Open standards security threat ignored: auditor

A senior technology auditor has raised concerns about his profession's awareness of the risks posed by critical infrastructure operators' shift from proprietary systems to open standards-based structures for the management of important tasks.

Certified information systems auditor (CISA) Barry Munns told ZDNet Australia the IT auditing profession had "largely ignored" moves by energy, gas and water utilities to adopt open standards for their telemetry and telecontrol infrastructure, often known as supervisory control and data acquisition (SCADA) systems and the dangers this created. These systems allow remote control or monitoring of infrastructure, such as substations or water pipes.

"There's a bit of a generational change that's happening," Munns said.

"Moving away from fairly closed system, proprietary type structures -- software and operating systems, to more open systems or public type systems. All the risks associated with things like hacking and denial of service, those risks are now very much coming to the fore in SCADA."

Munns has audited such systems for Energy Australia, and recently joined the Australian Nuclear Science and Technology Organisation (ANSTO).

"SCADA telemetry and telecontrol systems are moving towards that open arrangement and that inter-connected kind of model," he said.

"As an IT auditor, it's an area that's largely ignored and generally not known about.

"I think it's an area that doesn't have a great deal of profile in my profession."

While attackers would previously have had to have a high degree of specialised knowledge and sometimes physical access to the critical infrastructure operators' facilities to wreak havoc, now there task was a lot more simple, according to Munns.

"Whereas before you might have had a very much closed system, a proprietary SCADA system that you bought from a company and they gave you all the hardware and software ... and it was very unique to that arrangement.

"Nowadays, you might buy a SCADA system or develop a SCADA system but you might be using Linux as your operating system, you might be using TCP/IP as your communication protocol, you might be using generally available firewall software. So all of a sudden you're using stuff that is common. And because it's common, it's more exposed.

"So whereas before there might've only been a very small number of people who knew about this stuff ... we're actually moving to an area where you don't have to be an insider anymore. That's where the problem arises."

This greatly increased the number of potential attackers, Munns said.

"Often you needed physical access to these things to be able to get up to no good, well that level of security has been done away with as we move towards open standards."

Munns said more organisations needed to adopt IT governance frameworks in order to realise the risks.

"I'd strongly recommend the application of 7799 Information Security standard, in any organisation," he said.

The federal government last year published advice for chief executive officers on SCADA systems, and runs security forums such as the Trusted Information Sharing Network (TISN) to deal with the risks.

Munns declined to comment on Energy Australia's SCADA systems.

Advertisement

Talkback 3 comments

    Security through obscurity? Anonymous -- 30/05/06 (in reply to #120135206)

    I thought the idea of security through obscurity had been discarded.

    Avoid security through obscurity! Lawrence D'Oliveiro -- 30/05/06

    <P>What a stupid conclusion. I'm surprised that somebody whose job it is to worry about security would actually think that security-through-obscurity was actually something worth preserving.
    <P>He should look at the actual evidence from the adoption of open source and open standards in other fields: in most cases, the open products tend to suffer from <I>fewer</I> security vulnerabilities than their closed rivals.

    I think you miss the point Anonymous -- 23/04/08 (in reply to #120135224)

    I don't think the issue raised is whether organisations should continue to rely on 'security through obscurity'. Obviously they shouldn't, and that wasn't said.

    Rather, SCADA systems and technologies are trending away from very closed (often air gapped), proprietary, highly specialised and relatively unique architectures - towards open standards-based, corporate-networked and internet-worked systems. This poses new security risks to SCADA that were simply not significant in the past. Things change and security must keep up.

    The organisations operating these SCADA systems therefore really need to implement the sort of IT security that has generally been regarded as necessary by 'mainstream' IT for many years. Having said that, I understand most serious players are putting in a lot of effort to play 'catch up'.

    A worthwhile document on this is available for download from the US National Institute of Standards & Technology (NIST) "SP800-82 Guideline to Industrial Control System Security".

Add your opinion

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal Love me, tender
    Considering how expensive and drawn-out tender processes can be to solve problems that might be very immediate, it's little wonder that the Victorian Police IT department tried to work the tender exemptions system.
  • Array 2009 funding drought rolls on
    For Australian start-ups looking for venture capital, 2009 was a very bad year. 2010 may be no better.
  • Array Can not-so-smart meters help the NBN?
    It was interesting to witness Conroy's recent enthusiasm to spruik the NBN's role in supporting the Smart Grid, Smart City initiative. What a pity that Conroy hadn't yet seen the damning report from the Victorian auditor-general about that state's smart-meter roll-out.
  • More blogs »

Tags

Back to top

Featured