Control System Security Services

Project Experience

The following is a partial list of control system security projects conducted by the exida and Byres Research Team. Some names have been removed to protect the confidentiality of our clients.

Control System Cyber Security Strategy Consultant

Organization Name: Honeywell International Inc
Start / Finish Dates: June 2005
Description: Reviewed and advised Honeywell on its security strategy for Experion Control System Architectures

Control System Vulnerability Testing

Organization Name: Honeywell International Inc
Start / Finish Dates: January 2004 to December 2005
Description: This project involved conducting detailed cyber vulnerability tests and analysis against Experion and Safety System control devices used in process operations in the oil and gas and electric sectors.

Control System/Safety System Vulnerability Testing

Organization Name: Major International Petroleum Company
Start / Finish Dates: January 2004 to May 2006
Description: This project involved conducting detailed cyber vulnerability tests and analysis against six makes of key TCP/IP-based control devices used in process operations in the oil and gas.

Design of SCADA Security Simulation Models

Organization Name: National Defense University, US Dept of Defense
Start / Finish Dates: June 2007 – January 2008
Description:

In this project, physical simulation models are designed to allow the testing of possible cyber vulnerabilities and potential solutions for securing Modbus DNP-3 based Remote Terminal Units (RTUs) used in large military and commercial complexes.

Advanced mitigation solution developed included:

  • Firewalls capable of deep packet inspection of Modbus/TCP traffic for both compliance to specification and for specific function code and memory address ranges
  • VPN encryption tools with true drag and drop configuration capability

Developed Functional and Software Development Security Assurance Specifications

Organization Name: SA Security Compliance Institute
Start / Finish Dates: July to October 2009
Description:

Completed the development of the ISASecure Certification Program for Embedded Controllers focusing on the Functional Security dimensions of the certification.

Completed the development of an audit program for supplier software engineering practices which evaluates the extent to which suppliers include design-for-security in their software engineering practices.

Developed a certification report template and sample report

DNP3 SCADA Security Vulnerability Analysis

Organization Name: Cisco System Inc.
Start / Finish Dates: January 2005 to Present
Description:

DNP3 Security Vulnerability Analysis project was funded under Cisco’s Research Grants program to analyze this important SCADA protocol to determine the potential vulnerabilities.

  • Analysis of the DNP3 specifications to uncover possible risks inherent in the protocol.
  • Deconstruction of the protocol to allow the development of a vulnerability checker designed to test SCADA products deploying DNP3.
  • Based on the results of this analysis, recommendations were developed for improving the security of the protocol, the SCADA devices using it and the deployment of DNP3 SCADA systems.

Idaho National Labs (INL) CIP Site Testing

Organization Name: US Department of Homeland Security.
Start / Finish Dates: August 2007 to December 2007 (Pending)
Description: The team will work with Idaho National Labs (INL) to develop a security penetration strategy for testing the ExxonMobil Process Control and Equipment Monitoring Network (PCEM), carry out this strategy against two representative test systems (located at Yokagowa and Emerson laboratories) and then translate the results of these tests into a risk model using attack trees

Investigation of Firewall Effectiveness in SCADA Environments

Organization Name: National Infrastructure Security Coordination Centre, UK
Start / Finish Dates: April 2004 / January 2005
Description: This project assessed the effectiveness of deploying firewalls in SCADA and process control environments in critical infrastructures. Based on these results, a series of recommendations were developed as best practices for firewall installation in SCADA environments.
  • The first stage of the SCADA Firewall Effectiveness Investigation assessed the effectiveness of common IT firewalls deployed in SCADA and process control environments. The project commenced with a survey of end-users and vendors to determine current best practices for firewall deployment in these settings. The resulting configurations were then analyzed for effectiveness against typical CIP threats,
  • The second stage of the study included lab testing the effectiveness of current firewall technology in mitigating known SCADA vulnerabilities and identifying the limitations of these systems.
This document is now widely used as the primary reference document for firewall application in critical infrastructure protection by major international organizations including the UK- NISCC, the US Department of Homeland Security CSSP and Microsoft Corporation.

