<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Youssef El Maimouni on Senthorus Blog</title><link>https://blog.senthorus.ch/author/youssef-el-maimouni/</link><description>Recent content in Youssef El Maimouni on Senthorus Blog</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Fri, 12 Apr 2024 00:00:00 +0000</lastBuildDate><atom:link href="https://blog.senthorus.ch/author/youssef-el-maimouni/index.xml" rel="self" type="application/rss+xml"/><item><title>European energy sector targeted by cyberattacks</title><link>https://blog.senthorus.ch/posts/european_energy_sector_targeted_by_cyberattacks/</link><pubDate>Fri, 12 Apr 2024 00:00:00 +0000</pubDate><guid>https://blog.senthorus.ch/posts/european_energy_sector_targeted_by_cyberattacks/</guid><description>&lt;img src="https://blog.senthorus.ch/european_energy_sector_targeted_by_cyberattacks/european_energy_sector_targeted_by_cyberattacks_0.png" alt="Featured image of post European energy sector targeted by cyberattacks" />&lt;h2 id="introduction">Introduction
&lt;/h2>&lt;p>Energy infrastructures represent a critical concern for all cities and are increasingly the target of sophisticated attacks aimed at destabilizing certain countries. Particularly within the context of escalating geopolitical tensions. Attacks targeting electrical energy providers can trigger chain reactions leading to devastating consequences, particularly affecting safety and even causing natural disasters beyond their immediate impact on electricity availability.&lt;/p>
&lt;p>These attacks are utilized as a veritable arsenal of war when motivated by geopolitical tensions. This was evident in 2022 in Ukraine when the attack on the electrical infrastructure was coupled with a physical military assault. Or more recently, between May 11th and 30th, 2023, a large-scale attack took place against Danish electrical actors, targeting up to 22 companies in the same campaign.&lt;/p>
&lt;p>In this article, we will review these two attacks to draw concluding lessons regarding the tactics and techniques employed, along with recommendations to best monitor and protect critical infrastructures.&lt;/p>
&lt;h2 id="ukraine-2022--sandworm-apt-manages-to-cut-off-electricity-in-multiple-ukrainian-regions">Ukraine 2022 – Sandworm APT manages to cut off electricity in multiple Ukrainian regions
&lt;/h2>&lt;p>This is not the first time Ukraine has been targeted by the APT Sandworm. We recall the year 2015 when they used the specific malware BlackEnergy3, followed by Industroyer/Crashoverride in 2016, successfully cutting off electricity for several hours, forcing operations to switch to manual mode to restore power.&lt;/p>
&lt;p>On October 10, 2023, the APT Sandworm repeated its attack, this time with an even more stealthy approach and a more significant impact, using a new type of attack. The exact point of entry into the target infrastructure or the initial access date is not known precisely. However, it is known that the attackers were able to pivot to Supervisory control and data acquisition (SCADA) instances by exploiting the host hypervisor using an outdated version of the MicroSCADA software.&lt;/p>
&lt;p>Sandworm used then a set of Living Off the Land Binaries (LOTL) scripts to directly impact the control of electricity stations by disconnecting them. LOTL refer to cyber criminals’ techniques leveraging non-malicious binaries, generally built-in operating system, to hide their malicious activities via legit processes.&lt;/p>
&lt;p>The last phase of the attack involved the usage of a new version of CaddyWiper to erase attack traces on the IT side.&lt;/p>
&lt;h3 id="tactics">Tactics
&lt;/h3>&lt;p>The Mandiant incident response team estimates an intrusion around June 2022 (&lt;a class="link" href="https://www.mandiant.com/resources/blog/sandworm-disrupts-power-ukraine-operational-technology" target="_blank" rel="noopener"
