Showing posts with label 2008. Show all posts
Showing posts with label 2008. Show all posts

Tuesday, June 28, 2011

Design on SCADA Test-bed and Security Device

Abstract
Most of the national critical key infrastructure, such as power, piped gas and water supply facilities, or the high-speed railroad, is run on the SCADA (Supervisory Control and Data Acquisition) system. Recently, concerns have been raised about the possibility of these facilities being attacked by cyber terrorists, hacking, or viruses. Thus, it is time to adopt the relevant security management techniques.
This study analyzes the vulnerabilities of SCADA systems through scenarios, designs a test-bed to prove such vulnerabilities, and suggests security devices..
Keyword: SCADA Test-bed, SCADA Security Device, Modbus Serial Communication 

1. Introduction
The rapid development of information-communication technology in recent years has allowed large-scale facilities such as a railway, a power system, and a power plant to be operated by control systems. A control system is a computer-based system adopted by a number of infrastructure facilities and industries in order to monitor or control delicate processes as well as physical functions. The system collects data from the field and sensors, displays information, and executes sequential commands of local/remote devices. Such large- scale plant networks, based on the control systems, are mainly operated by the government and designated as key infrastructure facilities. What they have in common is that every device is connected with each other or with an external device to make possible remote access/control and equipped with the interactive communication environment for operating systems and giving commands. This environment in a broad sense is called SCADA (Supervisory Control and Data Acquisition), a kind of a control system including DCS (Distributed Control System) which is applied to plants executing distributed processes.
Most governments operate SCADA systems in closed networks and use a vendor’s own operation systems/protocols, which makes the systems safe from cyber-attacks. However, when the need for maximum efficiency or external service arises, attempts will be made to connect the systems to the Internet or commercial networks. This allows the public to share all the information operated by the government but the system could be vulnerable to fatal damage [1] inflicted by hackers.
The previous operation of key infrastructure facilities was safe from hackers because of local control, exclusive lines, real-time operation systems, private protocols, terminal PLC, and so on. Yet, more efficient management may need to introduce centralized remote control, TCP/IP network-based protocols, and PCs with common operation systems, which increases security problems [2]. Table 1 shows the comparison of control and information networks.
The SCADA systems have been operated for infrastructure based on closed networks. However, if aging systems are replaced by new internet worked units, it may cause serious vulnerabilities to threats of hackers.
Recent cyber threats tend to increasingly focus on SCADA systems, and once the system is attacked, the damage affects a multitude of people and national reputation is severely impaired. As hacking skills become more intelligent, preventive security measures shall be highlighted even more. For example, Gartner’s report [3] released in January 2004 pointed out serious vulnerabilities of major infrastructure facilities such as railway, power system networks, a power plant and a dam. That is, development of IP technology increases security threats to SCADA systems, making them a major target of cyber attacks since 2005. Originally, SCADA systems are operated in closed networks, safe from hackers who attempt remote access, but business rationalization calls for use of the Internet and common controllers using TCP/IP, exposed to fatal damage that hacking tools may incur [4].
Thus, this study is aimed to analyze the vulnerabilities of SCADA systems through virtual scenarios, design a test-bed to verify such vulnerabilities, and suggest security devices.

Sungmo Jung, Jae-gu Song, Seoksoo Kim
Department of multimedia, Hannam University, Korea SungmoJ@Gmail.com, bhas9@paran.com, sskim@hnu.kr




