1 / 18100%
Current Cyber Security Issues Related To Control Systems
Introduction
Every aspect in the present life greatly depends on some control system in the following
perspective; the refrigerator, the air conditioner, the automatic iron are all controlled by the
control system. Similarly, these systems apply in industries since they enhance the output.
Present industries and their infrastructure data networks and control systems in their operations.
Control systems also apply in the transport systems, power technology, weapon system among
other vast areas (Fernandes, 2013). The increase in the use of electronic services and operations
in diverse industries has given a platform for vast threats and malicious threat acts. The security
community has recently witnessed an increase on security threats on areas such as the
petrochemical plants, the oil and gas industry, water and energy supply threats, nuclear power
generation systems among others. The cyber security risks that occur include malfunctioning of
control systems, failures in power generation and hazardous material accidents. In order to dig
out more about cyber security threats in industrial control system, this paper will carry out an in-
depth investigative research regarding the issue. It will commence by analyzing the background
of control systems in industries in order to allow the reader to understand the concepts behind the
industry control system. The paper will then look at the evolution of the control systems
especially in organizations. The paper will further analyze how the control system works
technologically and how devices collaborate to create the end-product. The paper will then
review numerous types of control system threats and the consequences f these threats. Lastly, the
paper will review preventative measures that will help in curbing cyber threats within the
industrial control system.
Understanding industrial control systems
Industrial control devices are a system of devices that monitor and control the production
processes, safety-critical process and the critical infrastructure. In general terms, industrial
control system (ICS) encompasses numerous types of control systems that range from
supervisory control and data acquisition (SCADA), distributed control system (DCS),
programmable logic controllers (PLC) among others. Industrial control system consists of a
combination of vast control components that act together with an aim of attaining an industrial
objective. These components include mechanical, electrical, pneumatic and hydraulic
components and they coordinate to enhance manufacturing, transportation of energy or
transportation of matter.
Supervisory control and data acquisition (SCADA) systems are utilized to monitor and
control dispersed assets. It is used in vast distribution systems such as oil and natural gas
pipelines, water waste collection system water distribution, rail and public distribution systems
as well as in electrical utility transmission and distribution systems. It integrates data acquisition
and transmission through the aid of the HMI software to provide centralized monitoring and
control system in vast input and output processes (Gonda, 2014). Therefore, SCADA is designed
in a manner that it collects field information, transfer the information to the central computer
facility and display the information to the operators either in textual or graphical mode. In this
regard, it allows the operator to monitor and control an entire system.
Distributed control system (DCS) is a system that is applied to control production
systems for industries within the same geographical location. Therefore, its main role is to
control production systems in industries such as oil refineries, electric power generation plants,
chemical manufacturing plants among others. DCS are designed in a manner that they contain a
supervisory system that oversees multiple integrated sub-systems. It achieves this by using a
centralized supervisory control loop that mediates a group of localized controllers (Gonda,
2014). DCS enhance the operation of the production system by reducing the impact of a single
fault on the overall system
PLC is a system used in both DCS and SCADA system as a component that controls the
overall hierachial system. The PLC is programmed in a manner that it performs various
industrial control applications. These capabilities arise from the fact that the PLC is built with
modules such as the CPU, communication modules, I/O digital and analogue modules among
others (Gonda, 2014). The sensors of the PLC are connected to the input module as well as to
the output devices to actuators. The CPU bears the role of reading inputs from the sensors in a
continuous manner and in accordance with the outlined program. The inputs then proceed to
produce the outputs that operate the actuators.