>source&lt;/a>), during which the attacker deployed a webshell Neo-REGEOARG on an internet-facing server, ensuring persistent access to the station&amp;rsquo;s web servers. In July, this persistence was reinforced by deploying GOGETTER, an open-source tool acting as a tunnel to the attackers for their command-and-control servers over TLS.&lt;/p>
&lt;p>Using SystemD, the adversaries managed to establish persistence for Gogetter&amp;rsquo;s execution after machine reboots, all while disguising this service to appear legitimate.&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/european_energy_sector_targeted_by_cyberattacks/european_energy_sector_targeted_by_cyberattacks_1.png"
loading="lazy"
alt="Incident targeted attack lifecycle"
>&lt;/p>
&lt;p>&lt;em>Figure 1 Incident targeted attack lifecycle - Source: Mandiant&lt;/em>&lt;/p>
&lt;p>By exploiting a vulnerability in this end-of-life version of the SCADA control system, they managed to insert an ISO containing three scripts (lun.vbs, n.bat, s1.txt). However, no obvious malicious payload was included in these files because they succeeded in translating their goal directly into the SCIL language, which is the scripting language for the MicroSCADA control system. These commands were then transmitted to the Remote Terminal Units (RTUs) of the substations, likely to open the circuit breakers and achieve the attack&amp;rsquo;s objective.&lt;/p>
&lt;p>By using the LOTL scripts, the attackers were able to remain discreet. To complete the operation, on October 12th, they deployed a new version of CaddyWipper via Group Policy Objects (GPO) and a scheduled task to clean up the traces left behind.&lt;/p>
&lt;h2 id="denmark-2023---multiple-attacks-against-energy-sector-companies">Denmark 2023 - Multiple attacks against energy sector companies
&lt;/h2>&lt;p>On May 11th, 2023, the Danish energy sector was heavily impacted by a series of targeted attacks, affecting no fewer than 22 companies involved in the energy domain. The group of attackers exploited a vulnerability (CVE-2023-28771) in Zyxel firewalls, officially known since April 25th, 2023. Zyxel is widely used in Denmark and is found in many critical OT infrastructures designed to protect against threats. Ironically, the attack vector was precisely the device meant to ensure the protection.&lt;/p>
&lt;p>The attackers managed to leverage the resources of compromised entities in brute force and DDoS campaigns against other companies before the defense teams managed to isolate compromised infrastructures from the Internet.&lt;/p>
&lt;h3 id="tactics-1">Tactics
&lt;/h3>&lt;h4 id="first-wave">First wave
&lt;/h4>&lt;p>The vulnerability CVE-2023-28771 was exploited by sending a single crafted packet to port 500/UDP of the vulnerable firewall&amp;rsquo;s VPN service. The attacking group conducted a deep reconnaissance, as all sent packets successfully reached their target without one miss. This indicates that they precisely knew which firewalls were vulnerable, even though this information was not available publicly on Shodan. As a result, the attacker could execute commands with root privileges directly on the device without authentication.&lt;/p>
&lt;p>Once the attackers gained initial access, they proceed to the extraction of the vulnerable firewall configuration and user accounts information.&lt;/p>
&lt;h4 id="second-wave">Second wave
&lt;/h4>&lt;p>On May 22nd, 2023, a second wave of attacks was observed, where compromised companies were seen downloading new software through insecure connections. Additionally, encrypted command and control traffic was detected, utilizing either a recently created domain or known malicious IPs associated with a variant of the Mirai botnet called Moobot. This time, it appeared that the attackers exploited zero-day vulnerabilities, which were disclosed by the Zyxel vendor two days after the beginning of the second wave attack.&lt;/p>
