{"id":36779,"date":"2022-06-23T07:00:00","date_gmt":"2022-06-23T07:00:00","guid":{"rendered":"https:\/\/cloudnewshub.com\/archives\/36779"},"modified":"2022-06-23T07:00:00","modified_gmt":"2022-06-23T07:00:00","slug":"what-the-world-can-learn-from-saudi-arabias-fight-against-industrial-control-system-attacks","status":"publish","type":"post","link":"https:\/\/cloudnewshub.com\/?p=36779","title":{"rendered":"What the world can learn from Saudi Arabia\u2019s fight against industrial control system attacks"},"content":{"rendered":"<div><img decoding=\"async\" src=\"http:\/\/cloudnewshub.com\/wp-content\/uploads\/2022\/06\/what-the-world-can-learn-from-saudi-arabias-fight-against-industrial-control-system-attacks.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p><span data-contrast=\"auto\">The distinction between protecting information technology (IT) and protecting operational technology (OT) became very clear in 2010, when the Iranian nuclear enrichment facility <\/span><a href=\"https:\/\/en.wikipedia.org\/wiki\/Nuclear_facilities_in_Iran#Natanz\"><span data-contrast=\"none\">Natanz<\/span><\/a><span data-contrast=\"auto\"> was attacked by <\/span><a href=\"https:\/\/en.wikipedia.org\/wiki\/Stuxnet\"><span data-contrast=\"none\">Stuxnet<\/span><\/a><span data-contrast=\"auto\"> malware.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">OT includes programmable logic controllers (PLCs), intelligent electronic devices (IEDs), human-machine interfaces (HMIs) and remote terminal units (RTUs) that allow humans to operate and run an industrial facility using computer systems. These systems are connected to sensors and actuators within the site, which might be a power plant or a manufacturing facility. This collection of process control devices is often referred to as <\/span><a href=\"https:\/\/en.wikipedia.org\/wiki\/Industrial_control_system\"><span data-contrast=\"none\">industrial control systems<\/span><\/a><span data-contrast=\"auto\"> (ICSs).<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">Not only do these systems provide information to operators and engineers, but they also allow operators to act on what they see on screen. To change the speed of a turbine at a dam or a power plant, the operator modifies the required configuration on a workstation. In this way, when the operator sees warning signs indicating that a turbine is running too fast, he or she can slow the turbine down.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">A big difference between OT and IT is that operational technologies have traditionally been designed with safety and availability in mind, but with relatively little concern for cyber security. By contrast, for decades now, most information technologies have been designed with a specific goal of countering cyber security threats. The world is now catching on to the fact that OT also needs to be designed with cyber security in mind.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">Stuxnet was very sophisticated malware \u2013 the first of its calibre to attack an ICS. It famously infected engineering workstations at Natanz nuclear facility \u2013 workstations that were connected to PLCs that control nuclear centrifuges. Through this attack, threat actors were able to manipulate the speed (rotations per minute) of its rotor engines.&nbsp;<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">\u201cStuxnet was not decisively attributed to a specific threat actor, however, industry experts have suggested it would most likely have been the work of state-sponsored actors of Western governments with an interest in tripping up Iran\u2019s nuclear infrastructure,\u201d says <\/span><a href=\"http:\/\/linkedin.com\/in\/mohammad-al-kayed-63113710b\/?originalSubdomain=jo\"><span data-contrast=\"none\">Mohammad Al Kayed<\/span><\/a><span data-contrast=\"auto\">, director of cyber defence at <\/span><a href=\"https:\/\/www.blackmountain.ae\/\"><span data-contrast=\"none\">Black Mountain Cybersecurity<\/span><\/a><span data-contrast=\"auto\">.&nbsp;<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">Although neither country has admitted responsibility, the US and Israel are widely believed to have built the malware in a collaborative effort. Those two countries had the expertise to develop such a sophisticated worm, and they certainly had a motive to attack Iran\u2019s nuclear infrastructure.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">One of the challenges in getting to these controllers is that industrial facilities are often \u201c<\/span><a href=\"https:\/\/en.wikipedia.org\/wiki\/Air_gap_(networking)\"><span data-contrast=\"none\">air-gapped<\/span><\/a><span data-contrast=\"auto\">\u201d, which means there is no connectivity between the network inside the facility itself and the networks outside. Because it is not connected, there is no feasible way to attack the infrastructure directly. However, some of the world\u2019s savvier governments have found ways to overcome this countermeasure.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">Al Kayed says: \u201cStuxnet, at the time, was unique in the manner that it was designed to operate independently without the need for connectivity to a <a href=\"https:\/\/en.wikipedia.org\/wiki\/Botnet#Command_and_control\">command and control (C2) infrastructure<\/a>. It also specifically targeted Siemens Simatic S7-417 PLCs, a certain type of controller used in the nuclear facility that was attacked in Iran. Stuxnet does not affect any other systems. <\/span><\/p>\n<p><span data-contrast=\"auto\">\u201cHow the malware got onto controllers in the Iranian nuclear plant, we aren\u2019t sure. One plausible scenario could be that the malware was transferred to this facility by employees or contractors using USB devices or laptops. This could have been accomplished by first targeting somebody\u2019s laptop at home and infecting it with malware. Then, when that person takes their laptop back to work and connects it to the air-gapped network, they have basically bridged that gap and have given the malware a way into the industrial network, where it can start manipulating industrial controllers.