Improving Security for SCADA Control Systems

Executive Summary
The continuous growth of cyber security threats and attacks including the increasing sophistica- tion of malware is impacting the security of critical infrastructure, industrial control systems, and
Supervisory Control and Data Acquisition (SCADA) control systems. The reliable operation of modern infrastructures depends on computerized systems and SCADA systems. Since the emer- gence of Internet and World Wide Web technologies, these systems were integrated with business systems and became more exposed to cyber threats. There is a growing concern about the security and safety of the SCADA control systems. The Presidential Decision Directive 63 document es- tablished the framework to protect the critical infrastructure and the Presidential document of 2003, the National Strategy to Secure Cyberspace stated that securing SCADA systems is a na- tional priority.The critical infrastructure includes telecommunication, transportation, energy, banking, finance, water supply, emergency services, government services, agriculture, and other fundamental systems and services that are critical to the security, economic prosperity, and social well-being of the public. The critical infrastructure is characterized by interdependencies (physi- cal, cyber, geographic, and logical) and complexity (collections of interacting components). Therefore, information security management principles and processes need to be applied to SCADA systems without exception. Critical infrastructure disruptions can directly and indirectly affect other infrastructures, impact large geographic regions, and send ripples throughout the na- tional and global economy. For example, under normal operating conditions, the electric power infrastructure requires fuels (natural gas and petroleum), transportation, water, banking and fi- nance, telecommunication, and SCADA systems for monitoring and control.
In this paper, we provide an analysis of key developments, architecture, potential vulnerabilities, and security concerns including recommendations toward improving security for SCADA control systems. We discuss the most important issues concerningthe security of SCADA systems in- cluding a perspective on enhancing security ofthese systems. We briefly describe the SCADA architecture, and identify the attributes that increase the complexity of these systems including the key developments that mark the evolution of the SCADA control systems along with the growth of potential vulnerabilities and security concerns. Then, we provide recommendations toward an enhanced security for SCADA control systems. More efforts should be planned on reducing the vulnerabilities and improving the security operations of these systems. It is necessary to address
not only the individual vulnerabilities, but thebreadthofrisksthatcaninterfere with critical operations.
We describe key requirements and fea- tures needed to improve the security of the current SCADA control systems. For example, in assessing the risk for SCADA systems, use of general meth- ods for risk analysis including specific conditions and characteristics of a control system needto be applied. Effective risk analysis for SCADA systems requires a unified definition for mishap and identification of potential harm to safety. As computer systems are more integrated, the distinction between security and safety is beginning to disappear. In bridging the gap between these domains, we propose a unified risk framework which combines a new definition of mishap with an expanded definition of hazard to include the security event.
However, methods for risk management that are based on automated tools and intelligent tech- niques are more beneficial to SCADA systems because they require minimum or no human inter- vention in controlling the processes. We also identify a unified security/safety risk framework for control systems. Implementing security features ensures higher security, reliability, and availabil- ity of control systems. Thus organizations need to reassess the SCADA control systems and risk model to achieve in depth defense solutions for these systems. The increasing threats against SCADA control systems indicate that there should be more directions in the development of these systems.Therefore, achieving better quality and more secure SCADA control systems is a high priority.
Information security management principles and processes needto be applied to SCADA systems without exception. We conclude with a thought about the future of SCADA control systems. A strategy to deal with cyber attacks against the nation’s critical infrastructure requires first under- standingthe full natureofthethreat. A depth defense andproactive solutionstoimprovethe se- curity of SCADA control systems ensures the future of control systems and survivability of criti- cal infrastructure.

Keywords: industrial control system, SCADA control system, cyber security, critical infrastruc- ture, requirements, risk management, security framework.

Introduction
Supervisory Control and Data Acquisition (SCADA) systems, Distributed Control Systems (DCS), and other smaller control system configurations including skid-mounted Programmable Logic Controllers (PLC) are often found in the industrial sectors and critical infrastructures. These are also known under a general term, Industrial Control System (ICS). A control system is a device or set of devices to manage, command, direct, or regulate the behavior of other devices or systems. ICSs are typically used in industries such as electrical, water, oil and gas, and chemical including experimental and research facilities such as nuclear fusion laboratories. The reliable operation of modern infrastructures depends on computerized systems and SCADA sys- tems.
The Presidential Decision Directive 63 document established the framework to protect the critical infrastructure and the Presidential document of 2003, the National Strategy to Secure Cyberspace statedthat securing SCADA systems is a national priority.
The critical infrastructure includes telecommunication,transportation, energy, banking, finance, water supply, emergency services, government services, agriculture, and other fundamental sys-
tems and services that are critical to the security, economic prosperity, and social well-being of the public. The critical infrastructure is characterized by interdependencies (physical, cyber, geo- graphic, and logical) and complexity (collections of interacting components). Cyber interdepend- encies are a result of the pervasive computerization and automation of infrastructures (Rinaldi, Peerenboom, & Kelly, 2001). The critical infrastructure disruptions can directly and indirectly affect other infrastructures, impact large geographic regions, and send ripples throughout the na- tional and global economy. For example, under normal operating conditions, the electric power infrastructure requires fuels (natural gas and petroleum), transportation, water, banking and fi- nance, telecommunication, and SCADA systems for monitoring and control.
74There is a growing concern about the security and safety of the SCADA control systems in terms of vulnerabilities, lack of protection, and awareness (Byres & Franz, 2005; Byres, Hoffman & Kube, 2006).Therefore, information security management principles and processes need to be appliedto SCADA systems without exception.
This paper provides a relevant analysis of most important issues and a perspective on enhancing security of these systems. The rest of this paper is organized in sections as follows: next section provides an overview ofthe SCADA architecture. Then, in the following section, we describe key developments that mark the evolution of the SCADA control systems along with the increase of potential vulnerabilities and security concerns. In the next section, we provide recommenda- tions toward an enhanced security for SCADA control systems. We describe key requirements and features needed to improve the security of the current SCADA control systems. We conclude with a thought about the future of SCADA control systems.