&lt;p>Following the command-and-control activities, there was a coordinated DDoS attack on the United States and Hong Kong, as well as a SSH brute force attempt against a Canadian company, occurring just before the defensive containment measures.&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/european_energy_sector_targeted_by_cyberattacks/european_energy_sector_targeted_by_cyberattacks_2.jpg"
loading="lazy"
alt="Cyberkill chain of the attack"
>&lt;/p>
&lt;p>&lt;em>Figure 2 Cyberkill chain of the attack - Source: Sektocert.dk&lt;/em>&lt;/p>
&lt;h2 id="recommendation">Recommendation
&lt;/h2>&lt;p>It is recommended to implement strict network segmentation between OT and IT zones, as well as critical zones within the OT network. Additionally, when aware of vulnerable assets and the unability to patch them, it is essential to segment them to minimize the attack surface while allowing production to continue. This is particularly crucial for End-of-Life products, as demonstrated by the success of the Sandworm attack.&lt;/p>
&lt;p>Concerning operational industrial scripts and commands, collaborating with production teams is crucial to identify functions and commands for defining a configuration baseline. This helps to detect stealth techniques, such as LOTL. Effective collaboration within the industrial/production team would further enhance the ability to spot malicious activities, improving defense capabilities.&lt;/p>
&lt;p>Log collection from EDR and centrally managed Antivirus systems to improve detection capabilities. Integration with a SIEM and enrich with Threat Intelligence feeds to detect attacks based on tactics and known IOCs associated with known botnets or APTs.&lt;/p>
&lt;p>In addition to effective network segmentation, it is recommended to monitor potential threats to vulnerable systems using specific detection rules at the SOC level.&lt;/p>
&lt;p>Monitor the OT network, paying particular attention to flows from IT to OT and OT to/from the internet. Establishing a 24/7 detection capabilities for swift response, utilizing passive monitoring solutions coupled with machine learning to detect any changes in your environment or abnormal connections.&lt;/p>
&lt;h2 id="references">References
&lt;/h2>&lt;ul>
&lt;li>&lt;a class="link" href="https://www.mandiant.com/resources/blog/sandworm-disrupts-power-ukraine-operational-technology" target="_blank" rel="noopener"
>Sandworm disrupts power in Ukraine&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://sektorcert.dk/wp-content/uploads/2023/11/SektorCERT-The-attack-against-Danish-critical-infrastructure-TLP-CLEAR.pdf" target="_blank" rel="noopener"
>The attack against Danish critical infrastructure&lt;/a>&lt;/li>
&lt;/ul></description></item><item><title>Key controls for ICS environment</title><link>https://blog.senthorus.ch/posts/key_controls_for_ics_environment/</link><pubDate>Sun, 17 Sep 2023 00:00:00 +0000</pubDate><guid>https://blog.senthorus.ch/posts/key_controls_for_ics_environment/</guid><description>&lt;img src="https://blog.senthorus.ch/key_controls_for_ics_environment/Key_controls_for_ICS_environment.png" alt="Featured image of post Key controls for ICS environment" />&lt;h1 id="industrial-environment-security">Industrial Environment Security
&lt;/h1>&lt;h2 id="challenges-in-ot-network-security">Challenges in OT Network Security
&lt;/h2>&lt;p>Industrial environments networks are often considered less secure than traditional IT environments. This is partly because OT systems were designed to operate autonomously with a focus on performance and real-time with less attention on security. Additionally, the equipment and communication protocols used in OT environments are often outdated and vulnerable to attacks.&lt;/p>
&lt;h3 id="key-challenges">Key Challenges
&lt;/h3>&lt;ul>
&lt;li>&lt;strong>Difficulty of updating equipment&lt;/strong>: Many industrial equipment are difficult to update due to their critical nature or very long lifecycle.&lt;/li>
&lt;li>&lt;strong>Complexity of systems&lt;/strong>: Industrial systems are often complex and interconnected, making them difficult to manage and secure.&lt;/li>
