Global MBT:
Login  |  Register          Free Newsletter Subscription
 
Email
Print
Reprint
Learn RSS

Plant automation, IT dead center in cyber terrorism concerns

by Staff -- MSI, 11/1/2004

Until recently, it's been a truism—when it came to the subject of plant-floor security—that the greatest threat was internal, in the form of disgruntled employees or bona fide accidents. But according to researcher Eric Byres of British Columbia Institute of Technology, in the last several years, that's changed. Statistics he's compiled indicate today nearly 70 percent of incidents originate from external sources.

Don't think for a minute a firewall protects a company from sabotage. Intrusions today are more likely accomplished by means of dial-up modems, virtual private networks, or even someone bringing a diskette from home into the workplace.

Even then, the plant IT network and the business enterprise network often are thought to be separate. But all it takes is something as simple as a plant-floor engineer allowing an accountant real-time access to required plant-floor data, and the two no longer are. That means if the business enterprise can be accessed, the plant can be, too.

A final factor, discussed last month in an ISA Expo 2004 forum titled Automation systems, an Achilles heel to our critical infrastructure, was that while many plant systems are based on proprietary technology, commercial technologies are today more prevalent in industrial settings, making it easier for hackers to mount threats.

Larry Adams, a "controls resource" with ConocoPhillips Specialty Products, Bryan, Texas, says his company is aware of the dangers, adding that the newest technologies, "such as wireless PCs and Ethernet," exacerbate the challenge "because of holes in the technology."

All these concerns, and the times we live in, have heightened awareness within government to the very real risk of cyber attacks aimed at supervisory control and data acquisition (SCADA) systems. But as David Sanders of the Department of Homeland Security points out, for the foreseeable future, government efforts will focus on preventing the catastrophic events that can have serious economic consequences for the entire economy, not on protecting companies or individuals.

Nor can the government tell us how widespread these problems are, since victimized companies are reluctant to talk for fear they may subsequently be found liable. Legislation drafted to release honest companies in this regard was never enacted.

Nevertheless, two highly publicized incidents involving SCADA systems include the Slammer Worm infiltration of an Ohio nuclear plant, and a SCADA system implicated in a significant power outage in Canada.

Thus it's important that process industry manufacturers—like ConocoPhillips, which recently updated its control systems, in part to address security concerns—today know much more about the plant-floor security risk than they did even a few years ago, and, perhaps more important, thanks to efforts such as ISA's, they're learning what it is they don't yet know.

 

ISA Expo Forum Sources

For more information on security and process industry operations, access the sources offered here:

Critical Infrastructure Protection—Challenges and Efforts to Secure Control Systems; U.S. General Accounting Office, March 2004 www.gao.gov/new.items/do4354.pdf

The Electronic Attack Threat to Supervisory Control and Data Acquisition (SCADA) Control & Automation Systems; National Infrastructure Security Coordination Centre (NISCC) www.nisc.gov.uk

Security Technologies for Manufacturing and Control Systems; ISA-TR99.00.01-2004 www.isa.org/isatr9900012004

Integrating Electronic Security into the Manufacturing and Control Systems Environment; ISA-TR99.00.02-2004 www.isa.org/isatr9900022004

Intrusion Prevention in a Control Systems Environment and Process Control Network—Reference Architecture; Invensys Process Systems e-mail at csc@invensys.ips.com

Operational Security: The real threat to our critical infrastructure; OSIsoft www.osisoft.com/whitepapers.aspx?pid=199&product=IT%20Monitor

Email
Print
Reprint
Learn RSS

Talkback

We would love your feedback!

Post a comment

» VIEW ALL TALKBACK THREADS

Sponsored Links



 
Advertisement

More Content

  • Blogs
  • Webcasts
  • Podcasts

Blogs


Sorry, no blogs are active for this topic.

» VIEW ALL BLOGS RSS

Podcasts

Advertisements





NEWSLETTERS
Plug in and get the latest MBT news, trends and industry updates delivered directly to your inbox!

Mid-Day Report (Twice Weekly)
MBT Europe (Twice Monthly)
White Space (Monthly)
Innovation Strategies (Monthly)
Intelligent Manufacturing (Monthly)
Lean Enterprise (Monthly)

About Us    |    Advertising Info    |   Site Map    |   Contact Us    |    FREE Subscription    |   Affiliate Links    |    RSS
©2008 Reed Business Information, a division of Reed Elsevier Inc. All rights reserved.
Use of this Web site is subject to its Terms of Use | Privacy Policy
Please visit these other Reed Business sites