Evolution of industrial control systems
Industrial control systems have greatly transformed from the ancient noisy machinery in
industrial plants, control rooms with a bunch of operators checking gauges and handling the
alarm signals to a more modernized operation (Fernandes, 2013). Therefore, the embedded
digital controls replaced the ancient analog mechanical controls that were applied to rotate
machines and engines. Presently, the industrial control system is a commercial off-the-shelf
(COTS) operation systems and computers. These control systems bear the capabilities of
connecting to public networks such as the internet and vast other networks and enhancing
industrial objectives with without the aid of human. Present control systems have adapted the
“smart” technology and they are either automated or include human in the loop. There are three
basic types of industrial control systems namely open loop, manual mode and closed-loop. The
manual mode system is a system that is completely controlled by human. The open-loop system
is configured in a manner that the established setting controls the output (Fernandes, 2013). On
the other hand, the closed-loop control system is configured in a manner that the output directly
affects the input in such a way that they maintain the desired objective. The positive aspect about
industrial control system is that its engineering continues to evolve with an aim of providing
enhanced capabilities while at the same time maintaining the typical long lifecycles of these
systems. Engineering models and analysis are evolving in order to address emerging aspects such
as security, safety, privacy and environmental impacts.
How the control system works
An industrial control system contains numerous human interfaces, control loops,
maintenance, and diagnostic tools. All these components are built in an array of network
protocols and they collaborate in operation. The control loop has the role of utilizing sensors
controllers and actuators with an aim of manipulating a controlled process. The sensors that are
utilized by a control loop are devices that produces a measurements of a physical property and
sends this information to the controllers as controlled variable. The controller takes up the role of
interpreting the signal and in generating corresponding manipulated variables (Gonda, 2014).
Such signal interpretations are based on a control algorithm, which re-transmit the signals and
acquired data to the actuators. Actuators are devices such as switches, breakers, valves and
others and their role is to directly manipulate the controlled process through the commands
granted by the controller.
Cyber crime issues
Industrial control systems were initially designed for closed proprietary and gentle
environments but in some instances, they have become open and connected to the public. In this
case, the processes that they control have become susceptible to malware network disruption and
malware. In most instances, the infrastructure that the industrial control system control become
disrupted or end up being physically damaged. Cyber security attacks have increased over the
years due to technological advancement in industries. A 2011 report by the Computer
Emergency Readiness Team (CERT) Shows that the water sector reported 41% attempts of cyber
security threats, the chemical industry reported 4%, the nuclear industry had 5% while the
government facilities reported 6%. Currently cyber security has become a central concern among
industrial control systems and automation (Gonda, 2014). Reports by the BBC online news dated
December 2011 portray the heightening threats of cyber crimes n control systems. The FBI cyber
division released a report that portrayed that three US cities had been attacked by hackers who
managed to sneak into SCADA systems in one of the major city and proceeded to controlled the
entire system of the city. The FBI did not disclose these cities but they claimed that control
systems have become a target due to lack of security perception that the hackers possess.
On October 20 2017, the Department of Homeland Security (DHS) alongside the Federal
Bureau of Investigation (FBI) warned about an ongoing cyber attack campaign that targeted the
energy, nuclear and other critical infrastructure (BBC, 2012). The warning was carried out
through mail and it claimed that other cyber attack campaign had started earlier in May 2017 and
the espionage had the ability to disrupt energy systems. The federal agencies warned that the
threat was “advanced persistent threat” and the attackers were still drawing out attack
mechanism. The FBI further claimed that security threats aimed at power companies have been
on the rise. The security agencies claim that they are not taking chances since such attacks
happened in Ukraine two years ago. In the Ukraine case, the attackers disrupted the operations of
the electric grid operations within five minutes. The outcome was a total power disruption in a
huge demographic that lasted for six days. IT analysts claim that the attackers used a
BlackEnergy 3 malware; a virus that is extremely complex to monitor. Therefore, the FBI is
considering such cases in heightening cyber security in control systems (Abouzakhar, 2014). The
security measures bore fruits considering that on September 22 2017, the cyber security firm
named FireEye detected and blocked phishing emails that were sent to electric companies by
threat actors that were affiliated with North Korean government. The cyber security measures
that are underway disrupted the attacks from taking place. Analysts estimate that such an attack
bore the capability of shutting down entire operations in the targeted cities because power is
applied in every home, institutions and industries.