&lt;li>&lt;strong>Internal threats&lt;/strong>: Employees, subcontractors, or partners may access industrial systems and cause intentional or unintentional damage.&lt;/li>
&lt;/ul>
&lt;p>To enhance the security of industrial environments, it is important to have a &lt;strong>secure-by-design&lt;/strong> approach, develop best practices for &lt;strong>patching and coding&lt;/strong>, and have the &lt;strong>capability to monitor and respond&lt;/strong> when an incident occurs.&lt;/p>
&lt;h2 id="security-by-design">Security by Design
&lt;/h2>&lt;h3 id="the-purdue-model">The Purdue Model
&lt;/h3>&lt;p>The Purdue model was defined to establish best practices in terms of data separation between the OT and IT networks. It is based on a hierarchical architecture, dividing the information system into &lt;strong>six different levels&lt;/strong>, each with its own security concerns and requirements.&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/key_controls_for_ics_environment/Key_controls_for_ICS_environment1.png"
loading="lazy"
alt="The Purdue Model"
>&lt;/p>
&lt;p>The Purdue model proposes a &lt;strong>security architecture&lt;/strong> based on network segmentation into different security zones, including &lt;strong>DMZ buffer zones&lt;/strong>, particularly between levels 3 and 4, where the &lt;strong>industrial DMZ (level 3.5)&lt;/strong> is located.&lt;/p>
&lt;p>Although debated in terms of modern relevance, especially with the rise of IoT, it remains a recognized standard and provides a &lt;strong>solid foundation&lt;/strong> adaptable to industry-specific needs.&lt;/p>
&lt;h2 id="segmentation">Segmentation
&lt;/h2>&lt;p>OT network segmentation is a vital security practice. It reduces the &lt;strong>risk of attack propagation&lt;/strong> throughout the network.&lt;/p>
&lt;p>Key principles:&lt;/p>
&lt;ul>
&lt;li>ICS protocols must remain confined to the &lt;strong>control network&lt;/strong> (not above level 3).&lt;/li>
&lt;li>Lower layers, including the control level, must &lt;strong>never have direct internet access&lt;/strong>.&lt;/li>
&lt;/ul>
&lt;h2 id="hardening-and-patching">Hardening and Patching
&lt;/h2>&lt;p>Hardening and patching are critical but challenging due to:&lt;/p>
&lt;ul>
&lt;li>Use of &lt;strong>outdated and unsupported&lt;/strong> operating systems.&lt;/li>
&lt;li>Need to reduce attack surfaces via &lt;strong>effective segmentation&lt;/strong>.&lt;/li>
&lt;/ul>
&lt;p>It&amp;rsquo;s also important to follow good &lt;strong>coding practices&lt;/strong>, even for &lt;strong>PLC programmers&lt;/strong>. A guide of the 20 best practices for coding PLCs, based on the OWASP Top 10 format, has been developed to ensure secure programming. The list of recommendations in detail can be found &lt;a class="link" href="https://sansorg.egnyte.com/dl/HHa9fCekmc" target="_blank" rel="noopener"
>here&lt;/a>.&lt;/p>
&lt;h2 id="identification-and-monitoring">Identification and Monitoring
&lt;/h2>&lt;h3 id="asset-identification">Asset Identification
&lt;/h3>&lt;p>Understanding all assets is crucial. This includes:&lt;/p>
&lt;ul>
&lt;li>Identifying &lt;strong>&amp;ldquo;crown jewels&amp;rdquo;&lt;/strong> (critical assets).&lt;/li>
&lt;li>Inventorying physical equipment, data flows, and networks.&lt;/li>
&lt;/ul>
&lt;h3 id="baseline">Baseline
&lt;/h3>&lt;p>Defining a baseline enables anomaly detection:&lt;/p>
&lt;ul>
&lt;li>Data flows and configurations should be baselined.&lt;/li>
&lt;li>Example: A baseline could have prevented the &lt;strong>Stuxnet&lt;/strong> attack.&lt;/li>
&lt;/ul>
&lt;h3 id="monitoring">Monitoring
&lt;/h3>&lt;p>Effective monitoring requires:&lt;/p>
&lt;ul>
&lt;li>Passive rather than active scans (to avoid disrupting sensitive equipment).&lt;/li>
&lt;li>Tools like Nozomi, Claroty, Microsoft Defender for IoT.&lt;/li>
&lt;/ul>
&lt;p>Key areas of focus:&lt;/p>
&lt;ul>
&lt;li>Remote connections (RDP, VPN, TeamViewer&amp;hellip;)&lt;/li>
&lt;li>Border elements between IT and OT (e.g., data historian)&lt;/li>