Mariana Hentea Excelsior College, Albany, NY, USA
mhentea@excelsior.edu

Thursday, June 23, 2011

Improving Security for SCADA Control Systems

Executive Summary

The continuous growth of cyber security threats and attacks including the increasing sophistication of malware is impacting the security of critical infrastructure, industrial control systems, and Supervisory Control and Data Acquisition (SCADA) control systems. The reliable operation of modern infrastructures depends on computerized systems and SCADA systems. Since the emergence of Internet and World Wide Web technologies, these systems were integrated with business systems and became more exposed to cyber threats. There is a growing concern about the security and safety of the SCADA control systems. The Presidential Decision Directive 63 document established the framework to protect the critical infrastructure and the Presidential document of 2003, the National Strategy to Secure Cyberspace stated that securing SCADA systems is a national priority. The critical infrastructure includes telecommunication, transportation, energy, banking, finance, water supply, emergency services, government services, agriculture, and other fundamental systems and services that are critical to the security, economic prosperity, and social well-being of the public. The critical infrastructure is characterized by interdependencies (physical, cyber, geographic, and logical) and complexity (collections of interacting components).
Therefore, information security management principles and processes need to be applied to SCADA systems without exception. Critical infrastructure disruptions can directly and indirectly affect other infrastructures, impact large geographic regions, and send ripples throughout the national and global economy. For example, under normal operating conditions, the electric power infrastructure requires fuels (natural gas and petroleum), transportation, water, banking and finance, telecommunication, and SCADA systems for monitoring and control.
In this paper, we provide an analysis of key developments, architecture, potential vulnerabilities, and security concerns including recommendations toward improving security for SCADA control systems. We discuss the most important issues concerning the security of SCADA systems including a perspective on enhancing security of these systems. We briefly describe the SCADA architecture, and identify the attributes that increase the complexity of these systems including the key developments that mark the evolution of the SCADA control systems along with the growth of potential vulnerabilities and security concerns. Then, we provide recommendations toward an enhanced security for SCADA control systems. More efforts should be planned on reducing the vulnerabilities and improving the security operations of these systems. It is necessary to address not only the individual vulnerabilities, but the breadth of risks that can interfere with critical operations.
We describe key requirements and features needed to improve the security of the current SCADA control systems. For example, in assessing the risk for SCADA systems, use of general methods for risk analysis including specific conditions and characteristics of a control system need to be applied. Effective risk analysis for SCADA systems requires a unified definition for mishap and identification of potential harm to safety. As computer systems are more integrated, the distinction between security and safety is beginning to disappear. In bridging the gap between these domains, we propose a unified risk framework which combines a new definition of mishap with an expanded definition of hazard to include the security event.
However, methods for risk management that are based on automated tools and intelligent techniques are more beneficial to SCADA systems because they require minimum or no human intervention in controlling the processes. We also identify a unified security/safety risk framework for control systems. Implementing security features ensures higher security, reliability, and availability of control systems. Thus organizations need to reassess the SCADA control systems and risk model to achieve in depth defense solutions for these systems. The increasing threats against SCADA control systems indicate that there should be more directions in the development of these systems. Therefore, achieving better quality and more secure SCADA control systems is a high priority.
Information security management principles and processes need to be applied to SCADA systems without exception. We conclude with a thought about the future of SCADA control systems. A strategy to deal with cyber attacks against the nation’s critical infrastructure requires first understanding the full nature of the threat. A depth defense and proactive solutions to improve the security of SCADA control systems ensures the future of control systems and survivability of critical infrastructure.