The current most worrying cyber threat is the Stuxnet worm, which was detected in
Belarus in 2009. The worm has been circulating and it has found its roots into other countries.
The virus targets systems that are not attached to the internet due to reasons concerning security.
The worm infect window machines through USB keys. Once the firm’s internal network has
been infected through the machine, the attackers seeks the specific configuration of industrial
control software. Once the specific configuration is hijacked, the code goes ahead to reprogram
the programmable logic control (PLC) software by giving new instructions to the instructions
machinery (Abouzakhar, 2014). In this regard, the PLC is then mandated to carry out the
commands of the attackers. The US cyber security agencies claimed that detecting and
preventing such a virus is challenging. Challenges emerge in the sense that the virus is that it is
tricky to detect since it has tricks that include hiding itself on PLC and USB sticks. The other
challenge about Stuxnet is that it is a well funded and a planned project that is directed to
sabotage attacks. Being a planned project, the worm incorporates human aid who bear heavy
insider knowledge. Therefore, as technology advances with time, cyber threats on control
systems become complex.
Types of industrial security threats
Security analysts argue that numerous factors contribute to cyber security threats in
industries as well as in other fields. These factors are cyber criminals, frustrated employees,
terrorism, Software patching and frequent updates. Other vulnerabilities emerge from network
loopholes such as unsecured remote access inadequate firewall, lack of network segmentation.
These attacks aim at disrupting industrial activities for vast reasons such as political gain,
monetary, competition and personal grievance.
Cyber criminals
Cyber criminals are the major cyber security threats even in the control systems. Such
attacks are not intentional or adamant to the control systems, but once they occur they infect the
control systems with malware and the control system end operating inappropriately
(Abouzakhar, 2014). Cyber criminal attacks are common and most of the cases are never
reported. The few reported cases include the 2003 attack on Davis-Besse plant I that is located in
Oak harbor in Ohio. The plant’s computers were adversely infected with a virus referred to as
slammer worm, which shut down the safety display system. Initially, the slammer worm was not
intentionally designed to attack the control system but the application of commodity (Pretz,
2015). The software provided by the control systems gave room for this general-purpose worm
to infect safety-critical system computers. In 2006, an attack at a water filtering plant in
Pennsylvania. The attacker compromised the plant’s computer and used it as its own distribution
system. Though many cyber attack criminals carry out attacks with directives or with outlined
intensions, other cyber criminals do not intend to disrupt the operations of the control systems.
Instead, most of them are driven by curiosity of seeing how poorly the systems are protected. A
2012 report by FBI claims that a hacker named pr0f broke into a control system that supplied
water to the town of Texas (BBC, 2012). Though the hacker managed to disrupt water supply,
his main aim was to test he security features of the water system. Present day hackers are
utilizing the availability of downloaded passwords that hackers manipulate to gain access to the
control systems.
Insider/ unsatisfied employees
Another cause of cyber security threats is unsatisfied employees. Such employees have
the capability of easily accessing and disrupting control systems. Such a computer security
incident occurred in 2000 on Maroochy Shire Council sewage control system in Queensland
Australia. Immediately after the installation of the control system, the plant experienced many
problems that persisted for four months. The attacker managed to disrupt the normal operations
of the sewage systems (Pretz, 2015). The outcome was that pumps did not run when needed, the
alarms were silent; the communication between the control center and the pumping stations was
lost. The outcome was flooding of grounds with million liters of sewage. During the initial
stages, the operators presumed that the pipes had leaked but they later observed that the valves
were opening without commands. They found out the attack after they logged in and discovered
that spoofed controllers activated the valves. The attacker was later identified as a frustrated ex-
employ of the contractor company that had initially set up the control system. The ex-employee
in question carried out the act in order to sway the water treatment company to hire him so that
he could solve the problem. This portrays that employees who bear authorized access to
computers and control system networks can still carry out attacks despite that the control
networks were secluded from public networks. The positive facts about such attacks is that the
harm may not be so harmful compared to damages inflicted by a larger organized group.
