scieee Open visual document viewer

IT security aspects of industrial control systems

Holečko, P.

Abstract

This paper discusses a set of general network system architectures for industrial process control systems as well as vulnerabilities related to these systems and the IT threats these systems are exposed to from the point of view of Common Criteria methodology and ITU-T recommendation X.805.

Full text

Ad ances in Elec ical and Elec onic Enginee ing 136 IT SECURITY ASPECTS OF INDUSTRIAL CONTROL SYSTEMS P. Holeko, I. K bilo á Uni e si y o Zilina, Facul y o Elec ical Enginee ing, Depa men o In o ma ion and Con ol Sys ems Uni e zi na 1, SK 010 26, Zilina, Slo ak epublic E-mail: pe e .holecko@ el.u c.sk, izabela.k bi[email p o ec ed].sk Summa y This pape discusses a se o gene al ne wo k sys em a chi ec u es o indus ial p ocess con ol sys ems as well as ulne abili ies ela ed o hese sys ems and he IT h ea s hese sys ems a e exposed o om he poin o iew o Common C i e ia me hodology and ITU-T ecommenda ion X.805. 1. INTRODUCTION Real- ime con ol sys ems used in p ocess con ol applica ions ha e many cha ac e is ics di e en han adi ional p ocess in o ma ion sys ems. Fo emos among hese is design o e iciency and ime-c i ical esponse. Secu i y is gene ally no a s ong design mo i a ion and he e o e ends o ge ou o way o pe o mance. Compu ing esou ces a ailable o pe o m o secu i y unc ions a e o en e y limi ed. 2. PROCESS CONTROL SYSTEMS Digi al indus ial con ol sys ems can be classi ied in o p ocess-based sys ems o disc e e- based sys ems. P ocess-based con ols a e used o con ol a con inuous p ocess such as uel low in a powe plan o pe oleum in a e ine y. Disc e e- based con ols (also known as ba ch con ols) con ol disc e e pa s manu ac u ing o “ba ches” o ma e ial like in a chemical plan . Bo h ypes o con ol u ilize he same ypes o con ol sys ems, senso s, and ne wo ks. Figu e 1 shows he key con ol componen s o an indus ial con ol sys em, including he con ol loop, he human – machine in e ace (HMI), and emo e diagnos ics and main enance u ili ies [1]. A con ol loop consis s o senso s, con ol ha dwa e, p ocess ac ua o s, and communica ion o measu emen a iables. Measu emen a iables a e ansmi ed o he con olle om he p ocess senso s. The con olle in e p e s he signals and gene a es he co esponding con ol signals ha i ansmi s o he p ocess ac ua o s. P ocess changes esul in change o senso signals, iden i ying he s a e o he p ocess. The human – machine in e ace allows a con ol enginee o ope a o o con igu e se poin s, con ol algo i hms and pa ame e s in he con olle . The HMI also p o ides displays o p ocess s a us in o ma ion, ala ms, and o he ele an da a. Diagnos ic and main enance ools, o en a ailable ia modem and In e ne in e aces, allow con ol enginee s, ope a o s and endo s o moni o and modi y con olle , senso , and ac ua o p ope ies om emo e loca ions.                !  !  "" " Fig.1 Main con ol componen s A ypical indus ial con ol sys em con ains an ex ension o con ol loops, HMIs and Remo e Diagnos ics and Main enance ools buil on an a ay o ne wo k p o ocols. Supe iso y le el loops and lowe le el loops ope a e con inuously o e he du a ion o a p ocess a cycle imes anging on he o de o minu es o milliseconds. In a la ge en e p ise, he e may be se e al geog aphically dis ibu ed indus ial plan s. En e p ise business ope a ions can access plan in o ma ion o e he In e ne o in some cases o e a wide