Skip to main content

My InfoTech Journal!

My InfoTech Journal: Decoding the Networking Enigma: OSI vs. TCP/IP Reference Models

My InfoTech Journal: Decoding the Networking Enigma: OSI vs. TCP/IP Reference Models The OSI (Open Systems Interconnection) Reference Model and the TCP/IP (Transmission Control Protocol/Internet Protocol) Reference Model: The OSI Reference Model and the TCP/IP Reference Model are both conceptual frameworks used to understand and standardize how different networking protocols and technologies interact. Here are some areas of comparison: 1. Number of Layers: OSI Model : It consists of seven layers: Physical, Data Link, Network, Transport, Session, Presentation, and  TCP/IP Model : It has four layers: Network Interface, Internet, Transport, and Application. 2. L ayer Functionality: OSI Model : Tends to be more comprehensive and abstract, defining each layer's functions independently. TCP/IP Model : Reflects the actual implementation of the Internet and focuses on how protocols are used in practice. 3. Adoption / Use: OSI Model : Less commonly used in practice, but it is still valuab

CyberSecurity Vulnerabilities in Control Systems

My InfoTech Journal: 
CyberSecurity Vulnerabilities in Industrial Control Systems


For this article, I will be presenting an overview of CyberSecurity Vulnerabilities, using the US CyberSecurity & Infrastructure Security Agency (CISA) guidelines for Industrial Control Systems.

Please note that this US CISA CyberSecurity guideline is specific to Industrial Control Systems. Nonetheless the framework and line of thought can be used as reference for any other similar environment.

CyberSecurity aims to protect sensitive information hosted in critical systems from different faces of evolving threats.

Year-by-year business reports would publish the cost of data breaches globally in millions of US dollars. This includes losses in business revenues, cost of responding to the breach, cost of deciphering the extent of the data breach,  performing root cause analysis, and most of all the long term damage of the company reputation and brand.

In order to protect your Control System’s risk and exposure to Cyber Attacks, you have to be familiar with the CyberSecurity Vulnerabilities.

The US CyberSecurity & Infrastructure Security Agency (CISA) guideline is just one of several frameworks  that you can use as reference for your CyberSecurity program.

It is fundamental to start with a mindset that every component within your Control System is vulnerable from internal and external threats. 

To understand the system’s threats, you must understand your environment: how each individual systems work and how each network components communicate with each other. 

It is also very much important to learn and understand what are the vulnerabilities inherent to each components, as this is what hackers use as their attack vectors.

The following points of discussion were taken from the US CyberSecurity & Infrastructure Security Agency (CISA) Overview of Cyber Vulnerabilities for Control Systems. 1

This discussion (as posted in their website) provides a high level overview of these topics but does not discuss detailed exploits used by attackers to accomplish intrusion. 

  • Understanding Control System Cyber Vulnerabilities
  • Access to the Control System LAN
    • Common Network Architectures
    • Dial-up Access to the RTUs
    • Vendor Support
    • IT Controlled Communication Gear
    • Corporate VPNs
    • Database Links
    • Poorly Configured Firewalls
    • Peer Utility Links
  • Discovery of the Process
  • Control of the Process
    • Sending Commands Directly to the Data Acquisition Equipment
    • Exporting the HMI Screen
    • Changing the Database
    • Man-in-the-Middle Attacks


Understanding Control System’s CyberSecurity Vulnerabilities

To understand the Control System’s CyberSecurity Vulnerabilities, you must first understand your system’s environment. This is where the overall system and network diagram is crucial. 

Start with an accurate inventory of what are installed in your Control System network. This will be your point of reference for ensuring that every system and network components are accounted for. This will help you fully assess each system and component vulnerabilities. 

Perform Risk Assessment on your Control System environment. This will help you to understand the risk factors that may have potential impact on your critical systems. This is where you assess the severity of each risks and the probability of these risks from happening.

The Risk Assessment result will be your reference in prioritizing your remediation program and focusing your resources in the critical and highly probable risk areas.


Example of a Control System Environment 


Diagram 1: Example of a Control System Environment 
Photo Credits: US CISA (CyrberSecurity & Infrastructure Security Agency)1 


Diagram 1 is an example of a control system environment. 

The above diagram is a very valuable information to understand the system’s environment. This is a very useful information to start with understanding the system architecture and what components are there within the environment. 

The same diagram in the wrong hands, like that of an Attacker might possibly cause catastrophic results!

Understand how each component communicates with each other. You have to be thorough in your review and assessment on how each access points work and how authorized permissions are granted. 

Mark these components as target vectors by Attackers who are trying to gain access to the entire control system environment by all means possible. 

Follow the path of communication between each of the system components to understand any other vulnerabilities within your network.

You need to understand the vulnerabilities in each of the system components and how these affects the other systems or network components within the control system environment.

Ensure that each of the vulnerabilities in each device or systems are resolved or mitigated on a timely manner. 

The system risk assessment  and vulnerability patching has to be a continuous process so as to keep your system abreast with new patches.

Your CyberSecurity program does not end here, there are a lot of other areas to improve on. Like your Incident Response procedure, your Team’s skill sets and continuous learning, systems resiliency, data backup and recovery procedure, and continuous improvement on your systems to adapt with technological advancements as needed. 

There should also be a continuous learning and development process for End-User education.

Understanding the CyrberSecurity Vulnerabilities is a good starting point. 

Ensuring that your system environment is secured and protected has to be your main objective.



Attackers Perspective 

You may have always heard or read that it is important to also understand how an Attacker thinks. 

This may be too much to ask, but at least you have to understand the basic principle of what they look out for.

