From: Dark Reading
Existing process of vulnerability reporting, patching doesn’t go far enough in improving the overall security of critical infrastructure systems, SCADA experts say
By Kelly Jackson Higgins
The U.S. Department of Homeland Security’s ICS-CERT has been regularly issuing vulnerability advisories for SCADA products over the past couple of years, vendors increasingly have been issuing patches, but the gaping and easily exploitable design flaws inherent in many products remain.
Some renowned SCADA security experts contend that the current process of reporting bugs, patching bugs, and issuing alerts via ICS-CERT falls short. The bigger ICS/SCADA systems that control power plants or chemical plants are not typically the subject of ICS vulnerability alerts, they say, and most vendors still aren’t fixing features in their products that were created prior to the networked environment, or that just don’t factor in security (think lack of authentication).
ICS-CERT has been lauded for helping raise awareness of security problems in the systems and software that run power plants, as well for as other services it provides to the ICS industry, including incident response and free tools. ICS-CERT responded to 177 cyberattack incidents reported by industrial control system operators last year, according to its newly published annual report (PDF).
Ralph Langner of Langner Communications, a security expert who was one of the first to discover Stuxnet, says the current ICS vulnerability advisory process only covers smaller flaws that can be patched, while the bigger security holes lie within the design features of the products. “The reality is that the most serious vulnerabilities in control systems are deliberate design features, not bugs,” Langner says. And ICS-CERT doesn’t handle insecure design features, he notes.
“ICS-CERT doesn’t deal with insecure design features and is even reluctant to call those vulnerabilities — quite a stretch because by any definition, a vulnerability is a system property that an attacker can exploit, no matter if it came into existence by oversight or by poor design,” Langner says.
The focus on bugs in micro-PLCs and human machine interface (HMI) software is missing the mark, he says. “Big DCS products that are used to control power plants or chemical plants, for example, don’t make it into ICS-CERT publications, no matter how easily they can be exploited,” Langner says.
Dale Peterson, CEO of SCADA security consultancy Digital Bond, says the advisories issued by ICS-CERT don’t do much to improve overall security of SCADA systems. “Most of the vulnerabilities [in the alerts] have little impact on the security of the systems,” says Peterson, who has been blogging recently on building a better ICS-CERT process.
He says that instead of vulnerability coordination, ICS-CERT should provide support to US-CERT in that regard. ICS-CERT should prioritize vulnerabilities based on how “the vulnerability affects a system on their critical infrastructure list AND the vulnerability affects the security posture of the system,” which would give ICS-CERT the breathing room to drill down on fewer but more relevant security flaws, Peterson wrote in a blog post earlier this week. “The second requirement is important and often leads to misallocation of ICS-CERT effort. Does it really matter if there is a CSRF or buffer overflow vulnerability in a device that you can connect to and take complete control using a feature?”
But other SCADA experts say ICS-CERT is getting a bad rap. Eric Byres, CTO and vice president of Tofino Security, a division of Belden, says it’s not ICS-CERT’s mandate to deal with the systemic problems in control systems. “It’s the elephant in the room. Yeah, these systems were never designed with security in mind, some were designed 20- to 30 years ago. Vendors are aware of the problem,” Byres says.
It will take major players like Exxon, Duke Energy, for instance, and other corporations with the ICS purchasing power, he says, to force vendors to step up and fix the systemic security issues. “It’s not ICS-CERT’s mandate to stand on the bandwagon and scream and yell and advocate. Its [mandate is] information dissemination, testing, and training,” he says.
Byres says ICS-CERT is making a difference in SCADA security — as a mechanism for researchers to disclose vulnerabilities responsibly, and its DHS-backed status gives it a higher level of visibility at the executive board level of SCADA vendors. “Schneider gets railed on, but the size of their security team was zero two years ago, and now it’s about 20,” he says. “[Vendors] are dumping tens of millions of dollars into this problem.”
Doug Powell, who works for Canada’s third largest utility, says ICS-CERT is doing exactly what it was created to do. “Is that adequate or enough to tell people a patch is required even if the patch is not relevant or if it’s not applicable? That’s not ICS-CERT’s problem,” says Powell, who requested his company’s name not be published. “It’s got to be some responsibility for the vendor or owner-operator to take that information handed to them and do something with it.”
That means risk analysis and evaluation, he says. “What could happen to me if I patch this miniscule [flaw] or if I don’t do it? Those discussions happen” in utilities, he says. “There’s always a risk calculation being done in the background [for patching].”
Leave a Reply