News: 1633669085

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Air gaps have been 'shattered’, says new Indian policy on power sector security

(2021/10/08)


India has announced a new security policy for its power sector and specified a grade of isolation it says exceeds that offered by air gaps.

“The much hyped air gap myth between information technology (IT) and operational technology (OT) systems now stands shattered," the [1]policy states, before going on to offer a slightly odd definition of an air gap.

"The artificial air gap created by deploying firewalls between any IT and OT system can be jumped by any insider or an outsider through social engineering."

[2]

India's answer is … something that sounds a lot like an actual air gap.

[3]

[4]

The first item in the new policy is "hard isolation of their OT systems from any internet facing IT system".

Power sector players – generators, transmission utilities and distributors – have a requirement of "only one of their IT systems with internet facing at any of their sites/locations, if required, which is isolated from all OT zones and kept in a separate room under the security and control of CISO,” referring to the chief information security officer.

[5]

The policy also requires any activity on the sole internet-connected system to be done "through an identifiable whitelisted device followed by scanning of both for any vulnerability/malware". Even that device can only connect to whitelisted IP addresses.

[6]Infosys and Wipro employees charged with insider trading

[7]China demands internet companies create governance system for algorithms

[8]Indian state cuts off internet for millions to stop cheating in exams

If the OT kit at a power player must communicate with the outside world, it should happen over optic fibre and preferably over POWERTEL – a carrier operated by government owned electricity transmission company Power Grid Corporation of India.

One item in the policy to watch is the requirement to use only products deemed to come from "trusted sources", as that list appears not to have been created before the policy directive was issued. What's the bet anything made in China isn't on the list?

The policy also requires all operators of power infrastructure to create an Information Security Division, appoint a CISO to lead it, and ensure compliance with security advisories issued by CERT-IN – including prompt application of patches.

Lifecycle management of all kit is also required, with replacements ordered for any out-of-support products. That new kit must be certified against the Common Criteria standards.

[9]

The policy applies to system integrators, equipment manufacturers, and even hardware and software OEMs that serve India's power supply system. As India has undergone rapid electrification in recent years, under a plan to bring electric power to the entire nation, such suppliers have had huge growth opportunities.

The new policy implies that some of the entities involved in operating the resulting network of generation and transmission infrastructure might not be in the best of shape. Hopefully the document's debut doesn't provide an incentive to attackers. ®

Get our [10]Tech Resources



[1] https://cea.nic.in/wp-content/uploads/notification/2021/10/Guidelines_on_Cyber_Security_in_Power_Sector_2021-2.pdf

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YWAW8MlgPMRVvYbkyeP18wAAAEY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YWAW8MlgPMRVvYbkyeP18wAAAEY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YWAW8MlgPMRVvYbkyeP18wAAAEY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YWAW8MlgPMRVvYbkyeP18wAAAEY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2021/10/05/infosys_wipro_insider_trading_charges/

[7] https://www.theregister.com/2021/09/30/china_to_regulate_algorithms/

[8] https://www.theregister.com/2021/09/27/rajasthan_internet_block_for_reet_exam/

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YWAW8MlgPMRVvYbkyeP18wAAAEY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[10] https://whitepapers.theregister.com/



Potemkine!

The artificial air gap created by deploying firewalls

Typical IT illiterates bragging

The policy also requires any activity on the sole internet-connected system to be done "through an identifiable whitelisted device followed by scanning of both for any vulnerability/malware". Even that device can only connect to whitelisted IP addresses.

If India is able to produce a device detecting 0-day vulnerabilities, congrats.

Simples!

adam 40

That device is very simple, it has a red light that comes on when there is a 0-day in a piece of kit.

The light is, of course, permanently on.

Pandora = Germany?

Anonymous Coward

Country that makes your firewalls = country that hacks stuff quite legally

You know these laws they pass that let them legally compel backdoors in any system, and legally hack any system, and then shortly after, they sign a cyber cooperation treaty so they can sell that as a service to their buddies worldwide. And then you go put their crap on your network? Knowing they can or already have backdoored it?? Do not do this.

It's not just 5 eyes countries, Australia and UK, its Germany too:

https://cpj.org/2021/06/german-law-government-surveillance-hacking-journalists/

("German law increases government surveillance and hacking powers, removes protection for journalists")

I was trying to figure out who was behind the Pandora papers, a country that hates the Czech President, hates Tony Blair, King of Jordan, has high taxes , is known for its hacking (Crypto AG + various Swiss hacks), was not featured heavily on the list, has a legalized hacking law and just had an election to make it more left wing.

Germany, fits that bill. I think they did it.

The motive would be to raise more tax in other nations, rather than lower it at home, and also take a big side swipe at the UK to ensure it stays "on message" regarding high taxation EU.

If it was a country, like Germany, then it represents a state backed cyber attack.

Re: Pandora = Germany?

Anonymous Coward

Loooool, tin foil hat much?

Yeah everything is back doored, or it isn't then its mirrored onto a dark fibre, no big deal the SNR is so high that unless your looking for something specific you won't see it, run wireshark/tcpdump on your desktop, then multiply that noise by every device on your lan, then multiply by every customer on your isp, then multiply by every isp and that's what nation state level network surveillance looks like...

