What to do about inherent security flaws in critical infrastructure?
- Reference: 1656847031
- News link: https://www.theregister.co.uk/2022/07/03/inherent_security_flaws_ics/
- Source link:
But many of them are unfixable, due to insecure protocols and architectural designs. And this highlights a larger security problem with devices that control electric grids and keep clean water flowing through faucets, according to some industrial cybersecurity experts.
"Industrial control systems have these inherent vulnerabilities," Ron Fabela, CTO of OT cybersecurity firm SynSaber told The Register . "That's just the way they were designed. They don't have patches in the traditional sense like, oh, Windows has a vulnerability, apply this KB."
[1]
In research published last week, Forescout's Vedere Labs detailed [2]56 bugs in devices built by ten vendors and collectively named the security flaws OT:ICEFALL.
[3]
[4]
As the report authors acknowledged, many of these holes are a result of OT products' being built with no basic security controls. Indeed, Forescout's analysis comes ten years after Digital Bond's [5]Project Basecamp that also looked at OT devices and protocols and deemed them "insecure by design."
A few hours after Forescout published its research, CISA [6]issued its own security warnings related to the OT:ICEFALL vulnerabilities.
CVEs: The problem? Or the fix?
"Up until this point, CVEs haven't been generated for these insecure-by-design-things, and there's a reason for that," Fabela said. "It's bad for the industry."
Once a CVE is generated, it sets into motion a series of actions by industrial systems' operators, especially in heavily regulated industries like electric utilities and oil and gas pipelines.
[7]
First, they have to determine if the environment contains any affected products. But unlike enterprise IT, which usually has centralized visibility and control over IT assets, in OT environments, "everything is distributed," Fabela noted.
If industrial and manufacturing environments do have any products impacted by the vulnerability, that triggers an internal review and regulatory process that involves responding to CISA and developing a plan to improve security.
One SynSaber customer sarcastically described OT:ICEFALL as "the gift that keeps on giving," Fabela said. "He said, 'Now I have this on top of all my other like, the real vulnerabilities'," which present a slew of other problems when it comes to patching — such as having to wait until a planned maintenance outage that may be months out — if the manufacturer has a patch at all.
OT protocols don't use authentication
For example: The current [8]Modbus protocol , which is very commonly used in industrial environments, does not have authentication.
Forescout's analysis details nine vulnerabilities related to unauthenticated protocols and disputes the argument that against assigning a CVE ID to a product with an insecurity OT protocol.
[9]
"On the contrary, we believe a CVE is a community recognized marker that aids in vulnerability visibility and actionability by helping push vendors to fix issues and asset owners to assess risks and apply patches," the authors wrote.
While this makes sense from an IT security perspective, Fabela said it's unrealistic from an OT perspective, and ultimately doesn't make critical infrastructure any more secure.
Modbus, as a protocol that does not use authentication, could generate "thousands" of CVEs that "affect every product line in the world," he Fabela. "You're tying up the product security teams with the OEMs and you're tying up the customers, the asset owners with CVE that they can't do anything about."
Basecamp researcher weighs in
Reid Wightman is a senior vulnerability researcher with OT security shop Dragos' threat intel team. He's also one of the original Project Basecamp researchers, and, more recently has done work on the [10]ProConOs and MultiProg software vulnerabilities .
Forescout cited some of his research, and dedicated a section of the ICEFALL analysis to security flaws with the ProConOS runtime in PLCs.
In an email to The Register , Wightman noted that a lot of industrial controllers have the same set of problems that isn't going away: "they allow unauthenticated code to run on the PLC."
"This means that one malicious logic transfer to the PLC may permanently compromise the PLC," he added, noting that, because the control logic is causing the change, it can happen outside of a normal firmware update. "It's kind of a thing I've harped on since the Basecamp days, but may be worth repeating. Over and over again. Until the sun burns out, probably."
Lately, one of Wightman's "big, personal concerns" is that some vendors say they can use TLS and client certificates to secure controllers, presumably to avoid. In reality, this would just make the traffic more difficult to inspect, Wightman said.
[11]CISA and friends raise alarm on critical flaws in industrial equipment, infrastructure
[12]What if ransomware evolved to hit IoT in the enterprise?
[13]Threat group builds custom malware to attack industrial systems
[14]Five Eyes nations fear wave of Russian attacks against critical infrastructure
"If an attacker gets onto the engineering system, they may load a malicious payload using CVE-2022-31800/CVE-2022-31801 (or any of the similar problems that exist in almost every logic runtime) into the controller," he added. "Only, now we have no way of telling whether they did it because the traffic is encrypted."
So how do we fix the problem?
"I guess my answer would be: if your engineering system is compromised, throw away all of the controllers that it was allowed to talk to," Wightman said. "And I doubt most end users would go to that level of paranoia."
Which, again, points to the insecure-by-design nature of how these systems are engineered.
