Critical infrastructure devices operating in unprotected end-node environments are vulnerable to malicious actors who conduct hardware attacks such as reverse engineering and side-channel analysis. Boot data is rarely encrypted and typically travels across an accessible bus, enabling the data to be easily intercepted during system start-up. Encrypting the firmware would make reverse engineering extremely difficult for malicious actors and competitors. It would improve the effectiveness of tamper detection methods and deter zero-day vulnerability discovery. Increasing boot security could be a fundamental part of decreasing attack surfaces across the critical infrastructure sectors. This chapter describes a Talos II architecture implementation that encrypts a section of the boot image and decrypts it during initial program load. During power-on, the encrypted image travels across the Low Pin Count bus into a POWER9 module Level 3 cache and is decrypted in the processor. Boot image encryption is implemented using ciphers of different strengths. An analysis of their efficiency is conducted to determine the optimal algorithm.
The InfiniBand architecture is among the leading interconnects that support high performance computing. The high bandwidth and low latency provided by InfiniBand are increasing its applications outside the high performance computing domain. One of the important application domains is the critical infrastructure. However, InfiniBand is not immune to security risks. Previous research has shown that common traffic analysis tools cannot effectively monitor InfiniBand traffic transmitted between hosts. This is due to the kernel bypass nature of the InfiniBand architecture and remote direct memory access operations. However, if the Remote Direct Memory Access over Converged Ethernet (RoCE) protocol is employed, it is possible to restore traffic visibility in novel ways. This research demonstrates that the approach, coupled with an InfiniBand-capable adapter, enables common traffic analysis tools to be used to monitor InfiniBand network traffic without sacrificing bandwidth and performance.
Cyber-physical systems incorporate powerful devices that are used to monitor and control physical processes. These devices along with collectable statistics can be leveraged as sensors for network-based and host-based anomaly detection. Host-based anomaly detection can be used in a defense-in-depth strategy to complement traditional network-based anomaly detection systems as well in systems for which network-based options are infeasible due to their operating environments. This chapter discusses the development of an anomaly detection system for a SEL-3505 RTAC programmable logic controller using the recommended IEC 61131 programming tools. The required device statistics are harvested by creating a Modbus server on the test system and polling the server to retrieve data. The collected data is used to create a representative fingerprint for the associated task. When the measured behavior differs from the fingerprint, an anomaly is detected and an alarm is raised. This approach is flexible and easily implemented in existing installations. The performance of the anomaly detection system is evaluated against several network-based attacks across multiple firmware revisions and project types. Recommendations are made to improve anomaly detection performance.
It is crucial to secure the cyber-physical systems that automate the industrial processes essential to modern life. A hardware monitor utilizing the JTAG interface supported by most microprocessors could provide an immutable security monitor for industrial controllers. This paper explores the viability of using a commercial off-the-shelf debugger to dynamically extract memory and register data from industrial controllers to detect cyber attacks. We conducted five experiments using the Lauterbach PowerDe-bug Pro and the Schweitzer Engineering Laboratories RTAC-3505 real-time automation controller to determine access speed for register and memory information. The results show the fastest average downtime for register acquisition to be 8.178ms, with the fastest average downtime for processor pausing being 8.087ms. The fastest average time for reading 1KB of memory information was 24.798ms. The need to pause the microprocessor before data collection is the most significant performance-limiting factor. Based on these results, we conclude that commercial debuggers are not designed for high-speed data collection and are unsuitable for realtime cyber-attack detection. In the future, a custom tool may be designed to optimize data collection, reduce cost, and minimize the performance impact to the target device.
The OpenPOWER Foundation is an organization that promotes open-source high-performance hardware like the POWER9. OpenBMC is an OpenPower project that strives to produce an open-source firmware stack for Baseboard Management Controllers (BMCs). If hardware falls into the hands of competitors or bad actors, reverse engineering methods can be used to leak or manipulate sensitive information from the boot sequence. This represents a security concern because the root of trust can be invalidated. For example, since the Initial Program Load (IPL) data is frequently not encrypted and is sent over the Low Pin Count (LPC) bus, it is possible to intercept and conduct man-in-the-middle attacks to modify the boot process. The boot image flash chip could also be removed from the Talos II motherboard and examined by competing server architecture manufacturers to reveal detailed boot information. Firmware that developers deem to contain sensitive code or perform innovative operations needs to be protected before being flashed onto the boot image chip. This paper demonstrates a method to encrypt sections of the boot image by encrypting a section of the image before flashing it onto the Talos II. The encrypted image will be decrypted during the boot sequence in the Level 3 cache of the POWER9, proving that it is possible to prevent adversaries from interfering with the IPL flow or obtaining details on firmware from the flash chip. This paper presents a novel method to improve the security of the boot image on Talos II architecture by encrypting the boot firmware image and decrypting it during the boot process. The proof of concept was executed on a Raptor Engineering Talos II system running a POWER9 processor with OpenBMC firmware on the ASPEED AST2500 BMC. This research claims that this unique method increases boot time security through firmware without altering hardware.