a ea ne wo k (WAN). The local a ea ne wo k (LAN) o a p ocessing plan se ices all o he ope a ions wi hin he plan while he ac ual con ol sys em o he plan si s on a somewha isola ed pee - o-pee ne wo k. A his le el he sys ems can be ca ego ized in o wo ypes o supe iso y based con ol schemes, Dis ibu ed Con ol Sys ems (DCS) and Supe iso y and Da a Acquisi ion Sys ems (SCADA). DCS a e used o con ol la ge complex p ocesses such as powe plan s, e ine ies o chemical plan s ypically a a single delimi ed si e. By con as , SCADA a e used o con ol mo e dispe sed asse s whe e cen alized da a acquisi ion is as impo an as con ol. Examples o SCADA applica ions a e he wa e , gas, and elec ical ene gy dis ibu ion ope a ions. The gene al ne wo k a chi ec u es o DCS and SCADA a e shown in Figu e 2. By compa ison o hese schemes we can see ha a a highe le el o ne wo k a chi ec u e, he pe o med plan ope a ions a e simila o plan s using ei he DCS o SCADA sys ems. A his le el, e e y hing esides on a local IT secu i y aspec s o indus ial con ol sys ems 137 a ea ne wo k. Componen s include gene al pu pose wo ks a ions, p in e s, da abases, applica ion se e s and domain con olle s. Communica ion ou side he plan is ypically es ablished ia In e ne o WAN using a i ewall. The DCS and local SCADA componen s o a plan ypically ope a e on a pee - o- pee ne wo k. A DCS is comp ised o a supe iso y laye o con ol and one o se e al dis ibu ed con olle uni s wi hin he same p ocessing plan . The supe iso y con olle uns on he con ol se e and communica es wi h i s subo dina e uni s ia a pee - o-pee ne wo k. The supe iso sends se poin s and ecei es da a om dis ibu ed con olle s. The dis ibu ed con olle s con ol hei associa ed p ocess ac ua o s based on eques s om he supe iso and p ocess senso s eedback. The communica ion o con olle wi h i s senso s and ac ua o s is ypically ealized using a local ield bus elimina ing he need o poin - o-poin connec ion be ween he con olle and each o hese de ices. The e a e se e al ypes o con ol uni s used in dis ibu ed con ol poin s o a DCS. In dependence o applica ion he mos widesp ead a e machine con olle s, p og ammable logic con olle s (PLC), p ocess con olle s and single loop con olle s. A ypical SCADA consis s o a Cen al Moni o ing Sys em (CMS) and one o mo e Remo e S a ions (RST). The CMS houses he Con ol Se e and he communica ion ou e s ia a pee - o-pee ne wo k, collec s and logs in o ma ion ga he ed om by he emo e s a ions and gene a es necessa y ac ions. A emo e s a ion consis s o ei he a Remo e Te minal Uni (RTU) o a PLC which con ols ac ua o s and moni o s senso s. In mos cases he RST has a capabili y o diagnos ic and epai unc ions in e aced ia some ype o po able compu e . The communica ion channel be ween emo e s a ions and he CMS is ealized using me allic line, op ical line o adio equency wi h epea e s, whe e necessa y. Ne wo ked con ol sys em a chi ec u es which include con inuous ope a ions o ans o ma ion o aw ma e ials in o usable p oduc s, ollow he DCS scena io. On he o he hand, he ne wo k a chi ec u es suppo ing dis ibu ion ope a ions o usable p oduc s, copy he s uc u e o SCADA. 