The Department of Homeland Security's ICS-CERT released three security advisories this week on Industrial Computer Control Systems (ICS), re-emphasizing the serious security threats facing infrastructure and industrial networks today.
In a recent blog post summarizing the current threat landscape for ICS, Fortinet's Ruchna Nigam highlighted: "Most industrial control systems come from various vendors and run proprietary operating systems, applications, and protocols (including General Electric, Kwell, DNP3, and Modbus). As a result, host-based security solutions developed for IT departments are almost completely unsuitable for ICS.”
This undoubtedly makes the security of ICS even weaker, and it is the sole responsibility of the vendor to find and fix security holes. All discovered vulnerabilities cited in the three bulletins were independently identified and reported by the vendor - however, it is difficult to verify that their fixes actually resolved the issue.
Ivan Sanchez, who recently discovered the Rockwell IAB security breach, was quite shocked. In his day job, he is constantly searching for and discovering new ICS security vulnerabilities. Just last year, he released a report that identified more than 150 risk issues with Rockwell products alone. Generally speaking, after reporting related issues, relevant companies will make further consultation with him.
"In 95 percent of the cases, the business will ask me to re-test before making a final announcement," Sanchez said in an interview. "I think companies should be asking about specifics about security vulnerabilities, rather than just saying 'thank you' for what's currently being discovered."
Bulletin ICSA-16-056-01 describes a memory access violation error in Rockwell Automation's Integrated Architecture Builder (IAB) application. Once successfully exploited, it would allow an attacker to execute malicious code with the same privileges as an IAB tool. It can only be exploited by local users and has been fixed. However, before installing the latest version, it is still recommended that users avoid using IAB.exe to open any untrusted project files; in addition, all software should be run as a 'user' role, not an 'administrator' role.
Bulletin ICSA-16-061-03 describes a cookie-based security vulnerability that allows a remote attacker to configure EatonLightingSystems through EG2WebControl. Eaton has fixed the vulnerability, but it still takes time to roll it out to all systems.
Bulletin ICSA-16-096-01 describes four security vulnerabilities in Pro-face's GP-ProEXHMI software: one leads to information leakage, two are buffer overflows, and the other is a hard-coded credential issue. All four bugs have now been fixed.
There is a strong set of evidence that the current ICS security issues are far more dire than the statements in the Fortinet blog post.
In fact, Ivan Sanchez said in an interview, "The ICS industry must improve its own code quality and introduce security and audit controls. I've published 30% of the problems that have been found, and the industry has not had enough time to fix them all — —So I have to say, it's a big trouble."
Although the objectivity of the problem has become a consensus, it is still largely a potential problem for now.
Patrick Coyle, author of Chemical Facility Safety News, explained, "On the one hand, there are a lot of security holes in almost every control system that we need to carefully assess and prevent any intrusions that target them. On the one hand, these ICS control systems are simply too complex, and organizing an effective attack plan requires a wealth of ICS-related expertise.”
IPC He expects that attack activities will continue to increase in the future, but this increase is mainly reflected in the level of quality rather than quantity. "I think we're going to see more inefficient attacks directed at ICS. As with the hydraulic system intrusion reported by Verizon, the attacker simply changed the setpoint at will, but it was quickly discovered, and the security system or alarm The operator solved the problem easily.” In fact, it is the malicious activities that have been planned for a long time.
However, he cautioned, "My biggest concern is that some malicious actors may use ransomware to lock down critical infrastructure. It doesn't require any deep expertise, as long as they can break into the system.