CADA (Supervisory Control and Data Acquisition) networks have historically been in isolated locations and thought unassailable. In a post-Stuxnet world this assertion has been shown to not be true. Stuxnet exploited the Siemens Step7 programming software to perform a Control-logic injection attack, inserting malicious code into the programming traffic for end devices controlling centrifuges. This attack methodology poses serious risks to Industrial Control Systems (ICS). One forensic security tool, used for incident response and real-time monitoring, captures, and inspects network packets to identify potential malicious activity. As Programmable Logic Controller (PLC) manufacturers move from plain text protocols to more secure alternatives, care must be taken to protect the integrity and availability of the control commands in the network activity while still enabling the forensic process. In this work, we present an analysis of the programming protocol of the SEL-3505 Real Time Automation Controller and a process to extract the control logic program from the captured encrypted network traffic for forensic investigators. The results show that control traffic can be secure as it traverses the network but still successfully be used for a forensic investigation or continuous auditing purposes.
The InfiniBand network architecture, which delivers very high bandwidth and low latency, is one of the leading interconnects used in high performance computing. As its popularity increases, applications of InfiniBand in the critical infrastructure are growing, which creates the potential of new security risks. This chapter addresses some open security issues related to InfiniBand. It demonstrates that common traffic analyzing tools are unable to capture or monitor InfiniBand traffic transmitted between hosts. Due to the kernel bypass nature of InfiniBand, many host-based network security systems cannot be executed on InfiniBand applications and, unfortunately, those that can impose significant network performance penalties. The principal takeaways are that Ethernet security practices do not translate to InfiniBand networks and securing InfiniBand networks requires a hardware offload strategy.
Tire pressure monitoring systems have become a mandatory feature of modern automobiles, but their presence opens a new attack vector for a potential adversary.These systems have minimal security features, allowing for eavesdropping and data injection with low technical and financial costs. This chapter explores the potential for tire pressure monitoring systems to provide inputs to a remote sensing network, which leverages the data broadcast by the systems to identify vehicles and track their movements. A traffic simulation is employed to generate vehicle movements and tire pressure monitoring system packets. Experiments demonstrate that the tire pressure monitoring system data can help identify vehicles and reconstruct vehicle routes. They show that a determined adversary could deploy sensors to detect tire pressure monitoring systems and learn about the movements of individual vehicles without any insider information. Potential solutions to this privacy problem are discussed, focusing on low cost changes with the greatest consumer security benefits.
A controller area network bus is a communications system used in modern automobiles to connect the electronic control units that implement normal vehicular operations as well as advanced autonomous safety and driver comfort features. However, these advancements come at the expense of vehicle security – researchers have shown that automobiles can be hacked by compromising electronic control units or by connecting unauthorized devices to the controller area network bus. Physical layer device fingerprinting is a promising approach for implementing vehicle security. This chapter presents a fingerprinting method and classification algorithm for electronic control unit discrimination. Cross-lot discrimination is assessed using four Toyota Avalon electronic control units with different lot numbers as authorized devices, and a BeagleBoard, Arduino and CANable as rogue devices. The experiments yielded perfect rejection rates for rogue devices with false credentials and access denial rates exceeding 98
Industrial control systems employ a variety of hardware, software and network protocols to control physical processes that are critical to societal functions. It is vital that industrial control system operators receive quality training to defend against cyber attacks. Hands-on training exercises with real-world control systems enable operators to learn defensive techniques and understand the real-world impacts of their control decisions. However, cyber attacks and operator actions have unforeseen effects that can take a significant amount of time to manifest and potentially cause physical harm to systems, making high-fidelity training exercises costly and time-consuming. This chapter presents a methodology for accelerating training exercises by simulating and predicting the effects of cyber events in partially-simulated control systems. A hardware-in-the-loop simulation comprising a software-modeled water tank and a commercially-available programmable logic controller are used to demonstrate the feasibility of the methodology. The experimental results demonstrate that the effects of cyber events can be accurately simulated at speeds faster than real time, significantly enhancing operator training regimens.