3. VULNERABILITIES AND IT THREATS As we said be o e, in he sphe e o p ocess con ol, he IT secu i y has been o minimum impo ance. Sys ems we e p ima ily designed o mee pe o mance, eliabili y, sa e y, and lexibili y equi emen s and we e ypically physically isola ed and based on p op ie a y ha dwa e and communica ion sys ems. The in oduc ion o In e ne based in o ma ion echnology wi hin he p ocess con ols indus y has inc eased ulne abili ies o he indus y’s compu e sys ems. Cen alized ope a ion and emo e main enance o indus y sys ems pe o med o e public elecommunica ion ne wo ks p o ides po en iali ies o h ea ening in luences o his c i ical in as uc u e. DCS and SCADA sys ems ha ope a e on comme cial ha dwa e and so wa e, combined wi h connec ions o ex e nal ne wo ks, allow a simpli ied in asion and possible de as a ion o hese sys ems. In he su ey [2] which has been pe o med on a sample o o ganiza ions wi h 100 and mo e employees in di e en sec ions o indus y, business, se ices, and s a e adminis a ion, 75% o esponden s poin ed he occu ence o secu i y inciden s caused by i uses, 28% caused by LAN ailu e, and 24% due o WAN ailu e. The ea s can o igina e in di e en sou ces: despi e ul in ade , e o is g oup, disg un led employe , hos ile go e nmen , bu also acciden and na u al disas e . Fig.2 Example o DCS and SCADA a chi ec u es LAN Wo ks a ion HMI Hub/swi ch pee - o-pee ne wo k PLC senso s/ ac ua o s senso s/ ac ua o s senso s/ ac ua o s senso s/ ac ua o s HMI Machine Con olle P ocess Con olle Single Loop Con olle LAN Wo ks a ion HMI Hub/swi ch In e ne /WAN Con ol se e Dis ibu ed plan pee - o-pee ne wo k RTU/PLC RTU/PLC senso s/ ac ua o s senso s/ ac ua o s RST RST RTU/PLC RTU/PLC senso s/ ac ua o s senso s/ ac ua o s RST RST Con ol se e SCADA DCS Ad ances in Elec ical and Elec onic Enginee ing 138 4. THE COMMON CRITERIA (CC) PROJECT The goal o he Common C i e ia (CC) p ojec was o de elop a s anda dized me hodology o speci ying, designing, and e alua ing IT p oduc s ha pe o m secu i y unc ions which would be widely ecognized and yield consis en , epea able esul s independen ly o echnology and implemen a ion [3]. The h ee-pa CC s anda d ISO/IEC 15408, and he CEM a e wo majo componen s o he CC me hodology, as shown in Fig. 3. Fig.3 Majo componen s o he CC/CEM Fou key concep s a e p esen ed in Pa 1 o he s anda d: 1. P o ec ion P o iles (PPs), 2. Secu i y Ta ge s (STs), 3. Ta ge s o E alua ion (TOEs), 4. Packages. A P o ec ion P o ile is an implemen a ion- independen se o secu i y equi emen s o a ca ego y o TOEs ha mee speci ic consume needs [4]. Secu i y Ta ge deno es a se o secu i y equi emen s and speci ica ions o be used as he basis o e alua ion o an iden i ied TOE. Ta ge o E alua ion is an IT p oduc o sys em and i s associa ed adminis a o and use guidance documen a ion ha is he subjec o an e alua ion. A package is a eusable se o ei he unc ional o assu ance componen s (e.g. an E alua ion Assu ance Le els), combined oge he o sa is y a se o iden i ied secu i y objec i es. 5. ITU-T RECOMMENDATION X.805 The Recommenda ion de ines gene al secu i y- ela ed a chi ec u al elemen s ha app op ia ely applied can p o ide end- o-end ne wo k secu i y [5]. The a chi ec u e shown in Fig. 4 can be used wi h di e en ne wo k elemen s, se ices, and applica ions in o de o de ec , p edic , and co ec secu i y ulne abili ies. Fig. 4 Secu i y a chi ec u e o ne wo k secu i y A Secu i y Dimension is a se o secu i y measu es designed o add ess a pa icula aspec o he ne wo k secu i y. The Recommenda ion X.805 iden i ies eigh such se s ha p o ec agains all majo secu i y h ea s: 1. Access Con ol, 2. Au hen ica ion, 3. Non- epudia ion, 4. Da a Con iden iali y, 5. Communica ion Secu i y, 6. Da a In eg i y, 7. A ailabili