&lt;li>Collecting logs and sending to a &lt;strong>SIEM&lt;/strong> for early detection&lt;/li>
&lt;/ul>
&lt;h2 id="incident-response">Incident Response
&lt;/h2>&lt;p>A dedicated, &lt;strong>trained incident response team&lt;/strong> is essential. They should:&lt;/p>
&lt;ul>
&lt;li>Understand ICS processes&lt;/li>
&lt;li>Maintain regular contact with operational staff&lt;/li>
&lt;li>Be ready to minimize operational impact and downtime during incidents&lt;/li>
&lt;/ul>
&lt;h2 id="ics-cyber-kill-chain">ICS Cyber Kill Chain
&lt;/h2>&lt;p>The &lt;strong>ICS Cyber Kill Chain&lt;/strong> is a model from SANS Institute to understand and counter ICS-targeted attacks. It consists of two phases:&lt;/p>
&lt;p>&lt;img src="https://blog.senthorus.ch/key_controls_for_ics_environment/Key_controls_for_ICS_environment2.png"
loading="lazy"
alt="ICS Cyber Kill Chain"
>&lt;/p>
&lt;h3 id="phase-1-intrusion--learning">Phase 1: Intrusion &amp;amp; Learning
&lt;/h3>&lt;ol>
&lt;li>&lt;strong>Reconnaissance&lt;/strong>: Identifying vulnerabilities and entry points&lt;/li>
&lt;li>&lt;strong>Delivery&lt;/strong>: Deploying malware (e.g., phishing)&lt;/li>
&lt;li>&lt;strong>Exploitation&lt;/strong>: Using vulnerabilities to penetrate the system&lt;/li>
&lt;li>&lt;strong>Installation&lt;/strong>: Installing malware to gain remote control&lt;/li>
&lt;/ol>
&lt;h3 id="phase-2-attack">Phase 2: Attack
&lt;/h3>&lt;ol>
&lt;li>&lt;strong>Privilege Escalation&lt;/strong>: Gaining elevated privileges&lt;/li>
&lt;li>&lt;strong>Propagation&lt;/strong>: Spreading across other ICS systems&lt;/li>
&lt;li>&lt;strong>Malicious Act&lt;/strong>: Disruptions, parameter changes, or ransomware&lt;/li>
&lt;/ol>
&lt;h3 id="examples">Examples
&lt;/h3>&lt;ul>
&lt;li>&lt;strong>Stuxnet&lt;/strong>: Passed through all Purdue levels to reach nuclear centrifuges at level 0.&lt;/li>
&lt;li>&lt;strong>Havex&lt;/strong>: A RAT used in espionage campaigns; introduced via phishing and watering hole attacks.&lt;/li>
&lt;/ul>
&lt;h2 id="ics-security-resources">ICS Security Resources
&lt;/h2>&lt;ul>
&lt;li>&lt;a class="link" href="https://sansorg.egnyte.com/dl/HHa9fCekmc" target="_blank" rel="noopener"
>SANS ICS Cyber Kill Chain Model&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://attack.mitre.org/techniques/ics/" target="_blank" rel="noopener"
>MITRE ATT&amp;amp;CK for ICS&lt;/a>&lt;/li>
&lt;li>&lt;a class="link" href="https://www.cisa.gov/news-events/cybersecurity-advisories" target="_blank" rel="noopener"
>CISA ICS Advisories&lt;/a>&lt;/li>
&lt;/ul></description></item><item><title>ICS/OT Components overview</title><link>https://blog.senthorus.ch/posts/ics_ot_components_overview/</link><pubDate>Sun, 10 Sep 2023 00:00:00 +0000</pubDate><guid>https://blog.senthorus.ch/posts/ics_ot_components_overview/</guid><description>&lt;img src="https://blog.senthorus.ch/ICS_OT_Components_overview.png" alt="Featured image of post ICS/OT Components overview" />&lt;h2 id="ics-components-overview">ICS components overview
&lt;/h2>&lt;p>Today, many industrial sites are directly connected to the internet or the company&amp;rsquo;s information systems (IS). Although this can facilitate and automate operations, these connections can also be targeted by malicious intrusions if they are not sufficiently protected. It is therefore important to clarify the concepts related to industrial system security and provide some keys to prevent them.&lt;/p>
&lt;p>First, we must clarify the confusion between the different acronyms frequently used in industrial security OT, ICS, SCADA&amp;hellip;&lt;/p>
&lt;p>&lt;strong>OT&lt;/strong>, or operational technology, includes all the hardware and software technologies used to maintain the functioning and interact with the components and production infrastructure. Industrial control systems (ICS), building management systems (BMS), heating, ventilation, and air conditioning (HVAC) systems, as well as lighting, access, and security in buildings, are all part of OT systems.&lt;/p>