The industrial control systems (ICSs) that control the critical infrastructure essential to the day-to-day functioning, well-being, and the defense of the United States pose as a lucrative cyber target for potential adversaries. Unfortunately, many of those who operate these vital systems lack the training required to prevent, identify, defend against, analyze, and recover from ICS cyber attacks. ICS operators need to have the same training standards as those in any other high-risk, high-stakes occupation due to increased risk and the resulting damage of cyber attacks against ICSs. An ideal training curriculum would include exposure to full-scale, real world systems with interconnected processes. Such training facilities support the intense, realistic, and hands-on training curricula required. There are currently not enough of these ideal facilities, and the cost of new facilities is prohibitive. Thus, there is a need for small, mobile, realistic, scalable, and low-cost ICS training environments. Specifically, there is a need for training environments that blend real ICS components and simulated systems. These environments expose ICS operators to a wide variety of ICS protocols and programming software, provide interaction with real world ICS hardware, and support many training scenarios of varying complexity. They address many critical skills at a fraction of the cost associated with the construction of full-scale, fixed training facilities. This paper presents a mobile training platform which uses real world ICS protocols, software, and hardware. The platform simulates several physical processes in order to provide a highly and easily configurable training environment. The platform also maximizes realism and allows students to witness the cyber-physical effects of their decisions. It fosters the development of the skills required for ICS operators to minimize the risk and contain the effects of a cyber attack.
Industrial control systems are designed to be resilient, capable of recovering from process faults and failures with limited impact on operations. Current industrial control system resilience strategies use redundant programmable logic controllers. However, these redundant programmable logic controllers, which typically are the same or similar makes and models as the primary controllers, can be exploited by the same cyber attacks that target the primary controllers.This paper proposes a resilience strategy for industrial control systems that employs an active defense technique to reduce, if not eliminate, the likelihood of a common cause failure induced by a cyber attack. The active defense implementation is compared with a traditional industrial control system resilience implementation using a semi-simulated wastewater treatment system that was exposed to cyber attacks. The results demonstrate that the active defense implementation is very effective in the aftermath of a cyber attack whereas the traditional resilience implementation gives rise to a system disruption.
Designers frequently select Software-Defined Radios (SDRs) as their platform to implement their Radio Frequency (RF) systems. SDRs combine the flexible nature of software along with reconfigurable RF hardware to offer designers an expanded toolbox in which to develop, evaluate, and deploy their systems in a rapidly evolving spectral landscape. As is often the case, having a flexible system introduces possible security flaws. These security flaws become relevant when SDRs are embedded into real systems. Software-defined radars have been developed by defense contractors and may be poised to become the standard in a wide array of applications related to autonomous land, water, and air vehicles. However, no current work explores the security of a software-defined radar architecture. In this work, we examine example cyber attacks on small scale software-defined radar. The radar is composed of GNU Radio, a Linux framework for interacting with SDR hardware, and the Universal Software Radio Peripheral (USRP) N210, a reconfigurable RF frontend developed by Ettus Research. First we describe the operation of system from the GNU Radio software down to the packet format. This system analysis reveals that the communication channel within the radar is vulnerable to cyber attack. Specifically, it is possible to conduct Man-In-the-Middle (MITM) attacks between GNU Radio and the USRP to alter the operation of the radar. The MITM attacks alter the hardware configuration and data used by the USRP, creating measurable effects in the distance estimates produced by the radar. We quantify these attacks by comparing the radar position estimates before and during an attack. The first MITM attack modifies hardware settings on the USRP. We observe up to a 76% error in the distance estimate by modifying the hardware configuration commands. We then create a targeted attack by modifying the RF data packets GNU Radio sends to the USRP. We show that intelligently altering the RF packet data introduces a targeted arbitrary distance offset into the radar range estimation with less than 10% error. We conclude with suggestions on how to secure a software-defined radar system assuming a similar structure to the test bed architecture.
First responders and professionals in hazardous occupations undergo intense training and evaluation to enable them to efficiently and effectively mitigate risk and damage. For example, helicopter pilots train with multiple simulations that increase in complexity before they fly real aircraft. However, in the industrial control systems domain, where incident response professionals help detect, respond and recover from cyber incidents, there is no official categorization of training environments, let alone training regimens. To address this gap, this chapter provides a categorization of industrial control training environments based on realism. Four levels of environments are proposed and mapped to Bloom’s Taxonomy. The categorization enables organizations to determine the cyber training environments that best align with their training needs and budgets.