y, and 8. P i acy. In o de o o e he lexibili y o coun e ing he po en ial h ea s he e a e h ee secu i y laye s de ined: he In as uc u e Laye , he Se ice Laye , and he Applica ion Laye . The secu i y Laye s iden i y whe e secu i y mus be add essed in elemen s and sys ems by p o iding a sequen ial pe spec i e o ne wo k secu i y. The Managemen Secu i y Plane, he Con ol Secu i y Plane, and he End-Use Plane a e a ce ain ype o ne wo k ac i i y p o ec ed by Secu i y Dimensions. Ne wo ks should be designed in such a way ha e en s occu ed on one Secu i y Plane a e kep o ally isola ed om he o he Secu i y Planes. The a chi ec u e iden i ies secu i y issues ha need o be add essed in o de o p e en bo h in en ional as well as acciden al h ea s. The ollowing h ea s a e desc ibed [6]:  des uc ion o in o ma ion and/o o he esou ces,  co up ion o modi ica ion o in o ma ion,  he , emo al o loss o in o ma ion and/o o he esou ces,  disclosu e o in o ma ion,  in e up ion o se ices. The in e sec ion o each Secu i y Laye wi h each Secu i y Plane ep esen s a secu i y pe spec i e IT secu i y aspec s o indus ial con ol sys ems 139 whe e Secu i y Dimensions a e applied o coun e ac he h ea s. Table 1 shows mapping o Secu i y Dimensions o he designa ed secu i y h ea s. Table 1 Mapping Secu i y Dimensions o secu i y h ea s 6. CONCLUSION P e iously we in oduced he issue o secu ing dis ibu ed indus ial p ocess con ol sys ems build on DCS o SCADA sys em a chi ec u e wi h WAN o In e ne connec i i y. Such connec i i y o public accessible ne wo ks makes hese sys ems po en ial a ge s o a acks on hei ulne abili ies. The objec i e o ITU-T Recommenda ion X.805 is o gi e de elope s a comp ehensi e op-down basis o c ea ion o de ailed ecommenda ions o he end- o-end ne wo k secu i y independen ly o he ne wo k’s unde lying in o ma ion echnology o p o ocol s ack. The Common C i e ia p ojec is applicable as a guide o he e alua ion o sys ems wi h IT secu i y unc ions and IT secu i y measu es implemen ed in ha dwa e, i mwa e, o so wa e. The speci ic Ta ge o E alua ion can be a pa icula ne wo k elemen bu also an en i e subsys em o ne wo k. Usage o combina ion o hese amewo ks in design, implemen a ion and e alua ion o dis ibu ed con ol sys ems applied in oday’s indus y will lead o minimiza ion o secu i y h ea s impac s. Fu he wo k in ield o applica ion and de elopmen o me hodologies o inc easing secu i y o dis ibu ed indus ial con ol sys ems will con inue. REFERENCES [1] Falco, J., S ou e , K., Wa e ing, A., P oc o , F.: IT Secu i y o Indus ial Con ol Sys ems. Na ional Ins i u e o S anda ds and Technology, Gai he sbu g (2002). [2] In o ma ion Secu i y Su ey in he Slo ak Republic 2004. KPGM Slo ensko, DSM – da a secu i y managemen , NSA SR (2005). [3] He mann, D.S.: Using he Common C i e ia o IT Secu i y E alua ion. Aue bach Publica ions (2003). [4] Common C i e ia o In o ma ion Sys em Secu i y E alua ion, Ve sion 2.1, (1999). [5] D a ITU-T Recommenda ion X.805 (Fo me ly X.css), Secu i y a chi ec u e o sys ems p o iding end- o-end communica ions. ITU (2003). [6] CCITT Recommenda ion X.800, Secu i y a chi ec u e o Open Sys ems In e connec ion o CCITT applica ions. CCITT, Gene a (1999). SECURITY THREAT SECURITY DIMENSION Des uc ion Co up ion, Modi ica ion The , Remo al, Loss Disclosu e In e up ion Access Con ol     Au hen ica ion   Non- Repudia ion      Da a Con iden iali y   Comm. Secu i y   Da a In eg i y   A ailabili y   P i acy 