Is Cybersecurity Smart Enough to Protect Building Automation?

4 min read
Curated from tripwire.com →

Imagine that you are in an elevator in a high rise building when suddenly the elevator starts to plummet with no apparent stopping mechanism other than the concrete foundation below.  While this may sound like something from a Hollywood movie, consider the idea that a securely tethered, fully functional elevator is as vulnerable as it is smart.

Wired.com explored the possibilities for hacking an electricity grid via an air conditioning unit several years ago. To summarize, an electric company offered customers a discount to place a governor on an air conditioner. This allowed the electric company to adjust the air conditioner to maintain control to prevent power dips and surges during extreme demand. In doing so, the electric company introduced an Industrial Control System (ICS) into every residence that accepted the offer. 

However, as the Wired.com article explains, these ICS devices were not secured against unauthorized access, leaving them vulnerable to widespread attacks that could cause the problems they were trying to prevent. An attacker could control multiple devices, causing them to create a power dip, or a surge, by doing the opposite of what the electric company commanded.

There are many reasons why the cybersecurity of industrial control systems presents unique challenges. Unclear or overlapping responsibilities, technical issues, lack of security awareness on the part of the ICS operators, and insufficient ICS knowledge on the part of security experts are just some examples. Yet, most of these systems are vital for the business continuity and commercial success of their organizations; they should therefore be seen as critical infrastructure.

The range is huge, from data centre air conditioning, fire alarm systems, elevators, and electronic locking systems to refrigerator controls and connected coffee machines. These systems are usually outside the control of the cybersecurity officer, who may not even know which systems are on the network. As a result, the potential risk of a cyberattack targeting the data centre air conditioning system is not even considered even though it is accessible for remote maintenance.

Digital transformation encompasses various and complex use cases including heating, ventilation, and air conditioning (HVAC), electricity management, lighting control, video surveillance, access control systems, and elevator controls. On top of that, there are connected sensors and devices such as cameras, thermostats, and light sensors. Each of these systems promises considerable savings in operating and energy costs but also increases the attack surface for cyber threats and adds to the complexity of security management. Every system and individual device, and even each version and revision of every system or device, has its own specific and often unique cyber risks.

Cyber criminals have already compromised an enterprise network via an HVAC system in the successful cyberattack on U.S. retail chain Target. From the HVAC system, they moved laterally through the network to the retailer’s financial systems, where they stole more than 40 million credit card records.

This summer, Ripple20 rocked the IoT world. This is the name given to 19 vulnerabilities found in a TCP/IP software library, some of which are critical. As all network traffic is processed by the TCP/IP stack, any bugs in a TCP/IP library can lead to major vulnerabilities. The Ripple20 discovery endangers a huge range of appliances, including power sockets and medical devices but also ICS sensors. It was discovered and named by researchers of the Israeli security firm JSOF, who also determined that attackers could use the vulnerabilities to infiltrate and execute their own code (Remote Code Execution) or to exfiltrate critical data. 

Another attack vector cyber criminals can use to disrupt and compromise normal operations are insecure industrial protocols.

Continue Reading

Enjoyed this summary? Read the complete article at the source:

Continue at tripwire.com →

Yves Mulkers

Yves Mulkers is the founder of 7wData and a widely followed voice in the data and AI community. He curates the 7wData and AI Beat newsletters, reaching hundreds of thousands of data and AI professionals, and writes on data strategy, analytics, AI, and the evolving data ecosystem.