Presently, there have not been reported cases of insider or employee cyber-security
threats. Nevertheless, security agencies claim that insider threats are the main security threats in
2017. Outsiders are taking advantage of unsatisfied employees to acquire login details to vast
corporations. The most recent case is that hackers have been requesting Apple employees in
Ireland to grant them the corporate login details in exchange for 20,000 Euros. Anonymous
hackers have reportedly made the offer to random employees. None of the employees have
proceeded to grant the hackers their wishes; hence, portraying that Apples employees are
satisfied and they would not compromise the security of their company for any amount of
money.
Terrorism
Terrorism also poses threats to industrial control system attacks. Though the cases are not
common, they still happen. For instance, in 2008, a senior CIA analyst claimed that there were
evidences of computer intrusion in European utilities, which was followed by extortion demands
(Pretz, 2015). Many perceive Cyber terrorism as visible threats since people believe that
terrorism involve physical invasion that lead to injuries, deaths and destruction of property.
However, this is not the case because the recent attack on the largest NHS trust in England in
mid 2017 portrays the facts pertaining cyber terrorism on control systems. The attack targeted
the Bart’s Health trust, which runs four hospitals in East London. The attackers hacked into the
trust’s system and sent emails to vast employees. These mails trick the mail recipients to open
the attachments, which contain viruses that end up releasing malware into their system. The
attackers managed to affect thousands of confidential patients’ files. Though the trust did not ask
for any ransom, the incident pushed the trust to cancel hundreds of patients’ appointments since
the virus was shut down to remove the virus.
Software patching / update
Software patching and frequent updates also disrupt the functionality of the control
system. Most industries require months to plan how to take the system offline. Failure to do so
leads to disruption of activities in a plant or industry. A nuclear power plant had to shutdown in
2008 because a chemical and diagnostic data-monitoring computer ended up rebooting after its
software automatically updated itself (Luiijf & Paske, 2015). The computer rebooting incident
reset data; hence, pushing the safety system to re-interrupt the operations of the system. The
safety systems ended up interpreting lack of data as a drop in water reservoirs that usually cool
the plant’s radioactive nuclear fuel rods. Therefore, since control systems are autonomous
decision-making agents, organizations must always ensure that they keenly monitor the
operational environment in order to prevent automated software updates.
Consequences
Cyber attacks on industrial control systems foster physical, economic and social impacts.
Economically, cyber attacks in control system lead to losses through production, which end up
being damaged. It also leads to brand erosion because consumer will lack confidence on quality
compromises. These attacks can also lead to large penalties that result from regulatory
compliance.
Cyber attacks on industrial control systems foster physical impacts in terms of injuries,
deaths, loss of property, loss of data and other potential damages to the environment. For
instance, the recent terrorist attack on NHS trust in England lead to physical impacts because it
did not only disrupt the operation of the trust but also lead to loss of patients files that were
stored as data.
Economic impacts of cyber attacks on control system are common. Every plant that shuts
down or that disrupts the normal operations of an industry leads to economic losses because
manufacturing or distribution services come to a standstill (Candell et al, 2015). More so,
attackers that attack power or water supply sector lead to losses of millions of dollars to the
energy organizations because power or water distribution stagnate and no sales are recorded
during such periods (Luiijf & Paske, 2015). For instance, the 2012 hacker who the FBI identified
as pr0f deprived the water supplying industry in Texas millions of dollars the period the hacker
disrupted the water supply for two days. More so, the attack in NHS trust in England lead to
huge financial losses since the four hospitals that are directed by the NHS trust had to close
down operations for days so as to remove the virus from their system. Cancellation of patient
appointments could lead to future economic losses because the incident tarnished the
organizations brand.
