/ecatalog/2016/06131641.pdf
System Overview
Please attach a System Overview graphic (copy/paste from brochure):
Names and Functions of Key System Components:
A - loT Application Software Firmware
- Easily expandable and incorporates additional interfacing methods and application methods that assists system integrators in vertical market.
- Data retrieval to visualization through a cross-platform GUI
- Backup to a web-based server
- Comprehensive intelligent system integration, and system level solution
b- Data Visualization and Mobile Application
- Data analysis and processing tools for transforming information into business insight
C -Web-based cross-platform Dashboard
- support of multiple operating system and video management integration
D - WebAccess App
- remote monitoring and control
- alarm push notification
- multi-language support
- Supports iOS 10 and android OS 5 and above
e- WISE-PaaS/SaaS Composer
· True 3D Visualization Tool with Real Time Monitoring
· Reconstructs the on-site environment with 100% customization ability and simple intuitive 3D modeling application
· Updates critical data in a visually intuitive display
· On-premise version bundled with SCADA based on SCADA data sources
Names of System Communication Networks:
NFV Infrastructure-NFVI- Intel select solution for next gen 5G networks
What vendor-supplied security components are available?
The vendor-supplied security components are:
· SecureBootTM security package offers customizable protection for software and hardware
· TPM Suite security package aims at markets where boot-time verification must be provided. Secures loT security and the game environment against copying and tampering, and also providing platform authentication and access control security
· Embedded security solution
· Endpoint security 10- Blacklisting technology
· McAfee embedded security- Whitelisting technology
Does the vendor offer any other systems as part of their portfolio? If so, please provide system names.
Yes, the vendor offers other systems as part of their portfolio and they are
· WebAccess/CNC
· WebAccess/HMA
· a lot.SRP- Solution-Ready Packages(SRP)
· Industry 4.0 – Smart Manufacturing
· Auto Part Manufacture- Advantech’s auto part test and measurement solution
· WISE-PaaS Alliance for Industrial loT- Enalbles loT & Industry 4.0 with Advantech WebAccess
Communications and Protocols
Describe the primary protocols and methods used between the key system asset types. This must address communication to/from field-connected controllers, communication to/from human-machine interfaces, and communication to/from historical data repositories as a minimum.
The primary protocols and methods used between the key system by Advantech WebAccess/SCADA are OPC UA, Mod OPC DA,Ethernet/IP, DNP3, SNMP, Modbus, BACnet, DDE server and various database such as SQL Server, Oracle, MySQL and Microsoft Access Database
The system communicates to/from field-connected controllers through Ethernet/ip(or RS-232,RS-422 orRS-485 as a backup) using packet version of the Modbus RTU protocol. TCP/IP connection are acceptable
For its human-machine interfaces(HMI) it uses RS-232/422/485(DB9 Female), RS-422/485 (5-pin plug connector), RS-232(Com1:pin5;7;8) Ethernet(RJ45)-10/100 BaseT( for N2AE model), I/O’s USB client,host, Micro-SD Slot
Are any of these protocols proprietary? If so, please describe.
I think all the protocols used by Advantech are Industrial communication protocols like Modbus so that the devices and services can communicate with the system manufactured by other vendors. Use of proprietary protocols is a traditional approach and Advantech is trying to modernize their system. Some primary communication between devices take place in Advantech’s proprietary protocols which I am still investigating, but they too are using protocol gateway to communicate with other non-vendor devices.
Industry Sectors using this System
Please provide the primary markets the system is targeted. You can either use U.S. defined Critical Infrastructure and Key Resources (CIKR), or Standard Industry Classification (SIC) for industry identification.
(hint: https://en.wikipedia.org/wiki/Standard_Industrial_Classification)
The markets the system is targeted to are in SIC classification
|
7370 |
Services-Computer Programming, Data Processing, Etc. |
|
7371 |
Services-Computer Programming Services |
|
7372 |
Services-Prepackaged Software |
|
7373 |
Services-Computer Integrated Systems Design |
|
7374 |
Services-Computer Processing & Data Preparation |
|
7377 |
Services-Computer Rental & Leasing |
|
7380 |
Services-Miscellaneous Business Services |
|
5045 |
Wholesale-Computers & Peripheral Equipment & Software |
|
5734 |
Retail-Computer & Computer Software Stores |
|
3826 |
Laboratory Analytical Instruments |
|
8200 |
Services-Educational Services |
|
2000-3999 |
Manufacturing |
|
1311 |
Crude Petroleum & Natural Gas |
|
3670 |
Electronic Components & Accessories |
Vulnerabilities Disclosed for this System
Please provide any vulnerabilities that have been publicly disclosed that target the system under consideration. Include source, year, and disclosure reference identifier.
(hint: useful links are provided under the Week 8 Vulnerability and Exploit References provided on the Moodle LMS)
CVE-2018-17910-CVSS score- 9.3
Publish Date : 2018-10-29
https://us-cert.cisa.gov/ics/advisories/ICSA-18-298-02
CVE-2017-16720
The exploit for CVE-2017-16720 was released in March
CVE-2018-15704
Publish Date : 2018-10-22
https://www.tenable.com/security/research/tra-2018-33
Were publicly available exploit packages made available that target the identified vulnerabilities?
(hint: useful links are provided under the Week 8 Vulnerability and Exploit References provided on the Moodle LMS)
Yes, exploit packages were made available that target the identified vulnerabilities, and cometimes multiple packages had to be deployed in order to remedy the vulnerability like for CVE-2017-16720 they released 8.3, then 8.3.1 and again 8.3.2. Each one of the vulnerability were swiftly fixed by providing correct exploit packages, or are in progress of doing so.
Impact and Consequences to Industry Sectors Served (Risk Identification)
For the top 2-3 vulnerabilities discussed above, please provide a brief scenario (1-2 sentences) of how the successful exploitation of the vulnerability would impact the operating of the system and how it delivered its essential services to the industry it is deployed.
CVE-2018-17910-CVSS
The successful exploitation of the vulnerability would impact the operating of the system by the application failing to properly validate the length of user-supplied data, causing a buffer overflow condition that allows for arbitrary remote code execution.
CVE-2017-16720
This vulnerability allows for remote command execution via the Remote Procedure Call (RPC) protocol over TCP port 4592. By utilizing malicious Distributed Computing Environment / Remote Procedure Calls (DCERPC), the webvrpcs.exe service will pass command line instructions to the host
CVE-2018-15704
vulnerable to a stack buffer overflow vulnerability. A remote authenticated attacker could potentially exploit this vulnerability by sending a crafted HTTP request to broadweb/system/opcImg.asp and take control from there.
Mitigation (Risk Reduction)
Though NOT required for this Assignment, please be prepared in the term paper to discuss the vendor’s recommendations to mitigating the risk introduced from these vulnerabilities, and AT LEAST one compensating control that could be used to reduce risk in the absence of applying the vendor’s recommended corrective action. Attention should focus on minimizing the severity of the Consequence/Impact and not that of the vulnerability alone in isolation.
Do not forget to submit your work when you have completed this assignment.
CSCI 397.01W | CSCI 397.61W © 2012-2020 ICSCSI LLC
Fundamentals of Industrial Control System Cyber Security Page A7-1 of 9
Fall 2020 CSCI 397 F20 - Assignment 7.docx