&lt;h3 id="industrial-control-systems">Industrial Control Systems
&lt;/h3>&lt;p>&lt;strong>ICS&lt;/strong>, or industrial control systems, refer to the software or hardware solutions used for control and supervision operations in the OT environment of industrial production processes. Supervisory Control and Data Acquisition (&lt;strong>SCADA&lt;/strong>) systems are one of the most common ICS solutions, and are offered by various players such as ABB, Rockwell Automation, Schneider Electric, and Siemens. These systems collect information from different production units and sensors to allow operators to remotely visualize or modify real-time production operations.&lt;/p>
&lt;p>In the industrial world, &lt;strong>Safety and Reliability&lt;/strong> must be the watchwords, even before the traditional principles of &lt;strong>confidentiality, integrity, and availability (CIA)&lt;/strong> of the IT world. ICS systems are omnipresent in all industries and are a vital element for critical industries such as nuclear power plants, electricity, water, gas, and oil distribution. It is therefore crucial to protect these systems against malicious attacks because compromising an ICS can have serious consequences, including loss of human lives or environmental disasters.&lt;/p>
&lt;h3 id="scada-architecture">SCADA Architecture
&lt;/h3>&lt;p>SCADA architectures include both hardware and software components, making them a prime target for cyber-attacks in OT environments. Within a SCADA architecture, there are several common components, including &lt;strong>Programmable Logic Controllers (PLCs)&lt;/strong>, &lt;strong>Remote Terminal Units (RTUs)&lt;/strong>, &lt;strong>historian databases&lt;/strong>, &lt;strong>Human Machine Interfaces (HMI)&lt;/strong>, &lt;strong>sensors&lt;/strong>, and &lt;strong>actuators&lt;/strong>.&lt;/p>
&lt;p>SCADA systems are designed to collect information on geographically dispersed industrial processes, allowing operators to centrally view, supervise, or control operations in real time and remotely. This information may include states, temperatures, and pressures obtained from valves, sensors, pumps, etc.&lt;/p>
&lt;p>This information is transmitted to the SCADA software by on-site controllers that are involved in the industrial process, especially by PLCs and RTUs. PLCs are input/output-based microprocessors that execute programmed actions based on received inputs. RTUs do the same but tend to be used for less complex applications than PLCs as they are less flexible in terms of programming and are cheaper.&lt;/p>
&lt;p>The information collected by the different PLC/RTU is transmitted to the SCADA software, which centralizes it and makes it accessible via the HMI interface. Operators can then view and react to alarms in real-time.&lt;/p>
&lt;p>A &lt;strong>data historian&lt;/strong> is a centralized database located on the control system&amp;rsquo;s local network. It enables users to collect a significant amount of real-time data and business data to transform operations by providing information on equipment trends, patterns, and performance.&lt;/p>
&lt;p>ICS data historians typically collect data from various sources such as control devices, sensors, and PLCs. The collected data is usually obtained via specific/proprietary SCADA systems or &lt;strong>OPC DA/UA&lt;/strong> protocols. The data is then stored and made accessible via a user interface or API for reporting or analysis needs.&lt;/p>
&lt;p>In addition to being a central point across a network of sensors, control devices, and PLCs, data historians can also be connected to other systems such as &lt;strong>Enterprise Resource Planning (ERP)&lt;/strong> systems and analytics platforms to enable more comprehensive data analysis and decision-making. Therefore, due to its unique position between IT and OT, attackers are most likely to target the data historian and could use it as a pivot point to reach the OT network.&lt;/p>
