How to Detect Hidden Threats in SCADA Networks

389 views
•
September 26, 2017
by
RSAC Cybersecurity
YouTube video player
How to Detect Hidden Threats in SCADA Networks

TL;DR

Detect SCADA compromises early by combining observations from field devices, controllers, human-machine interfaces, hosts, network traffic, logs, and decoys in a central security monitoring process. Because attackers may remain inside networks while learning how industrial systems operate, defenders must watch every attack stage and interpret proprietary protocols, configuration changes, set points, ladder logic, alarms, and endpoint behavior.

Transcript

All right. Thank you everybody for attending today. I'm Gib Sorbo, Chief Cybersecurity Technologist with Leidos. Uh, today we wanna talk about, uh, SCADA security, as some call it, uh, or industrial control system security, uh, and look at really the h-how, uh, how we really can detect whether or not, um, a particular, uh, uh, attack is, uh, has ha... Read More

Key Insights

  • SCADA security requires specialized visibility because industrial networks use proprietary controls, serial connections, unusual protocols, and devices that differ from conventional enterprise technology. Standard security concepts remain relevant, but defenders must adapt collection and interpretation methods to the operational environment.
  • Physical damage can result from manipulated or inaccurate sensor data because control processes depend on measurements to guide automated actions. The Taum Sauk reservoir failure was not described as a cyberattack, yet detached water-level sensors contributed to overfilling and a destructive washout.
  • Early detection is essential because attackers may spend long periods exploring a network, moving between zones, and learning how industrial processes work. Greater operational knowledge can allow an adversary to design more damaging actions than an attacker who launches destructive commands without understanding the system.
  • The attack life cycle creates detection opportunities during reconnaissance, establishment of an initial foothold, lateral movement, and mission completion. In industrial environments, the foothold may begin in the enterprise network before the attacker crosses into increasingly sensitive control-system zones.
  • Field-device monitoring is difficult because sensors and actuators are often analog and may lack sophisticated logging capabilities. Defenders must still seek useful measurements from pumps, switches, temperature sensors, vibration sensors, and other equipment to identify deviations that could indicate failure or manipulation.
  • Controller-level detection can identify unauthorized operational changes by monitoring set points, ladder logic, controller software, and available logs. These signals are especially important because controllers translate measurements and commands into actions that directly affect industrial equipment and physical processes.
  • Higher-layer monitoring can reuse familiar enterprise security methods because human-machine interfaces and supervisory systems often run Windows or Linux. Defenders can track alarm settings, controller update code, configuration files, workstation state, application settings, analytics, triggers, network traffic, and endpoint behavior.
  • Centralized analysis is most effective when a security information and event management platform receives information from packet collectors, aggregators, intrusion detection systems, endpoint agents, logs, and lower-level monitoring interfaces. Proprietary data may require unique parsers before analysts can understand its operational significance.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How can organizations detect a hidden SCADA compromise?

Organizations can detect a hidden SCADA compromise by combining evidence from every control-system layer. Useful sources include field measurements, controller set points, ladder logic, human-machine interface alarms, configuration files, operating-system activity, packet captures, endpoint agents, and logs. A central security information and event management platform can aggregate these signals, while specialized parsers and collectors interpret proprietary protocols and serial communications.

Q: Why is early detection important in industrial control networks?

Early detection is important because attackers may remain inside a network while exploring systems, identifying vulnerabilities, moving laterally, and learning how physical processes operate. That knowledge can enable more carefully targeted damage. The German steel mill example suggests limited attacker understanding constrained the harm, while Stuxnet illustrates how deeper knowledge and insufficient device monitoring can support a more sophisticated operation.

Q: What stages of an industrial cyberattack can defenders monitor?

Defenders can monitor reconnaissance, establishment of an initial foothold, lateral movement across zones, and completion of the attacker’s mission. Each stage offers a chance to detect the intruder or stop further progress through human, automated, or protective mechanisms. In a control-system environment, the initial foothold may occur on the enterprise network before movement into more sensitive industrial segments.

Q: What should be monitored at the field-device layer?

At the field-device layer, defenders should observe sensors and actuators that measure conditions or change process behavior. Examples in the talk include temperature and vibration measurements, pumps, and switches. Monitoring is difficult because many of these devices are analog and cannot produce sophisticated logs, so organizations may need alternative ways to collect measurements and identify abnormal physical behavior.

Q: How can controller changes reveal a SCADA attack?

Controller changes can reveal an attack when monitoring identifies unexpected modifications to set points, ladder logic, software, or logged activity. Controllers influence how equipment responds to measured conditions, making these changes operationally significant. Reviewing controller state alongside physical measurements and higher-level commands helps defenders determine whether an unusual action reflects an authorized adjustment, a malfunction, or potentially malicious manipulation.

Q: Can enterprise security tools work in SCADA environments?

Enterprise security tools can work in SCADA environments, particularly at higher architectural layers that use Windows or Linux systems. Intrusion detection, firewalls, packet collection, endpoint agents, application monitoring, analytics, alarms, triggers, and workstation configuration controls can all contribute. However, lower layers may require serial monitoring, proprietary protocol support, custom collection methods, and specialized interpretation before their data becomes useful.

Q: How should proprietary SCADA logs and protocols be handled?

Proprietary SCADA logs and protocols should be collected through compatible interfaces and translated with parsers that understand their formats. Lower-level data may arrive over serial connections or other specialized protocols, while logs are generally more available at level one and above. The processed information can then feed an aggregator, intrusion detection capability, or security information and event management platform for alerting and analysis.

Q: What role do honeypots play in industrial network detection?

Honeypots act as decoys designed to attract intruders and reveal unauthorized activity. The talk presents them as a relatively new area for both enterprise and industrial control environments and encourages organizations to examine their use. When deployed relatively safely, they can provide another detection mechanism alongside traffic monitoring, endpoint agents, controller inspection, log analysis, and centralized event aggregation.

Summary & Key Takeaways

  • Industrial control attacks can produce physical consequences by manipulating sensors, controllers, or operational data. The Taum Sauk reservoir failure illustrates how incorrect sensing can cause severe damage even without a cyberattack, while Stuxnet, the German steel mill incident, and Ukraine grid disruptions demonstrate the importance of detecting malicious activity before it affects operations.

  • Attackers commonly progress through reconnaissance, an initial foothold, lateral movement across network zones, and mission completion. Each stage creates an opportunity for detection or prevention. Early discovery matters because intruders can remain inside a network for extended periods, study specialized equipment, identify exploitable weaknesses, and develop enough operational knowledge to cause greater damage.

  • Effective SCADA monitoring combines data from multiple architectural layers. Defenders can examine physical measurements, controller set points, ladder logic, human-machine interface alarms, configuration files, operating systems, applications, packets, serial communications, proprietary logs, and endpoint agents. A security information and event management platform can aggregate these signals for interpretation, alerting, and investigation.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