\u201d<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\"> <br \/><\/span><\/p>\n<section class=\"section main-article-chapter\" data-menu-title=\"Iran learned from the attack\">\n<h3 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"><\/i>Iran learned from the attack&nbsp;<\/h3>\n<p><span data-contrast=\"auto\">Al Kayed adds: \u201cThe attack by Stuxnet opened the world\u2019s eyes to the fact that you can now develop cyber weapons that can destroy real-life targets. You can get into an entire infrastructure of a country and cut off electricity, for example. By the way, this is exactly what Russia did to Ukraine \u2013 twice.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\"> <br \/><\/span><\/p>\n<p><span data-contrast=\"auto\">\u201cIran learned from the attack that industrial control systems can actually be targeted using the right toolset. Also, it realised how effective those attacks can be. Some time between 2012 and 2018, we started seeing cyber attacks attributed to Iranian actors targeting other countries\u2019 industrial facilities in the region \u2013 including Saudi Arabia.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\"> <br \/><\/span><\/p>\n<p><span data-contrast=\"auto\">\u201cOne example was a malware called <\/span><a href=\"https:\/\/en.wikipedia.org\/wiki\/Shamoon\"><span data-contrast=\"none\">Shamoon<\/span><\/a><span data-contrast=\"auto\">. We have seen three different waves of that malware hit industrial facilities in Saudi Arabia. The first version hit Saudi Aramco, and a few other companies. Two other versions came out within a couple of years or so after that. All of them targeted the oil and gas industry and petrochemical companies within Saudi Arabia.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\"> <br \/><\/span><\/p>\n<p><span data-contrast=\"auto\">\u201cSaudi was a target for those kinds of attacks because it has a lot of manufacturing facilities and large-scale oil-producing operations. It is also a political superpower in the region, and an adversary of Iran.\u201d<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\"> <br \/><\/span><\/p>\n<\/section>\n<section class=\"section main-article-chapter\" data-menu-title=\"OT connected to IT is easier to attack\">\n<h3 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"><\/i>OT connected to IT is easier to attack&nbsp;<\/h3>\n<p><span data-contrast=\"auto\">It is even easier to attack industrial control systems when they are connected to an IT network. Threat actors can target OT infrastructure remotely by attacking the IT network first. All they have to do is send a phishing email to an unsuspecting employee or a consultant. If they can trick just one person to click that link in an email, they can compromise a device within the target organisation, which gives them access to the corporate infrastructure. From there, they can then traverse the network until they reach a device or server that has access to the OT infrastructure.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">Even if a threat actor gains access to only one computer, they can use numerous tactics and techniques to dump valid administrative credentials. If a computer is connected to a domain controller, for example, in an organisation where system admins log in remotely from time to time to help troubleshoot an issue or to install new software for users, administrative passwords are automatically cached on the computer by the operating system. If threat actors can collect those passwords, they can then log into other machines in the network with administrative privileges.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">\u201cJust imagine this scenario,\u201d says Al Kayed. \u201cAn employee comes in, gets something to eat, is bored to death and gets some email that says, click here. He or she clicks on that link and a malware is installed on their device. It\u2019s all over. That person\u2019s computer is now compromised \u2013 and it\u2019s connected to the IT network, where the opportunity arises for the threat actor to use certain techniques to target numerous systems. <\/span><\/p>\n<blockquote class=\"main-article-pullquote\">\n<p><figure> \u201cIf a power plant that generates electricity for a city stops working for an hour, that\u2019s a huge problem\u201d <\/figure><figcaption> <strong>Mohammad Al Kayed, Black Mountain Cybersecurity<\/strong> <\/figcaption><i class=\"icon\" data-icon=\"z\"><\/i> <\/p>\n<\/blockquote>\n<p><span data-contrast=\"auto\">\u201cIf, by any chance, some admin somewhere along the way logged in to troubleshoot that employee\u2019s device, then it is highly likely that those administrative credentials still persist. The credentials can be dumped by threat actors and used elsewhere in the corporate network.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\"> <br \/><\/span><\/p>\n<p><span data-contrast=\"auto\">\u201cNow with that administrative password, a threat actor can connect to other systems within the network. Now they start hopping from one device to another, until they find the device that they are interested in, such as a server that is connected to the industrial facility.\u201d<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\"> <br \/><\/span><\/p>\n<p><span data-contrast=\"auto\">Al Kayed adds: \u201cInside an industrial facility are engineering workstations and other computer systems that you can jump into. Now you have a way to remotely install that malware on those industrial control systems. You don\u2019t have to initially compromise any engineering workstation in the facility, but because that facility is connected to the corporate network, which, in turn, is connected to the internet, then there is a path that you can take. You can hop from one device to another until you reach the targeted\u202fengineering workstation within the petrochemical facility or within the power plant.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\"> <br \/><\/span><\/p>\n<p><span data-contrast=\"auto\">\u201cIf your favourite social media platform stops working for an hour, it\u2019s not such a big deal. But if a power plant that generates electricity for a city stops working for an hour, that\u2019s a huge problem. With the interconnectivity of those systems, and with those systems connected to your IT network, whoever targets the IT network can gain access also to OT infrastructure.