MODBUS Security Vulnerability Analysis

Organization Name: UK National Infrastructure Security Coordination Centre.
Start / Finish Dates: January 2005 to May 2006
Description: SCADA Security Vulnerability Analysis project was funded under Cisco’s Research Grants program to analyze this important SCADA protocol to determine the potential vulnerabilities.
  • Analysis of the MODBUS specifications to uncover possible risks inherent in the protocol using attack tree models
  • Deconstruction of the protocol to allow the development of a vulnerability checker designed to test SCADA products deploying MODBUS.
  • Detailed testing of representative SCADA products.
  • Based on the results of this analysis, recommendations were developed for improving the security of the protocol, the SCADA devices using it and the deployment of MODBUS SCADA systems.

NERC Cyber Security Assessment of Substation

Organization Name: Whatcom County PUD
Start / Finish Dates: February 2010
Description:
     
  • Conducted Cyber Vulnerability Risk Assessment (CVA) of the electric utility SCADA system and made computer network security recommendations regarding compliance of NERC CIP-002 through CIP-009 and other regulations and standards
  •  
  • Conducted workshop with District staff to present and collaborate on the following
    • Cyber Vulnerability Assessment (CVA) and compliance of NERC CIP-005 & CIP-007. 
    •  
    • Overview of NERC’s CIP standards 2 through 9 compliance
    •  
    • Applying standards such as ISA 99 and NERC CIP-002…009
    •  
    • Best practices in security policy, security education programs, layering of firewall defenses and the hardening of endpoint devices through patch management, antivirus deployment, and micro-firewalls within the control network, resulting in compliance

Network Robustness Testing of a DCS System

Organization Name: Major Automation Supplier
Start / Finish Dates: January 2010
Description: Performed Achilles Level 1 testing of the client’s redundant DCS controller and compact controller and issued a test report with recommendations.

Network Robustness Testing of a DCS/Safety System

Organization Name: Major Automation Supplier
Start / Finish Dates: November – December 2009
Description:
  • Performed Achilles Level 1 testing of clients integrated DCS and Safety System with and without external firewall
  • Issued test report with recommendations

OPC Good Security Practices Research

Organization Name: Kraft Foods Ltd.
Start / Finish Dates: October 2005 to May 2006
Description:

To create a report defining good security practices for the use of the OLE for Process Control (OPC) industrial communications standards in industrial settings. This includes the widely used Data Access (DA), Alarms and Events (A&E), and Historical Data Access (HDA) portions of the OPC standards.

  • The project methodology consisted of literature search and document reviews, an internationally conducted survey of end-users on OPC practices and lab testing of the DCOM/RPC protocol in a simulated industrial setting.
  • The final report provides detailed guidance on the secure use of this common protocol in critical industrial control environments.

Process Control System Security Audit

Organization Name: Major North American Petroleum Company
Start / Finish Dates: July 2004 to November 2004
Description:

This project developed and then deployed a non-intrusive audit methodology for determining the detailed status of all assets connected to process control networks in multiple company locations.

  • The audit project started with the development of a set of non-intrusive security audit instruments and procedures tailored to process control facilities in the petroleum industry (in particular Honeywell based systems).
  • Once these methodologies were completed, the project moved into the audit phase and four team members traveled to the client sites to conduct structured interviews with process control management and staff
  • Next the team conducted a detailed device audit, investigating all networked devices in the process areas at these sites.
  • On return from the sites, the audit team commenced the reduction and analysis of the collected device and interview data to produce a comprehensive risk analysis. 
  • An audit report was produce outlining the areas of both compliance and concern. In addition, a consolidated asset database was created for the company’s long term security management.

Process Control System Security Review

Organization Name: Major Petroleum Company
Start / Finish Dates: July 2006 to March 2008
Description:

Performed a cyber security review of process control systems and corporate practices at the company refineries. This was then used to develop a detailed plan for process control security program.

  • An initial review of process control architectures and policies using client supplied diagrams and documentation.
  • Onsite inspections of key facilities to view and assess actual security status of each control network.
  • A report reviewing the security policies and architectures used to protect Honeywell systems from cyber attack, providing recommendations for possible security improvements.

Quantitative Risk Analysis Methodology for Cyber Attacks

Organization Name: US Department of Homeland Security/ Idaho National Labs
Start / Finish Dates: March 2005/October 2005
Description:

Development of a framework and methodology which can be used to estimate the risk associated with cyber attacks on SCADA/Control Systems and the risk reduction when mitigating factors are employed. Primary emphasis is on the development of quantitative parameters and tools to support the risk analysis methodology. Includes the development of a defensible process to estimate the probability of deliberate attacks coming through specific nodes of an attack tree. The attack trees will be used to estimate the risk associated with an electronic attack (eA) and/or cyber attack (cyA) on a SCADA/Control System and correlated with actual reported events of attacks.

