Showing posts with label cyber war. Show all posts
Showing posts with label cyber war. Show all posts

Thursday, August 28, 2014

SonicWALL LDAP Vulnerabilities


URGENT: Dell SonicWALL Notice Concerning Multiple LDAP Vulnerabilities:


Dell SonicWALL has identified multiple LDAP authentication protocol vulnerabilities exposed when SonicOS is configured to use Microsoft Active Directory / LDAP for authentication of AD/LDAP usernames who are members of SonicWALL Administrator groups.

Please immediately logon to MySonicWALL ( https://www.mysonicwall.com/ ) , go to “My Products > Issue List”, and carefully review the related Dell SonicWALL Service Bulletin to determine if firmware upgrade or configuration remediation is applicable: https://www.mysonicwall.com/profile/issueresolution.aspx

Tuesday, August 5, 2014

Cyber War, Safety, and OSHA Revisited

Back on January 31, 2013, I posted an article on this blog titled "Cyber War, Safety, and OSHA." I introduced the new term "Workplace Industrial Cyber Safety."

It looked at computer viruses affecting Programmable Logic Controllers (PLCs). PLCs are essentially mini-micro-computers (a single chip) that run large, complicated machines or processes.

As technology advances we find new products that are either the same benefit as old products but with the use of technology, OR products improved (with new technological features/improvements) that make them a separate product in their own right.

A good example of the first kind of product ( same benefit via technology) is the Internet joke, "MS Word for blondes." MS Word provides the same benefit (a correspondence for example) as a pencil. You need a letter (the benefit), whether you write it or type it.


An example of the second (product with technological features/improvements) would be the ipod (compared to the old walkman. It is (basically) the same product (a music player/radio) but with new technological features; plays MP3s, and connects to the Internet.


The same happened with PLCs. PACs are PLCs with technological improvements, mainly networking and user interface:
A few years ago, the term PAC (Programmable Automation Controller) started to appear. Many PLC manufacturers began to market new PAC's along with their traditional line of PLC's (see AutomationDirect.com HERE for an example). If you use AutomationDirect.com as an example, their traditional line of PLC's (DL05, DL06, and others) are still available - and still fairly inexpensive. The new Programmable Automation Controller in contrast, is predictably more expensive and has many more options for networking, expandability, and user interface. This seems to be the differentiation between the traditional PLC and the newer PAC: Relative cost, expandability, functionality, and user options. (Source: PLC Engineers)

The most important  (and dangerous) features are the networking and user interface. The options for the user interface means that a technician no longer has to plug a cable into a PLC and "terminal" in (think DOS terminal). The technician can now connect from any computer (which acts as the terminal) via a network.


The second dangerous feature is the networking. Networking is a means of linking electronic devices so they can share data. The Internet is a network. There are many different types of networks, the most popular being a wired network, a Bluetooth network, power line networking, and a Wi-Fi network. All these have the potential, and most likely will be connected to the Internet.

This will gives hackers direct access to the machinery via the internet. Even if the network is nor connected to the Internet, hackers may gain access through a process called "War Driving." This has the potential to create man-eating machines. Almost all security systems are Internet connected, so hackers can potentially watch as they take over machines.


What is even more frightening is that companies want to network the appliances in our homes. Whirlpool has created (and is selling) digitally networked appliances with what it calls its "6th Sense Live technology." Whirlpool has a refrigerator, a dishwasher and a washer/dryer unit, all network enabled.


This started as a novel idea of being able to control lighting and appliances in one's own home remotely. This allows each appliance to be link up to a household Wi-Fi network, show up on customer smartphones, tablets and PCs, and be controlled (turned on/off) from the devices. See here:


GE is pushing their "Smart Grid" that will let homeowners cut annual energy consumption to zero by 2015. Learn more about appliance networking here:


I have been warning my clients about this for over 10 years, and I am surprised that nobody has picked up on this yet. So far it has been about terrorist attacks on infrastructure (power grid, waste water plants, nuclear power plants, etc.) and in academia.

A Good Resource:

Dr. Raj Jain, a professor at Washington University in St. Louis has an excellent web page titled: "Security in Private Networks of Appliance Sensors and Actuators," you can download it in a .pdf file here:

My Predictions:

Everything is becoming more linked together. This is creating new, unseen hazards. As I stated previously, it may be 5-10 years before a fatality occurs from a machine who's PLC/PAC has been hacked or infected with a virus. It could be longer than that until it is (forensically) discovered that the cause was hacking or a virus.

My Advice:

There is hope. With consumer appliance and whole home networks being advanced, they will be the first networks hacked/infected. The consumer will not put up with refrigerators that can be hacked, turned off, and millions of dollars worth of food going bad. These advanced will carry over to industry. As a safety professional, you should begin educating yourself about PLCs and PACs.

Thank you for reading.






Thursday, January 31, 2013

Cyber War, Safety, and OSHA


There is a new hazard that companies need to be aware of: 
Workplace Industrial Cyber Safety Hazards.

Hazard Alert!