From an Attackers point of view, the fundamental objective is to:

1. Perform reconnaissance to understand the environment, identify weak points and vulnerabilities.

2. Exploit these vulnerabilities and gain access to the Control System’s local area network.

3. Take over control of the Control System’s processes.

If an Attacker is successful with the three basic objectives, your control system is owned!


End Notes

1 US CyberSecurity & Infrastructure Security Agency (CISA): Cyber-Vulnerabilities


Disclaimer 

This article is a result of my personal research and is not a substitute for legal advise. 

Please consult your Legal Team, Ethics & Compliance, or Regulatory Team for the interpretation of  specific CyberSecurity requirements.



Support My InfoTech Journal






Comments

POPULAR: My InfoTech Journal

Information Security Tenets (The CIA Triad)

My InfoTech Journal:   Information Security Tenets The CIA Triad The   three tenets or fundamental principles of Information Security are  Confidentiality ,  Integrity , and  Availability .  This is also commonly known as the CIA Triad . The Information Security  programs refers to the controls designed and implemented to protect these three tenets:  Confidentiality ,  Integrity , and  Availability .   What is Confidentiality? Confidentiality ensures that private information remains private and that these private information can only be accessed or viewed by authorized individuals on need to know basis. Information Security controls must therefore be put in place to protect the data from unauthorized disclosure.  Examples of  Information Security controls  to ensure Data Confidentiality : Access Control List (ACL) Username and Password  Encryption  Two-Factor Authentication (Password, Token, PIN, Biometric, etc) What is Integrity? Integrity refers to the accuracy and completeness of t

MyInfoTechJournal: Never Let a Crisis Go to Waste: The Ultimate Business Continuity Plan (BCP) for Thriving in Any Situation (Part 3 of 3: EXAMPLE)

MyInfoTechJournal: Never Let a Crisis Go to Waste: The Ultimate Business Continuity Plan (BCP) for Thriving in Any Situation  (Part 3 of 3: EXAMPLE)

Are You Safe? The Shocking Truth About Privacy Risks and How to Protect Yourself

My InfoTech Journal: Are You Safe? The Shocking Truth About Privacy Risks and How to Protect Yourself

Network Security: How to minimize the Risk of your Wireless Network

My InfoTech Journal: What you can do to minimize the risk of your wireless network? Access Points are usually targets for unauthorized access. You have to ensure that your access points are secured to prevent unauthorized access.  There are several ways of securing your wireless access points.  Here is a Security Tip from the US CISA. Change default password. Restrict access. Encrypt the data on your network. Protect your Service Set Identifier (SSID). Install a Firewall. Maintain Anti-Virus software.I Use file sharing with caution. Keep your access point software patched and up to date. Check your internet provider’s router or router manufacturers wireless security options. Connect Using Virtual Private Network (VPN). A more detailed discussion of this tip can be found in this post:   US CISA: Security Tip (ST 005-003) Securing Wireless Networks End Notes  US CISA: Security Tip Disclaimer   This article is a result of my personal research and is not a substitute for legal advise.  Ple

Fortifying the Digital Frontier: Unmasking Network Security Risks and Solutions

Fortifying the Digital Frontier:  Unmasking Network Security Risks and Solutions It has been a while since my last post. I have been busy with work and learning Microsoft PowerBI and Power Automate. These are very good tools for dashboard creation and automation. Very easy to learn and use. Kudos to Microsoft for coming up with these great tools! Fast forward, I have recently enrolled in a Master of Information Systems (MIS) program via Distance Education. I am excited to be an online distance education student. It has been a    very long time since I was a student. I know there will be adjustments needed from me… to be diligent, to be disciplined in balancing my work-studies-life, and to persevere to achieve my goal of getting my Master’s Degree. I have decided to share my research in  MyInfoTech Journal  hoping these information will also be able to help those researching for similar topics. Today, I am researching on the  Network Layer  and its Security Implications . The informatio

Unlock the Secrets of the Top 10 Information Security Solutions and Safeguard Your Digital World!

{color: #000000; } My InfoTech Journal: Unlock the Secrets of the Top 10 Information Security Solutions and Safeguard Your Digital World!

The Ultimate Guide to Protecting Your Company's Secrets and Personal Information - Don't Get Hacked!

My InfoTech Journal: The Ultimate Guide to Protecting Your Company's Secrets and Personal Information - Don't Get Hacked!

Playbook for Conducting a Comprehensive IT Infrastructure Audit

Playbook for Conducting a Comprehensive IT Infrastructure Audit

Network Security: How to Secure Your Network

My InfoTech Journal: Network Security  To set the context of this domain, I have here several definitions from different service providers. Network Security  refers to the practices of protecting computer network from intruders, including both wired and wireless connections. - US CISA Network Security  is any activity designed to protect the usability and integrity of your network and data. It includes both hardware and software technologies. Effective network security manages access to the network. It targets a variety of threats and stops them from entering or spreading on your network. - Cisco Network Security  combines multiple layers of defenses at the edge and in the network. Each network security layer implements policies and controls. Authorized users gain access to network resources, but malicious actors are blocked from carrying out exploits and threats. - Cisco Network Security  are measures taken to protect a communications pathway from unauthorized access to, and accidenta

MyInfoTechJournal: Never Let a Crisis Go to Waste: The Ultimate Business Continuity Plan (BCP) for Thriving in Any Situation (Part 1 of 3: INTRODUCTION)

MyInfoTechJournal: Never Let a Crisis Go to Waste: The Ultimate Business Continuity Plan (BCP) for Thriving in Any Situation  (Part 1 of 3: INTRODUCTION)