&lt;h3 id="ics-protocols">ICS protocols
&lt;/h3>&lt;p>One of the specificities of the OT environment compared to IT lies in the differences in protocols. Indeed, a whole range of proprietary and non-proprietary protocols connect communications between the various components of the ICS. One common trait of these protocols is that they are &lt;strong>insecure by design&lt;/strong>, as when they were developed (mostly a long time ago), the primary goal was performance. Messages are transmitted in clear text for most protocols or are affected by numerous security vulnerabilities. As a result, there is a risk that anyone who penetrates the control network would be able to read or send control instructions to a controller.&lt;/p>
&lt;p>Some of the most common ICS protocols include:&lt;/p>
&lt;ul>
&lt;li>&lt;strong>Modbus/TCP&lt;/strong>: Generally used for communication between equipment such as PLCs and supervisory computers or remote control devices. It is relatively simple to implement and deploy, making it a popular choice for industrial applications.&lt;/li>
&lt;li>&lt;strong>OPC&lt;/strong>: A communication protocol that allows software from different vendors to communicate with each other. There are 2 versions: &lt;strong>OPC DA&lt;/strong> (older, unencrypted) and &lt;strong>OPC UA&lt;/strong> (supports encryption).&lt;/li>
&lt;li>&lt;strong>DNP3&lt;/strong>: Developed for electric power distribution networks. It includes security mechanisms such as authentication, key management, and cryptography enhancement.&lt;/li>
&lt;li>&lt;strong>EtherNet/IP&lt;/strong>: A proprietary protocol developed by Rockwell Automation.&lt;/li>
&lt;li>&lt;strong>Profinet&lt;/strong>: A communication protocol developed by Siemens.&lt;/li>
&lt;li>&lt;strong>S7COMM&lt;/strong>: A protocol developed by Siemens for SIMATIC S7 controllers.&lt;/li>
&lt;/ul>
&lt;p>From a security standpoint, the most important thing about all ICS protocols is not to know them in detail, but rather to &lt;strong>know the expected behaviors and traffic&lt;/strong> through a baseline in order to quickly detect anomalies on the network.&lt;/p>
&lt;h3 id="common-attacks-vector-to-penetrate-ot-networks-from-it">Common attacks vector to penetrate OT networks from IT
&lt;/h3>&lt;p>Attackers often seek to penetrate OT systems through attack vectors originating from the IT network, such as malware, phishing attacks, and system vulnerabilities. In this article, we will explore three common attack vectors from IT to OT.&lt;/p>
&lt;h4 id="insufficient-network-segmentation">Insufficient network segmentation
&lt;/h4>&lt;p>Flat networks are widespread in the world of OT (where air-gapped network should be), which allows attackers to move from IT to OT and vice versa. A significant portion of the attacks perpetrated in the ICS network may not necessarily be targeted and prepared for these environments. In fact, most attacks target the IT environment, and network exploration allows malware to deploy in the OT and disrupt or interrupt production, which can be easily achieved with ransomware-type malware. It is therefore essential to implement effective security measures to protect ICS systems, including &lt;strong>network segmentation&lt;/strong> and establishing &lt;strong>security barriers&lt;/strong> to prevent attackers from moving easily between IT and OT.&lt;/p>
&lt;p>Although segmentation can be used to protect information technology and operational technology systems, there are often gaps and vulnerabilities that persist between them. This can be particularly true for &lt;strong>historians&lt;/strong>, which are databases that serve as a gateway between the two types of systems. Unfortunately, if these historians are not properly segmented, they can become an easy entry point for attacks targeting ICS. Hackers can exploit a vulnerability in the historian&amp;rsquo;s model to gain access to the rest of the network.&lt;/p>