\u201d<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\"> <br \/><\/span><\/p>\n<\/section>\n<section class=\"section main-article-chapter\" data-menu-title=\"Saudi government fights back\">\n<h3 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"><\/i>Saudi government fights back&nbsp;<\/h3>\n<p><span data-contrast=\"auto\">One of the lessons from this series of events is that cyber weapons are dangerous for everyone. The country that is targeted can learn the tools of the trade and potentially refurbish the weapon that was used against it and then target someone else. Saudi Arabia is the country in the region with the biggest bull\u2019s eye on its back because it has a lot of manufacturing facilities. So it isn\u2019t surprising that the Iranians took what they learned and used it to attack their biggest competitor in the region.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">But the Saudi government is taking action to prevent such attacks from happening again. It is introducing a set of laws, called the <\/span><a href=\"https:\/\/nca.gov.sa\/files\/ecc-en.pdf\"><span data-contrast=\"none\">Essential Cybersecurity Controls (ECC)<\/span><\/a><span data-contrast=\"auto\">, which are mandatory cyber security controls devised by the <\/span><a href=\"https:\/\/www.cybersecurityintelligence.com\/national-cyber-security-authority-nca-saudi-arabia-4633.html\"><span data-contrast=\"none\">National Cyber Security Authority (NCA)<\/span><\/a><span data-contrast=\"auto\"> to counter the kind of attack described above. Saudi Arabia is now one of the few countries in the region with a security initiative that focuses on more than just IT systems. It has included the risks on OT infrastructure as well.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">\u201cRegardless of the past setbacks, Saudi Arabia has proven itself to be a leading country in the region when it comes to cyber security,\u201d says Al Kayed. \u201cThe focused efforts during the past five years and the ability to make swift decisions with regard to Saudi\u2019s critical infrastructure cyber security has paid off. Saudi Arabia is now ranked second in the most recent <\/span><a href=\"https:\/\/www.itu.int\/epublications\/publication\/D-STR-GCI.01-2021-HTM-E\"><span data-contrast=\"none\"><em>Global cybersecurity index<\/em><\/span><\/a><span data-contrast=\"auto\">, setting an example for other countries in the region to follow.\u201d<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><\/p>\n<\/section>\n<section class=\"section main-article-chapter\" data-menu-title=\"World learns four big lessons on ICS security\">\n<h3 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"><\/i>World learns four big lessons on ICS security&nbsp;<\/h3>\n<p><span data-contrast=\"auto\">The whole world is now scrambling to protect industrial control systems. The US National Institute for Standards and Technology (NIST) published its <\/span><em><a href=\"http:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.800-82r2.pdf\">Guide to industrial control systems security<\/a><\/em><span data-contrast=\"auto\"> in 2015, a comprehensive set of guidelines on protecting industrial technology from cyber security threats.&nbsp;<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">But the attack on Iran and the subsequent attacks on Saudi Arabia teach four big lessons. The first is to segregate IT and OT networks. Too many organisations allow broader access to the OT network than is required.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">The second is to use an industrial anti-malware and intrusion detection and prevention system. HMIs and PLCs are the prime targets for attacks on OT networks. Many people mistakenly believe they can use IT anti-malware on engineering workstations to counter these attacks. But most IT anti-malware systems do not recognise OT malware, which attacks PLCs rather than computers.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">The third measure is to make use of specialised technology such as <\/span><a href=\"https:\/\/en.wikipedia.org\/wiki\/Unidirectional_network\"><span data-contrast=\"none\">data diodes<\/span><\/a><span data-contrast=\"auto\">, which do in a physical manner what a network firewall does in a logical manner. The design of the circuit within a data diode only allows communication to go in one direction. So, for example, you can read data from an RTU, but you can\u2019t instal anything on it.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><\/p>\n<p><span data-contrast=\"auto\">The fourth critical measure is monitoring. The practice of \u201csecurity monitoring\u201d is common in IT. Analysts monitor the infrastructure on a 24\/7 basis. However, not many OT facilities currently do that. They should.<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">&nbsp;<\/span><\/p>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>The distinction between protecting information technology (IT) and protecting operational technology (OT) became very clear in 2010, when the Iranian nuclear enrichment facility Natanz was attacked by Stuxnet malware.&nbsp; OT includes programmable logic controllers (PLCs), intelligent electronic devices (IEDs), human-machine interfaces (HMIs) and remote terminal units (RTUs) that allow humans to operate and run an [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":36780,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[533],"tags":[],"class_list":["post-36779","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-it"],"_links":{"self":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/36779","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=36779"}],"version-history":[{"count":0,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/36779\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/media\/36780"}],"wp:attachment":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=36779"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=36779"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=36779"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}