Social impacts are also common in cyber security threats on control systems. Ideally, the
society or community depends on the functionality of water supply, power supply, transportation
and other vast routines for day-to-day normalcy (Luiijf & Paske, 2015). However, when such
supplies are cut short for days by attackers, the community not only faces operation challenges
but also become disturbed. For instance, the ongoing Stuxnet virus scare has kept everyone alert
because the society cannot figure out how the attacker’s aim of spreading such a virus
(Abouzakhar, 2014). Additionally, the ongoing curious attackers who are on the rise trying to
check out the safety measures that most operation plants have installed is causing a public scare.
The society knows that not all hackers are curious since others intend to inflict further damages
once they access the control systems of vast plants such as the water supply plant. These hackers
could proceed to poisoning the water supply; hence, causing massive deaths. In this regard, the
society, the plants and the security agencies are all affected by cyber security threats in diverse
ways. Therefore, implementing effective security measures is extremely vital and beneficial.
Benefits of industrial control systems safety
The industrial control systems have greatly benefited vast organizations in vast ways. For
instance, organizations presently operate with the help of fewer operators because most roles are
carried out by automated systems. Fewer operators mean that the organizations spend less on
employee wages and benefits and the machinery that replaced human work force records more
output. Therefore, ensuring the control systems of the organizations are safe lead an organization
or industry to benefit from much profits. Additionally, the industrial control systems have
enabled organizations to have increased flexibility and process adaptability and it enhances
coordination due to its integration with corporate IT (Abouzakhar, 2014). The beneficiaries of
the industrial control systems are the manufacturing industries because the systems allow them to
enhance numerous processes. For instance, the control systems aid the operations of the process-
based manufacturing industries by providing a continuous manufacturing process. Therefore
safeguarding the control systems in industries guarantee continuous operations. The
manufacturing industries also benefit from batch manufacturing process by enhancing distinct
process steps that is usually conducted on a quantity of material. Food manufacturing industries
carry out batch manufacturing processes. Thus, utilization of control systems enhances speed,
accuracy and efficiency in the entire process. The discrete-based manufacturing industries such
as mechanical and electronic parts assembly also greatly benefit from the control systems since
these systems conduct a series of steps on a single device in creating the end-product. The
industrial control systems also increase operations in the distribution sector by geographically
dispersing assets that are scattered over thousands of kilometers. Therefore, safeguarding the
control systems in the manufacturing industries and plants is adversely beneficial since it ensures
that no disruption occurs.
Preventing cyber security in the control systems
Industrial cyber security is not an IT problem but a boardroom issue that involves the
executive personnel since they contribute in manages the risks of the business objectives. Thus,
addressing cyber security requires the full support of the executive (Gregory-Brown, 2017).
Therefore, an organization must collaborate in diverse perspectives. For instance, the concerned
personnel must ensure that they keep the operations environment safe and secure against
evolving trends of cyber threats. Additionally, industries should develop programs that secure
their infrastructure from possible intrusion and security threats.
More so, the information security teams should be greatly involved in curbing control
system cyber threats. They should define, carryout inventory and application of computer
systems within the industrial control systems. They should also monitor the networks within the
interface of the industrial control system. They should not specifically focus on devices but on
the systems that include SCADA, DCS, PLC and other instrument based systems that utilize
HML monitoring devices (Gregory-Brown, 2017). More so, the information security team should
be keen on assets that use a routable protocol. They should also review and update the ICS asset
list annually as well as after every asset is added or removed. On a different note, the information
security team must be careful when using information technology inventory tools that bear the
capabilities of identifying and documenting all software and hardware resident on a network.
Therefore, teams must assess how these tools work and the impact they might inflict on the
connected control equipment. This include reviewing control program systems that use
passwords in order to ensure these passwords cannot be easily traced and used to authenticate
vast processes that lead to hacking (Abouzakhar, 2014).. The security team must also ensure that
they plan for software patching and update in order to ensure that they do not disrupt the
operations of the organizations when the needs for such processes arise.