&lt;p>Recently, Claroty&amp;rsquo;s Team82 security team demonstrated how a hacker could compromise a GE (General Electric) historian. To learn more about this attack, you can refer to their &lt;a class="link" href="https://claroty.com/team82/research/hacking-ics-historians-the-pivot-point-from-it-to-ot" target="_blank" rel="noopener"
>article&lt;/a>.&lt;/p>
&lt;h4 id="unsecured-remote-connections">Unsecured remote connections
&lt;/h4>&lt;p>There are several types of remote connections that are commonly used in ICS. These include:&lt;/p>
&lt;ul>
&lt;li>Engineering host on the business side that accesses ICS with poorly configured VPN&lt;/li>
&lt;li>Human-machine interface (HMI) through &lt;strong>Virtual Network Computing (VNC)&lt;/strong> or &lt;strong>Remote Desktop Protocol (RDP)&lt;/strong>&lt;/li>
&lt;li>Unsecure VPN with or without credential theft from the IT side&lt;/li>
&lt;/ul>
&lt;p>These remote connections are often used to provide remote access for engineers, technicians, and other personnel who need to perform maintenance or diagnostics on ICS equipment from outside the control room. However, these connections can also create significant security risks if they are not properly secured.&lt;/p>
&lt;p>Cybercriminals can exploit vulnerabilities in these connections to gain unauthorized access to ICS networks, which can result in severe consequences, such as the loss of production, equipment damage, or even injury to personnel. Moreover, cyberattacks on ICS networks can also cause widespread disruption and harm to critical infrastructure.&lt;/p>
&lt;p>Several cyberattacks on critical ICS networks have exploited unsecured remote connections. For instance:&lt;/p>
&lt;ul>
&lt;li>&lt;strong>Triton/Trisis&lt;/strong>: In 2017, this malware was discovered targeting a Middle Eastern petrochemical plant. The hackers used an unsecured VPN connection to gain access to the plant&amp;rsquo;s ICS network and executed a malware based on a vulnerability in the plant&amp;rsquo;s safety system. The malware was designed to manipulate the safety system, which could have resulted in a catastrophic incident if it had not been detected and mitigated in time.&lt;/li>
&lt;li>&lt;strong>Ukraine Power Grid Attack&lt;/strong>: On December 23, 2015, hackers gained access to the grid&amp;rsquo;s network by exploiting a vulnerability in the grid&amp;rsquo;s VPN system, causing a blackout that left hundreds of thousands of people without electricity.&lt;/li>
&lt;/ul>
&lt;p>These attacks highlight the importance of securing remote connections in ICS networks.&lt;/p>
&lt;h4 id="third-parties">Third parties
&lt;/h4>&lt;p>Industrial control systems networks are increasingly being connected to &lt;strong>third parties&lt;/strong> such as suppliers, service providers, and maintenance companies to facilitate the exchange of information and interactions between different parties. However, this interconnectivity can pose significant risks to the security of ICS. Third parties can access the OT network through various pathways such as VPN connections, direct cable connections, energy management systems, and building management systems.&lt;/p>
&lt;p>&lt;strong>Norsk Hydro&lt;/strong>, a Norwegian aluminum manufacturer, suffered from a ransomware attack in 2019. The attack began by targeting a third-party IT service provider for Norsk Hydro, which allowed the attackers to gain access to the company&amp;rsquo;s network. Once inside, the attackers deployed ransomware that encrypted the company&amp;rsquo;s files and disrupted its production systems, causing significant financial damage.&lt;/p>
&lt;p>The attack suffered by Norsk Hydro highlights the risks associated with third-party suppliers and vendors in the supply chain of industrial control systems. This underscores the need for organizations to conduct &lt;strong>deep risk assessments&lt;/strong> of their supply chain and ensure that their third-party suppliers are duly evaluated and secured.&lt;/p></description></item></channel></rss>