"Thankfully, we see no signs of any widespread abuse of these protocols or 'features' in spite of some of the bugs being well-known for years," Wightman added. "I really do hope it stays that way." ®
Get our [15]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YsG9HPZ1BpjKsmkkOHPLRgAAAAg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://www.theregister.com/2022/06/21/56_vulnerabilities_critical_industrial/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YsG9HPZ1BpjKsmkkOHPLRgAAAAg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YsG9HPZ1BpjKsmkkOHPLRgAAAAg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://github.com/digitalbond/Basecamp
[6] https://www.cisa.gov/uscert/ncas/current-activity/2022/06/22/cisa-releases-security-advisories-related-oticefall-insecure
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YsG9HPZ1BpjKsmkkOHPLRgAAAAg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://www.incibe-cert.es/en/blog/evolving-towards-secure-modbus
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YsG9HPZ1BpjKsmkkOHPLRgAAAAg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[10] https://www.cisa.gov/uscert/ics/advisories/ICSA-15-013-03
[11] https://www.theregister.com/2022/06/21/56_vulnerabilities_critical_industrial/
[12] https://www.theregister.com/2022/06/01/ransomware_iot_devices/
[13] https://www.theregister.com/2022/04/14/hackers-custom-malware-ics-scada/
[14] https://www.theregister.com/2022/04/21/five_eyes_russia/
[15] https://whitepapers.theregister.com/
1000 cuts
From what I have seen, corporations in manufacturing look to pay as little as possible to the engineers. They are like persona non grata, they can't complain and unions like to channel the anger of the floor workers at engineers - often telling them you make so little, because engineers take the most of the budget! And look they just sit there and do nothing! Of course, for a fat wad of cash under the table, they'll never say that actually corporation does that on purpose. It's better than workers behave like crabs in the bucket and not see what's really going on.
That being said, it often goes like that: "Steve, you did some programming right? Would you be able to fix this machine here? It seems to be discarding too many components that look just fine! The code is on that computer in the corner, unfortunately we lost documentation, but it's just Siemens S7, so my dog could do that but it's too fkin lazy. Just do it over the weekend and take Thursday and Friday off. Thanks mate!"
Many of these protocols run in air-gapped environments which limits the utility of many of these exploits to requiring somebody to be physically on-site in environments full of deadly hazards. If necessary, all of these protocols can be wrapped in infrastructure that secures them all the way down to at the wire level. Also keep in mind that simplicity can be a physical security / safety feature. If a connection between two devices suffers an authentication failure and that failure, say, causes an explosion at a chemical plant, was the addition of authentication to a system that could only be exploited at the wire level by cutting into conduits really a smart trade-off?
> Many of these protocols run in air-gapped environments
Or it was a case that when the systems were designed they were air gapped
Then someone hooks them up to a system which is networked and the air gap is bridged.
Money
And thats part of the problem. Arseholes above see an network admin sitting there all day "Doing nothing" so they then look to cut costs and IT is always the first to be poked. The amount of marketing emails we see come in that go to managers "You can save thousands with the cloudy" "cloudy cloud cloudy cloud, savings". They then fall for the bullshit, fork out money for a consultant who just wants to sell you shit or knows a mate who can sell you shit. They point at IT as they want rid so you can point out they are talking bollocks.
Eventually you're "made redundant" only to hear a few months later the new, cost effective system, had a massive breach and "Lessons have been learned".
Sick of it.
Re: Money
It is more insidious than that.
IT seems to be one of those areas where everyone who has a 'puter at home or a smartphone suddenly thinks they are an expert when IT disagrees or objects with what they want.
Couple that with a senior management who hold similar views and the outcome is deep, sticky, brown and very very smelly.
Oh - and THEN they call IT to come clean it up and wipe their backsides for them.
it's not all bad
In the mid 1990s I was sent to repair a cardboard box maker. The cough logic controller consisted of plug-in modules the size of a house brick with various switches and controls - pretty difficult to compromise I'd say.
Seriously, PLCs have always been a disaster waiting to happen.
Re: it's not all bad
Have they?
I'd trust a proper dedicted PLC from a manufacturer who has been in the business decades than any of these abortions built around Rasperry Pis or Arduinos etc and programmed by people who THINK they know what they are doing.
The problem comes when connectivity gets involved and security is sacrificed for "convenience" aka LAZY buggers who want to do everything via their effing phones. And when IT/security says no they "squeem and squeem, stamp their feet and throw their toys out the pram" until they get their way.
We're doomed
Its a choice for the manglement really
1. Air gap the critical systems from anything internet related (glueing up the USB ports too), then only applying updates from a secure scanned laptop
2. Leave everything as is , as its much more easy to download the production numbers from the line to your desktop PC than to dial the line supervisor and say "how many widgets made today"..... after opening the urgent e.mail from 'accounts' that has a PDF.exe file attatched.............
I know which choice our manglers would pick....