Home » Under-reporting Bedevils Estimates of Cyber Threat
Under-reporting Bedevils Estimates of Cyber Threat
ControlGlobal.com
12/02/2009
By Andrew Bond, Industrial Automation Insider
Our observation, in reporting publication of a new white paper from cybersecurity specialist Innominate, that the most surprising aspect of the cybersecurity issue as it relates to process plant and critical infrastructure is "just how few really serious cases have been added to the list of documented incidents over the years" did not go unnoticed.
Frank Dickman, who wrote the original paper, entitled "Hacking the Industrial Network" and downloadable from www.innominate.com/white_paper_registration, emailed us to point out that, while most of the published incidents he quoted were already familiar, that was because "I specifically chose published source documents to allow the reader to readily check every statement of fact, rather than write unsupported opinion." And he cites a number of references to support the argument that the principal reason for the dearth of reported incidents is non- or under-reporting. For example, the U.S. General Accounting Office (GAO) report "Critical Infrastructure Protection: Challenges and Efforts to Secure Control Systems" of 2004 estimates that "as much as 80% of actual security incidents go unreported in most cases because (1) there were no indications of penetration or attack, (2) the organization was unable to recognize that its systems had been penetrated, or (3) the organization was reluctant to report."
Similarly Idaho National Laboratory’s 2005 report, "Cyber Incidents Involving Control Systems" states that ". . . the confidential nature of cyber incidents makes it difficult to collect data and project future losses."
Reliable data
Clearly there is a problem in arriving at a reliable estimate of the level of attacks, both successful and unsuccessful, and in assessing how valid is the widely accepted contention that actual incidents are many times more numerous than the few that are reported.
Nonetheless, it is still surprising, for example, that the Repository for Industrial Security Incidents (RISI), which is maintained by Byres Security on behalf of Idaho National Laboratories and logs incidents directly affecting SCADA and process control systems, including those reported in confidence by organizations, currently holds data on a total of only some 150 incidents, according to the Byres web site. Nevertheless that makes it, so it is claimed, the largest known repository of SCADA security data in the world.
Nor is the problem getting any easier. Dickman writes that "Hackers and malware authors have metastasized from teenagers seeking peer recognition to professionals seeking profit within recent years" and concludes that "it is my expectation that we will see more efforts at profit-centered extortion in the future." With organizations and companies almost certainly even more reluctant to admit that they have been blackmailed than that they have simply been attacked, the need for more reliable data on the scale of the threat is even more pressing.
More News:
-
02/03/2012
Online Measurement Will Drive Liquid Analytical Market to $1 Billion by 2014
Study from Flow Research Finds That the Worldwide Market for Leading Liquid Analytical Instruments Is Projected to Grow
-
02/01/2012
Shell Scotford Upgrader Named 2011 HART Plant of the Year
Engineers Get Connected to HART Communication to Facilitate Loop Testing, Start-Up, Valve Tuning, Safety Systems and Remote Device Diagnostics
-
01/25/2012
Magnetrol's Eclipse Model 705 Receives SIL 3 Certification
exida awards Magnetrol International's Eclipse Model 705 Guided Wave Radar Transmitter as Safety Integrity Level (SIL) 3 capable per IEC 61508
-
01/25/2012
Fieldbus Foundation To Hold 2012 General Assembly
This year's General Assembly, scheduled for March 6-8 in Brazil, is themed, "In a World of Choices, FOUNDATION Brings it all Together"
-
01/24/2012
Video Explains Interface Detection for Air, Oil and Gas
Video Explains Interface Detection for Air, Oil and Gas With Thermal Flow Switches In Petrochemical Applications
-
01/19/2012
Siemens Becomes Strategic Process Automation Partner for Dow Corning
The Global Supply Contract will feature Siemens Simatic PCS 7 as the strategic platform for Dow Corning's batch, continuous and discrete process automation solutions
-
01/19/2012
Honeywell's 2012 Student Competition Now Expanded Across Asia Pacific
Honeywell's 2012 Student Competition to Include Entries from Korea, India, Japan, China, South East Asia, Australia and New Zealand
-
01/16/2012
Metso DNA Automation System Increases Efficiency, Operational Knowledge and Control
Metso's New DNA applications for power generation industries
-
01/16/2012
Steam Energy 2012 Training Course Schedule
Spirax Sarco releases 2012 steam energy training course schedule
-
01/16/2012
Custom Cabinetry and Millwork for Control Room Installations
Winsted Launches New Custom Wood Division
- All news »
Sponsored Links
Control Digital Edition
Access the entire print issue on-line and be notified each month via e-mail when your new issue is ready for you. Subscribe today.
- Featured White Papers

Print page