Defending critical infrastructure assets is an important, but extremely difficult and expensive task. Historically, decoys have been used very effectively to distract attackers and, in some cases, convince attackers to reveal their attack strategies. Several researchers have proposed the use of honeypots to protect programmable logic controllers, specifically those used in the critical infrastructure. However, most of these honeypots are static systems that wait for would-be attackers. To be effective, honeypot decoys need to be as realistic as possible. This chapter introduces a proof-of-concept honeypot network traffic generator that mimics a genuine control system in operation. Experiments conducted using a Siemens APOGEE building automation system for single and dual subnet instantiations indicate that the proposed traffic generator supports honeypot integration, traffic matching and routing in a decoy building automation network.
When systems are targeted by cyber attacks, cyber first responders must be able to react effectively, especially when dealing with critical infrastructure assets. Training for cyber first responders is lacking and most exercise platforms are expensive, inaccessible and/or ineffective. This chapter describes a mobile training platform that incorporates a variety of programmable logic controllers in a single system that helps impart the unique skills required of industrial control system cyber first responders. The platform is modeled after a jail in the United States and was developed to maximize realism. Training scenarios are presented that cover specific cyber first responder skills and techniques. The results demonstrate that the platform is robust and highly effective for conducting sustained training exercises in curricula developed for cyber first responders.
The increased connectivity of medical devices expedites patient treatment and provides lifesaving capabilities, but the lack of emphasis on device security has led to several cyber security breaches. Most medical professionals do not have adequate expertise in information technology or cyber security, yet they are responsible for assessing which medical devices provide the best balance of risk and probability of success. This paper proposes a cyber risk scoring system that considers a physician’s worst-case assessment of the potential of a medical device to impact a patient. The scoring system also relies on a security questionnaire based on the STRIDE model that helps generate a risk score for the medical device. Three test scenarios involving medical devices are used to demonstrate the application and utility of the risk scoring system.
The critical infrastructure, which includes the electric power grid, railroads and water treatment facilities, is dependent on the proper operation of industrial control systems. However, malware such as Stuxnet has demonstrated the ability to alter industrial control system parameters to create physical effects. Of particular concern is malware that targets embedded devices that monitor and control system functionality, while masking the actions from plant operators and security analysts. Indeed, system security relies on guarantees that the assurance of these devices can be maintained throughout their lifetimes. This paper presents a novel approach that uses timing-based side channel analysis to establish a unique device fingerprint that helps detect unauthorized modifications of the device. The approach is applied to an Allen Bradley ControlLogix programmable logic controller where execution time measurements are collected and analyzed by a custom anomaly detection system to detect abnormal behavior. The anomaly detection system achieves true positive rates of 0.978–1.000 with false positive rates of 0.033–0.044. The test results demonstrate the feasibility of using timing-based side channel analysis to detect anomalous behavior in programmable logic controllers.
First responders go through rigorous training and evaluation to ensure that they are adequately prepared for emergencies. For example, fire departments continually evaluate the readiness of their firefighting personnel using a defined set of criteria that measures their performance in fire suppression and rescue procedures. However, in the cyber security domain, similar evaluation criteria and rigor are severely lacking for professionals who help detect, respond to and recover from cyber-based attacks against critical infrastructure assets. To address the gap, this paper provides a framework for evaluating the readiness of cyber first responders responsible for critical infrastructure protection. The evaluation criteria are conceptually based on the NFPA 1410 standards that are used to assess the readiness of firefighter first responders. The utility of the framework is illustrated using a military cyber training exercise that evaluated the readiness of professionals who respond to real-world cyber attack scenarios.
Critical infrastructure assets – and especially industrial control systems – are at risk. Malicious actors are constantly developing exploits that sneak past security controls. Honeypots offer an opportunity to acquire knowledge about the tactics, techniques and procedures used by malicious entities to compromise sensitive systems. However, the proprietary, and often expensive, hardware and software used by industrial control systems make it very challenging to build flexible, economical and scalable honeypots. This paper describes a technique that uses proxy technology to produce multiple high-interaction honeypots using a single programmable logic controller. The technique provides a cost-effective method for distributing multiple, authentic, targetable honeypots at slightly more than the cost of a single programmable logic controller.
Barry E. Mullins合作论文数Air Force Institute of Technology6