Nope just bogstandard whistle blowing in my opinion, it's always someone about to get caught with hand cookie jar. Burn it all down then claim immunity

Re: Pandora = Germany?

Anonymous Coward

"Nope just bogstandard whistle blowing in my opinion"

Impossible. Coordinated leaks across 14 different companies? So 14 whistleblowers in 14 companies simultaneously and in coordination releasing their wares....

No way, it's a state attack. The question is which state.

I'm ruling out Russia because many of the leaders targetted are Putin friendlies. I ruled out China because the targets aren't their preferred enemies and includes Hong Kong. UK, the usual hacker? Nope, blantant attacks on UK leaders like Blair. Australia? Testing out their new legalized hacking laws? No, because they're in UK's surveillance group and UK was targetted. Israel? Attacking friendlies? No chance, too much risk of backfire.

Germany, ahhh.. yeh... I can see that.

It's not just the hack, its the propaganda op needed. Tony Blair buying a trust that owns a Marylebone office, instead of buying the office directly from the trust and incurring extra property taxes? I mean that's not a thing without the innuendo needed to pump it. Nobody pays more tax than needed. See IR35 contractors for details of that.

"Czech President buys 26 million euro property in Monocao via a trust", again, so what? He's a successful businessman worth billions and disclosed he owns hundreds of millions in property assets which must be somewhere! Without the innuendo of "didn't mention it [this specific property] on his political disclosure form".... to whom? The paparazzi? Monaco would certainly have him registered. When he goes to his holiday home, does he blindfold his security so they don't know where it is? It's ridiculous without the innuendo.

That's a state op.

Re: Pandora = Germany?

Anonymous Coward

More evidence popping up today pointing to Germany.

That global minimum corporation tax rate Ireland just signed up to was pushed by Germany and France:

https://www.reuters.com/world/china/germanys-scholz-greets-us-move-work-global-corporate-minimum-tax-rate-2021-04-06/

"I'm in high spirits that with this corporate taxation initiative, we'll manage to put an end to the worldwide race to the bottom in taxation," said German Finance Minister Olaf Scholz, a firm backer of the initiative."

German corporate tax is 30%, its the highest among the larger OECD countries. With only Columbia higher at 31%, and France only a little lower at 28.4%.

Total payroll tax among OECD countries... Germany is second only to Belgium. A clear incentive to try to force up taxes in other OECD countries.

Clear motivation there. Uncompetitive countries, drowing in taxes, trying to drag the other OECD members down with them.

Notice the low number of frenchies on the Pandora papers? Yet french property tax is between 7% and 10% of the purchase price... you'd think there would be a lot of French rich people simply wrapping property in trusts to be bought and sold freely, both in France and every other high property transfer country. Yet not in the Pandora papers.

what can go wrong?

ColinPa

The great wall of china was rendered useless when the baddies bribed a door keeper to let them in. I am expecting problems to occur because of human behaviour - "What harm will there be if I copy this amusing document around my work colleagues". I'll bring it in on a USB device.

Re: what can go wrong?

Pascal Monett

Humans always are the weakest link. If the Internet-facing computers can only access whitelisted web pages, and if they are, essentially, on a private web, then there likely won't be very many amusing documents to copy to the colleagues.

Of course, said amusing document can always be mailed from home.

Re: what can go wrong?

Anonymous Coward

Glue gun the USB sockets if you give a shit, can be non destrucivly removed, cheaper and more effective than socket locks, ohh and put the padlock through the loop on the chassis lid...

But yeah pay the grunts enough to make bribes less attractive and make the consequences severe

This though is just a political greasy pole doc, for someone wanting a promotion, complete unworkable chod, maybe Amber "hashtags" Rudd took a consultancy gig and offered her insight here...

Re: what can go wrong?

aregross

It sounds to me that something has already gone wrong, they've discovered it, and are trying to make sure it doesn't happen again.

Peter Galbavy

Sounds, based purely on the article, like yet more "cargo cult science" (based on Feynman's description) as IT security.

"something that sounds a lot like an actual air gap"

steelpillow

Couldn't have said it better myself. This shattering advance is exactly the precautions I found in use, and helped implement repeatedly, daily for may years in the 1990s and 2000s. Mind you, I never did power stations.

Oh, the fun when we would find a WiFi hub sneaked into the secure zone for sysadmin's convenience, on the grounds that it was an air gap! Obtaining and installing patches at max speed was the usual excuse, but gaming engines often proliferated on the more favoured workstations...

Bureaucrats pronounce

Mike 137

" "The artificial air gap created by deploying firewalls

As several others have rightly indicated - a firewall is not an air gap.

However quite a lot of research has found ways of breaching real air gaps (commonly via infiltration of inconspicuous kit) so there is a genuine problem. To quote Major General Jonathan Shaw (Late Head of Cyber Security, MoD) “...about 80 per cent of our cyber problems are caused by what I call poor cyber hygiene.” That's commonly the greatest weakness, both against cyber attack and other accidents, and is how such infiltration takes place.

All you need is a removable storage device that jumps the gap. A colleague once set up a secure comms unit in a war zone. The red and black systems were the statutory 1 metre apart, but on returning a month or so later he found a USB stick hung from the ceiling between them on a length of elastic.

Marriage Ceremony: An incredible metaphysical sham of watching God and the
law being dragged into the affairs of your family.
-- O. C. Ogilvie