Zibb
Subscribe to Control Engineering
FirstLight
Email
Print
Reprint
Learn RSS

Live hacking into your process

By Mark T. Hoske, Editor-in-Chief -- Control Engineering, 11/1/2005

Related Reading

It's real. I saw it. Believe. Hackers can remotely enter facilities via laptop, run pumps, and actuate valves without the knowledge of owners/operators. It can be done, through multiple firewalls, with active security measures and technologies in place.

U.S. Department of Energy and Department of Homeland Security, working through Idaho National Labs (INL), demonstrated a gut-wrenching breach to prove the need to aggressively lessen chances of process facility intrusion.

There's no such thing as security, just layers of protection. In a morbid sense, that means running faster than your buddy, not faster than the bear looking for lunch. In this case, the bear, an INL cyber-security engineer, worked for three weeks to hack into a tasty demo of real equipment and software. If that wasn't unsettling enough, INL confirmed that real-world facilities have been breached already. Press releases generally aren't issued, nor is law enforcement telling, which doesn't help quantify risks of standard hackers, organized crime, and nation/states with terror in mind.

Firewalls aren't enough. Defending proprietary controls (PLC or DCS) isn't enough. Microsoft, Linux, Unix—it doesn't matter; all are vulnerable.

'Our goal isn't to get people to throw up their arms and say, 'There's nothing we can do,' but to encourage people to acknowledge there are problems and take some actions,' said a grim-faced John Hammer, INL cyber-security engineer/hacker.

This isn't the only way 'in,' but, briefly, here's what I saw. Invasive code embedded into clip art was innocently downloaded into a PowerPoint presentation. The code was disguised and programmed to dial out undetected, through commonly used enterprise firewall software. The hacker used available tools to get permissions to get through a second firewall. A list of devices was found, the controller was reverse engineered, and the hacker took control via laptop.

INL's hacker showed on-screen tags on the plant human-machine interface, and pushed a spoofed set of values onto the screen, while actuating devices underneath that deception to do what he wanted, without triggering alarms. Imagine explaining that to spouses of dead coworkers, bosses, shareholders, media, and settlement-hungry attorneys after a toxic breach.

The live hacking demonstration, at the 2005 Emerson Global Users Exchange, left many attendees with mouths agape, not knowing if they should applaud, call the police, or immediately dial back home to alert coworkers that the threat is more real than anticipated. This column under November 2005 at www.controleng.com/archives has links to help augment your layers of protection.

Mark T. Hoske, Editor-in-Chief

mhoske@reedbusiness.com

ONLINE EXTRA

Hackers may visit soon

Hackers have conferences and Web sites to exchange best practices and best-in-class tools, explained INL, on Oct. 4, at the Emerson users conference in Orlando, FL. And hackers generally work longer hours than most control engineers. Don’t think you’re immune to intrusion. Ask any of 50,000 Daimler-Chrysler workers at 13 plants, idled for a time during 2005, while damage from Zotob worm was fixed, INL said.

For related information, click here.

Email
Print
Reprint
Learn RSS

Talkback

We would love your feedback!

Post a comment

» VIEW ALL TALKBACK THREADS

Related Content

Related Content

 

By This Author

Sponsored Links

 

Advertisement
SPONSORED LINKS

More Content

  • Blogs
  • Discussions
  • Webcasts
  • Podcasts
  • Videos

Blogs

  • Charlie Masi
    Ask Charlie

    December 1, 2008
    Why should we spend billions of dollars on high-energy physics research?
    This question came in as a (rather irate sounding) Talkback item for a recently published article in a Control Engineering print issue. It rea......
    More
  • Paul Grayson
    AIMing for Automated Vehicles

    November 30, 2008
    Pass In Review
    Photo: AIM photo archive US ARMY M35A2 US Army cargo truck on loan to AMERICAN INDUSTRIAL MAGIC for the DARPA Grand Challenge. The phot......
    More
  • View All BlogsRSS

Discussions

  • Re: Modbus Slave Simulator (reply posted by Mark)

  • Magelis XBTGT with Zelio Smart Relay via MODBUS (posted by N1K0)

  • P & I Autocad symbols (posted by Takudzwa)


  • Source: Control.com, the global online discussion community for automation professionals.

    Webcasts

    Engineering-driven Ethernet
    This Control Engineering Roundtable Webcast will address the engineering issues you should be aware of when exploring the adoption of Ethernet or when looking to expand its use in your facility.

    Bridging gaps with wireless
    Discover how you can create stronger, flexible and cost-effective wireless connections for your entire plant. Register today!

    View All Webcasts
    Advertisements





    NEWSLETTERS

    Get engineering industry news, trends, and business-critical information delivered directly to your inbox!

    Click on a title below to learn more.

    Weekly News (Weekly)
    Process Instrumentation & Sensors (Monthly)
    System Integration Monthly (Monthly)
    Process & Advanced Control (Monthly)
    Machine Control (Monthly)
    Information Control (Monthly)
    Automation Control (Monthly)
    Product Review (Monthly)
    Simplified Safety
    Fieldbus Facts
    PROFInews North American Edition
    About Us   |   Advertising Info   |   Site Map   |   Contact Us   |   Useful Sites   |   FREE Subscription   |   RSS
    © 2008 Reed Business Information, a division of Reed Elsevier Inc. All rights reserved.
    Use of this Web site is subject to its Terms of Use | Privacy Policy
    Please visit these other Reed Business sites