This includes:

  • Developing a typical deployment model for a SCADA/Control System.
  • Developing meaningful and orthogonal indicators for the capabilities needed to exploit a vulnerability (The ISID database of known system attack events is be a critical asset used to develop these indicators).
  • Identifying the threat agents interested in an eA/cyA of a SCADA/Control System.
  • Writing meaningful profiles for each threat agent and assigning appropriate levels to each indicator.
  • Testing the profiles and indicators by case study.
  • Developing meaningful functions for risk mitigation.

Security Analysis of the Process Control Access Domain Architecture

Organization Name: Shell Global Solutions
Start / Finish Dates: March 2007 – January 2008
Description: This project involved conducting detailed cyber vulnerability analysis and testing of the standard corporate architecture for remote access to process operations in the oil and gas exploration and production division.

Security Development Process Gap analysis

Organization Name: Major DCS and Safety System Manufacturer
Start / Finish Dates: August – October 2009
Description: Performed a Security Development Process Gap Analysis for major DCS and Safety System manufacturer based on comparison of their current safety and security development procedures to industry best practices such as ISO/IEC 15408, IEC 61508, RTC DO-178B, Microsoft Security Development Lifecycle and ISA 99.

Security Needs in the Energy Sector

Organization Name: Industry Canada
Start / Finish Dates: March 2006
Description: Industry Canada provided funding for the development of report and industry seminar on the “Security Needs for Critical Infrastructure in the Energy Industry”. The RCMP was a co-presenter in the event. The seminar was held at the BCIT Downtown Campus on March 28, 2006, with 65 participants attending from a mixture of energy and security companies throughout BC. The final report was delivered to Industry Canada on March 31.

Security Review of Serial Gateways in Industrial Control Systems

Organization Name: ExxonMobil
Start / Finish Dates: September 2008 to November 2008
Description:

This project focused on providing a security analysis of serial gateways used for the inter-connection of 3rd party systems into control systems in the Exxon refineries. The results of this analysis is then used to develop corporate policy for the use and configuration of these systems in Exxon refineries worldwide. This project includes the following stages:

  • Development of a threat modeling process for analyzing cyber risk serial to LAN gateways. This must be applicable in case of older legacy systems where detailed information may be limited.
  • A review of gateway architectures, policies and configuration requirements using client and vendor supplied diagrams and documentation for three specific serial gateway products.
  • Creation of a report providing an assessment of risk involved in the use of these gateways and recommendations for the appropriate deployment in control systems.

Security Testing and Certification of Safety System

Organization Name: Honeywell Process Management
Start / Finish Dates: November – December 2009
Description:
     
  • Performed Achilles Level 1 testing of the Honeywell Safety Manager in multiple configurations  
  •  
  • Issued Achilles Level 1 Certification and Certification Report

Toolkit for SCADA Protocol Testin

Organization Name: US Department of Defense
Start / Finish Dates: September 2004/November 2005
Description:

The project focused on the development of a security module generator and toolkit that will provide a rapid means for creating application layer test modules for specific SCADA protocols. Once created, the modules will operate on the Achilles Protocol Vulnerability Test Platform and will allow network security specialists and equipment manufacturers to test critical SCADA network components for both known and undiscovered security flaws at the application layer prior to deployment of the equipment.

  • This project extended the Achilles Protocol Vulnerability Test Platform by creating the methodology and a core toolkit to allow testers to inexpensively generate application layer security modules for specific SCADA protocols. Once generated by the toolkit, these modules can then be used for testing SCADA devices using fuzzy and two-cover traffic generation techniques.  As part of this project, modules will be developed for the MODBUS/TCP protocol, with other protocols developed at a later date.  Project phases include:
  • Development of module generation toolkit consisting of a structured protocol description language (PDL), a PDL interpreter and case file generator for creating application layer fuzzy, two-cover and corner-case test modules.
  • Using the toolkit described above to generate application layer software tools for the vulnerability testing of MODBUS/TCP devices.
  • Testing the complete SCADA Protocol Vulnerability Test Platform system against two representative MODBUS/TCP devices.
Copyright 2000 - 2012 . exida.com LLC | Site Map