Keywords: industrial control system, SCADA control system, cyber security, critical infrastructure,
requirements, risk management, security framework.



Material published as part of this publication, either on-line or
in print, is copyrighted by the Informing Science Institute.
Permission to make digital or paper copy of part or all of these
works for personal or classroom use is granted without fee
provided that the copies are not made or distributed for profit
or commercial advantage AND that copies 1) bear this notice
in full and 2) give the full citation on the first page. It is permissible
to abstract these works so long as credit is given. To
copy in all other cases or to republish or to post on a server or
to redistribute to lists requires specific permission and payment
of a fee. Contact Publisher@InformingScience.org to request
redistribution permission.

Mariana Hentea
Excelsior College, Albany, NY, USA
mhentea@excelsior.edu

Advanced digital VCR for compressed videos

Abstract:



With the establishment of MPEG video coding standards, many video sequences for modern streaming applications are encoded in MPEG formats. However, the MPEG standards employ motion-compensated prediction in which the compressed data is not invariant to changes in frame order. This hinders users from browsing video in a more interactive way. To enrich the user's viewing experience, it is desirable to perform various video cassette recording (VCR) functionality such as backward, fast-forward/backward, random access, etc. in digital video. Therefore, in this thesis, some novel techniques are suggested for the efficient implementation of VCR functionality in a digital video streaming system with minimum requirements on the decoder complexity and the network traffic. Backward playback is one of the most common VCR functions. One popular approach is to use a reverse transcoder in the server which converts I-P frames into another I-P bitstream in reverse frame order. When a playback device decodes this reverse-encoded bitstream, backward playback can be achieved. To expedite the transcoding process, we propose a fast reverse motion estimation algorithm with smart mode decision for H.264 reverse transcoding. By analyzing the motion vectors and modes decoded from the forward bitstream, the best mode and motion vector for each reverse transcoded macroblock are estimated. A remarkable reduction of computational complexity involved in reverse motion estimation can be achieved by the proposed algorithm with only negligible impact on the rate-distortion performance.

Afterwards, we propose a compressed-domain approach for an efficient implementation of the MPEG video streaming system to provide backward playback over a network. In the proposed video streaming server, according to the motion information, macroblocks in the requested frame are classified into two categories - backward macroblocks (BMBs) and forward macroblock (FMBs). Two novel macroblock-based techniques are used to manipulate the necessary macroblocks in the compressed domain and the server then sends the processed macroblocks to the client machine. For BMBs, we propose a sign inversion technique, which is operated in the variable length coding (VLC) domain, to reduce the number of macroblocks to be decoded by the decoder and the number of bits to be sent over the network in the backward-play operation. By identifying the related macroblocks of FMBs in their reference frame, a direct addition technique for discrete cosine transform (DCT) coefficients is designed to further reduce the computational complexity of the decoder. We also contrive a mixed VLC and DCT domain technique for the FMBs to offer better performance of the proposed system. With these compressed-domain techniques, the proposed architecture manipulates macroblocks in the VLC and DCT domain only to achieve a server with low complexity. Experimental results show that, as compared to the conventional system, the new streaming system reduces the required network bandwidth and the decoder complexity significantly. Although the new scheme exhibits promising results for backward playback, it encounters a problem when backward playback traverses the group-of-pictures (GOP) boundary since the proposed sign inversion technique makes use of the motion relationship between two adjacent frames. But, no inter-frame prediction takes place between the last frame of one GOP and the first frame of the successive GOP. In this thesis, we also provide a novel solution to cope with the GOP discontinuity problem of the video bitstream by re-building the motion linkages across GOP boundaries. By employing the compressed-domain techniques, the work in this thesis shows significant improvements in terms of the server complexity, the network traffic, and the quality of reconstructed video during backward playback. Undoubtedly, the results of our work will certainly be useful for the future development of digital VCR.


Authors: Fu, Chang-hong
Subjects: Hong Kong Polytechnic University -- Dissertations
Digital video
MPEG (Video coding standard)
Videocassette recorders
Issue Date: 2008
Publisher: The Hong Kong Polytechnic University