Home » PCSF group moves to detect control system attacks
PCSF group moves to detect control system attacks
ControlGlobal.com
06/13/2006
According to Dale Peterson, Director, Network Security Practice, Digital Bond, Inc. and Chair of the SEM Working Group, the purpose of the Group is to serve as a clearinghouse of information and tools to detect attacks on control systems.
Accurately determining risk is extremely important to control system security. Today, the control system community understands two-thirds of the risk equation: the impact of a control system outage due to cyber attack and the vulnerabilities of control systems. What is missing is quantitative and qualitative measurement of the risk. SEM services, in the form of managed security services providers (MSSPs), are monitoring many control system networks for attacks and have threat data. Some asset owners also have deployed SEM products and have threat data.
The first task of the SEM Working Group is to gather and normalize this threat data from disparate sources. The SEM Working Group has been collaborating with these entities to develop a format that will allow them to easily—and anonymously—submit this data to the PCSF.
Next, the Group plans to analyze the data and provide statistics to the community through the PCSF. Planned statistics include the number of control systems being monitored, the number of actionable cyber security events, and the breakdown of the actionable cyber security events into seven event categories.
Today, SEM products and services monitor traditional IT systems such as firewalls, operating system logs, and intrusion detection systems (IDS). However, the majority of these products and services do not account for security events in the supervisory control and data acquisition (SCADA) and distributed control systems (DCS) application logs, because each application logs these security events differently.
In response to this, the SEM Working Group also plans to develop a data dictionary containing a normalized list of control system application log events and a description of the impact of each event. Additionally, they plan to create a database that will use pattern recognition to identify similar events from different SEM products.
More News:
- 02/05/2010 Innovative program to smooth boiler system start-ups
- 02/05/2010 Emerson, Shell sign multi-year deal for technologies and services
- 02/04/2010 New report: better performing plants mean better performing businesses
- 02/04/2010 Illinois groups launch Illinois Coalition for Chemical Safety
- 02/04/2010 Some process industry segments primed for growth in 2010
- 02/02/2010 Honeywell Gets Rights to Shell's Operator Rounds Technology
- 02/02/2010 MooreHawke, P+F Get First H1 Device Coupler Registrations
- 02/02/2010 GEIP in Asset Management Deal with Metso
- 02/02/2010 Industrial PC Market Driven by Technology Advances
- 02/02/2010 BP-Husky to Invest $400 Million in Toledo Refinery
- All news »
Sponsored Links
Control Digital Edition
Access the entire print issue on-line and be notified each month via e-mail when your new issue is ready for you. Subscribe today.
- Featured White Papers

Print page