Another preventative measure that industries must consider is engaging the control
systems operators by providing them with adequate information awareness. Operators should be
trained to detect impending attacks and how to respond and recover from them. This involves
training the employees so that they too can assist in detecting and reporting any possible
evidences of impending attacks (Candell et al, 2015). Therefore, organizations should utilize
resources by investing in employee training and exposure to security threats as well as investing
heavily on up-to-date technological devices that help in monitoring organization’s security
measures. In this context, managing cyber security risks is challenging; hence, it should be
shared by all departments. Keeping the industry system operation-environment safe is crucial
because it maintains the safety of workers, communities and industrial assets.
Industries should borrow a leaf from the electric sector in North America, which
presently formed the North American Electric Reliability Corporation (NERC) body to oversee
cyber security standards. This alliance bears the authority to enforce cyber security standards for
control systems in all electric utilities. The alliance was formed in 2010 and it has been
monitoring cyber security standards over the years. Additionally, organizations have also teamed
up to implement sensor networks in their process control systems. Such an institution is the
National Institute of Standards and technology (NIST) is concerned with cyber security
threatening industrial control systems (Candell et al, 2015). The institute is developing a
performance test bed that aims at measuring the performance of the industrial control system. It
measures security applications processes such as chemical plant control, distributed supervision
especially in wide- area networks, dynamic assembly using robots and other processes.
Lastly, industries should collaborate with security agencies within their locality since
such measures will allow both parties to adversely tackle the issue. Collaborating with security
agencies allow the security teams in vast industries to be conversant with latest impending cyber
attack trends, which in turn help industries to adjust their security concepts (Gregory-Brown,
2017). Additionally, teaming with the security agencies such as the FBI will allow these agencies
to understand impending trends that hackers are utilizing to threaten the control systems.
Therefore, considering cyber threats is on the rise and it is targeting utility supply industries;
collaboration between organizations and the security team will be a significant measure in
curbing and minimizing threats and attacks.
Conclusion
Cyber security threats in control system are not a new phenomenon. The concept is
presently common especially in manufacturing and supply industries. Cyber security threats on
industrial control system emerged decades ago especially when embedded digital controls
replaced the ancient analog mechanical controls that were utilized by industries to rotate
machines and engines as well as carryout operations. Presently, the industrial control system is a
commercial off-the-shelf (COTS) operation systems and computers and such advancement in
technology has offered a wide platform for cyber threat attackers to carry out attacks. The
security agencies are concerned with the rise of cyber threats on control systems (Abouzakhar,
2014). The most worrying concept is that criminals with different intentions that range from
ransom, revenge, curiosity and other reasons carry out these attacks. The most recent trend is
curiosity, which is driving many attackers to “test” the security measures implemented by
different plants. In this regard, there is need for industries to strategize on top-notch
technological measures that will allow them to define, analyze and track the trends of impending
attacks. This will involve the collaboration of different players within an organization, which
range from the executive, the IT security team and the employees (Pretz, 2015). Collaborating
with the local agencies is also vital since it will grant a platform for these players to analyze and
understand the changing trends of cyber threats that vast industries are currently facing.
References
Abouzakhar, S.N. (2014). Cyber Security For Industrial Control And Automation Systems.
International Summit on Industrial Engineering.
BBC News. (2012). FBI Says Hackers Hit Key Services In Three US Cities. BBC News.
Candell, R., zimmerman, T. & Stouffer, K. (2015). An Industrial Control System. Cybersecurity
Performance Testbed. National Institute of Standards and Technology
Fernandes, I. (2013). Cyber Security For Industrial Automation & Control Environments:
Protection And Prevention Strategies In The Face Of Growing Threats. Frost & Sullivan.
Gonda, O. (2014). Understanding the Threat to SCADA networks. Network security, 9(1).
Gregory-Brown, B. (2017). Securing Industrial Control Systems – 2017: A SANS Survey. SANS
Institute.
Luiijf, E,. & Paske, B. (2015). Cyber Security Of Industrial Control Systems. Global Conference
on Cyberspace.
Pretz, K. (2015). Unhappy Workers Are Increasingly Behind Security Breaches. The Institute.
Students also viewed