There's a war going on, and it's raging here at home; not in the streets or the fields, but on the Internet. You can think of it as a war on the digital homeland. If you work for a power company, bank, defense contractor, transportation provider, or other critical infrastructure type of operation, your organization might be in the direct line of fire. And everyone can become collateral damage.

The Responsibility of Safety Professionals

So what responsibility do we as Safety Professionals and what responsibility do our companies (as employers) have to address cyber industrial safety hazards in workplace? Today computer malware go beyond identity theft. Today computer malware attacks PLC (Programmable Logic Controllers) that control the automation of industrial processes; for instance, to control machinery.

Cyber attacks evolve from espionage attacks that steal intellectual property or monitor communications to disruptive or destructive attacks. Destructive and disruptive cyber attacks are relatively uncharted and troubling territory. Computer virus can start a machine and prevent it from being shut down. Stuxnet is a computer worm; a destructive program that appears to have wiped out roughly a fifth of Iran’s nuclear centrifuges.


The worm itself now appears to have included two major components. One was designed to send Iran’s nuclear centrifuges spinning wildly out of control (Stuxnet). Another seems right out of the movies: The computer program (Flame) secretly recorded what normal operations at the nuclear plant looked like, then played those readings back to plant operators, like a pre-recorded security tape in a bank heist, so that it would appear that everything was operating normally while the centrifuges were actually tearing themselves apart.


"What if the machinery in your facility started up unexpectedly, started spinning wildly out of control, and refused to shut down? That is the new reality today. Are you prepared for it?"


In the past six months, there have been foreign attacks on oil and gas companies in the Middle East and on U.S. banks, including Bank of America, PNC Bank, Wells Fargo, Citigroup, HSBC, and SunTrust. How will we react if the next attack is against the electric grid, or our food and water supply.

Policies such as the 2012 Securities and Exchange Commission's Guidance on Cyber Disclosure now require many Fortune 500 companies to report any type of meaningful cyber threats in their organizations.

OSHA, LOTO, and the General Duty Clause

OSHA requires employers to provide a safe and healthful workplace that
is free from serious recognized hazards. LOTO requires machinery to be shutdown and no be able to be restarted, cycled, or energised.
Workplace Industrial Cyber Safety Hazards are a trigger here requiring employers to address them.

Malware

Both Flame and Stuxnet are considered malware. Malware, short for malicious (or malevolent) software, is software used or created by attackers to disrupt computer operation, gather sensitive information, or gain access to private computer systems. It can appear in the form of code, scripts, active content, and other software. Malware is a general term used to refer to a variety of forms of hostile or intrusive software.

Malware includes computer viruses, ransomware, worms, trojan horses, rootkits, keyloggers, dialers, spyware, adware, malicious BHOs and other malicious programs

Flame

Flame secretly mapped, recorded, and monitored Iran’s computer networks, sending back a steady stream of intelligence to prepare for a cyber­warfare campaign.

Stuxnet

Stuxnet infects Windows systems in its search for industrial control systems, often generically (but incorrectly) known as SCADA systems are used to control and watch industrial processes. Industrial control systems consist of PLC (Programmable Logic Controllers), which can be thought of as mini-computers that can be programmed from a Windows system.

These PLCs contain special code that controls the automation of industrial processes; for instance, to control machinery in a plant or a factory such as those used in pipelines or nuclear power plants. Stuxnet can enter a computer system, steal the formula for the product you are manufacturing, alter the ingredients being mixed in your product and indicate to the operator and your antivirus software that everything is functioning as expected.

Stuxnet is the first-ever computer worm to include a PLC (Programmable Logic Controllers) rootkit to hide itself and target critical industrial infrastructure. Successful exploitation of this vulnerability results in the injection of a backdoor, as well as the installation of two rootkits that will hide both the .lnk files and the accompanying .tmp files.

Origins of Flame and Stuxnet

The United States and Israel jointly developed a sophisticated computer virus named Flame and Stuxnet. Flame collected intelligence in preparation for cyber-sabotage (Stuxnet) aimed at slowing Iran’s ability to develop a nuclear weapon, according to Western officials with knowledge of the effort.

The effort, involving the National Security Agency, the CIA and Israel’s military, has included the use of destructive software such as the Stuxnet virus to cause malfunctions in Iran’s nuclear-enrichment equipment.

U.S. Attorney General Eric Holder announced a criminal probe last June (2012), shortly after a lengthy article by The New York Times' chief Washington correspondent, David Sanger, reported that anonymous, high-level sources in the Obama administration had told him that the U.S. and Israeli governments had used the Stuxnet worm to attack centrifuges at Iran's Natanz nuclear plant.

The Fix

Many security vendors have released Stuxnet removal tool and Microsoft has released Stuxnet FixIt tool too. There is a Microsoft Fix-IT solution, a solution called the G Data LNK Checker to block malicious LNK files, and a Stuxnet Rootkit Remover to clean the infected computers from common Stuxnet variants.

BitDefender has also released a free Stuxnet (Win32.Worm.Stuxnet) removal tool. This tool is capable of removing all known variants of Win32.Worm.Stuxnet, as well as the rootkit drivers that are used to hide critical components of the worm. The tool can be run on both 32-bit and 64-bit Windows operating system installations and will eliminate both the rootkit drivers and the worm.

[ Download Free BitDefender Stuxnet Removal Tool here: ]

[ Download Other BitDefender Security Tools here: ]

Consequences of Cyber War

Until the conflicts are resolved, almost everyone becomes a victim of unintended consequences during war, even cyber war. Cyber war may be digital, but it is still a form of war.

TRIA

The Terrorism Risk Insurance Act (TRIA) is a US federal law signed into law by President George W. Bush on November 26, 2002. The Act created a federal "backstop" for insurance claims related to acts of terrorism, mainly 9/11. The Act is intended as a temporary measure to allow time for the insurance industry to develop their own solutions and products to insure against acts of terrorism. The Act was set to expire December 31, 2005, but was extended to Dec. 31, 2014.

TRIA created a U.S. government reinsurance facility to provide reinsurance coverage to insurance companies following a declared terrorism event. TRIA is a short-term measure designed to help the insurance market recover from 9/11 and develop solutions to insuring terrorism.

Terrorism is not War.

War: An organized, armed, and often a prolonged conflict that is carried on between states, nations, or other parties usually over territory or resources. War can also be the liberation of a nation.

Terrorism: The French word terrorisme in turn derives from the Latin verb terreĊ meaning “I frighten.” Although “terrorism” originally referred acts committed by a government, currently it usually refers to the killing of innocent people by a non-government group in such a way as to create a media spectacle.

War usually has rules of conflict, such as the treatment of prisoners, terrorism does not follow the same rules, and often target civilians to put fear into the populace.
Most insurance policies include an "Act of War Exclusion." This can leave an employer vulnerable to (injury) claims as a result of a cyber attack.

Realistically....

It may take 5 to 10 years before we hear of a fatality caused by a machine with an infected PLC.Until then we will not hear about the machines refusing to shut down and "burning out" or "flying apart." We will not hear about the minor injuries from these events either. The employers may not even realize that their machines have been infected by a computer virus. They may simply say these were machine failure. 

Overshadowed by Terrorism


 There are warnings to power plants, pipelines, utilities, etc. for this, but they are for terrorism, not worker safety. Yes there is a danger to the public from these kinds of companies, but there is an even bigger danger from companies that are not considered terrorist targets. The danger is from being unaware that these computer viruses can affect their machinery.

These companies that make soda cans, plastic food containers, and key chains are not aware that one of these viruses that is aimed at a gas pipeline can find its way into their machinery and injure a worker. They may not even know it after the fact if they do not do a forensic investigation into the machine failure.

On the Front Line

Note: I am going to simplify the issue of Nuclear Automation. I realize to a certain degree today automation exists, the proposal (and reality) is much more complicated.
I have kept my eye on this issue from my work in the nuclear industry. The rule of thumb is triple redundancy, and up until recently, there were not three (reliable) computer OSs (Operating Systems) to provide triple redundancy. With Apple's OSX now a mainstream OS, there are three (Windows, Linux, and OSX).

Now there is real talk of automation in the Nuclear Industry. It scares me personally. There is no such thing as a completely closed system, and trying to achieve it is impractical. I question how much of the push for automation is for safety and how much is a cost savings.

Final Thoughts

I wear two hats in my organization: Risk Manager and IT Manager. It is from this unique perspective I was able to recognize this emerging threat. For years I have warned, educated, trained, and help prepare my clients for cyber threats.

For the last 10+ years I have been working with my clients to assess and prepare for hazards related to automated control systems. I am at the point now that I feel comfortable to come forward and begin educating our profession.

This opens up a new field in safety: Workplace Industrial Cyber Safety. This provides new opportunities for safety professionals such as myself, and gives a new career and  learning option for existing and upcoming safety professionals.

Employers and safety professionals need to think about and plan for escalating cyber conflicts and for disruptive and destructive attacks, not just espionage or intellectual property theft (the major focus undertaken against advanced persistent threats and hack in recent years). After all, more countries and groups will gain the ability to launch sophisticated attacks.

What can we do as Safety Professionals?

  • As safety professionals, we need to make sure that we have mechanical energy-isolation devices, that are not dependent on software, PLCs, to Lockout/Tagout our equipment.
  • Anticipate, recognize, prepare, and train for hazards from automated control systems becoming infected or corrupt, such as machinery that has been shut down starting, "run away" machinery,  and prevent machinery from being shut down.
  • Work with stakeholders (vendors, suppliers, maintenance, management, IT) to protect against automated control system hazards (upgrading existing networks, ordering new equipment with mechanical safeguards built in).  
  • Conduct (or have conducted) threat assessments based on level of cyber security and industry. 
  • Review your company's need to comply with policies such as the 2012 Securities and Exchange Commission's Guidance on Cyber Disclosure
  • If we do not have the expertise, then bring in someone who does. 
  • More training.

 

Take note:

 I have searched the Internet, published works, other blogs, and this is the first and only place to recognize the risks of cyber attacks as a workplace hazard in respect to OSHA. This is the cutting edge, forward thinking that I try to provide.

Thank you for reading.