SANS NewsBites, Vol.14 Number 99: Control Systems under Attack -why the scare tactics?

Dec. 17, 2012
On December 14, SANS came out with the following headlines: All 3 "top of the news" stories this week illustrate an important security trend: Internet facing control systems are becoming much more prevalent allowing easy exploitation of disclosed vulnerabilities for disruption as well as back door access to other corporate systems...

On December 14, SANS came out with the following headlines: All 3 "top of the news" stories this week illustrate an important security trend: Internet facing control systems are becoming much more prevalent allowing easy exploitation of disclosed vulnerabilities for disruption as well as back door access to other corporate systems...

New Jersey Control System Exploited Due To Lack of Due Diligence In Perimeter Security
(December 13, 2012)
Using information obtained online, hackers gained access to a New Jersey company's internal heating and air conditioning system. .. The incident was revealed in an FBI memo that was recently made public. The breach occurred in February and March 2012.

--German Power Grid Operator Hit With DDoS Attack
(December 12, 2012)
50Hertz, a German power utility grid operator, was hit with a distributed denial-of-service (DDoS) attack late last month. For a short while, the company's Internet communications systems were unusable. The attack did not affect electricity supplies.

--Web-based SCADA Gathers More Fans
(December 5, 2012)
A summary of the trends that affect/afflict SCADA systems today. On one hand there is cause for concern as "common" attacks now work against these systems. On the other hand, there is a small, growing body of security professionals that at least have experience dealing with the technology.

There have been some very significant control system cyber incidents as well as issues such as Aurora that are still being effectively ignored. Many of these incidents or vulnerabilities are not IT issues and cannot be addressed by SANS general IT and Windows recommendations. It is a shame that SANS is playing games with such an important subject as control system cyber security.

Joe Weiss

Sponsored Recommendations

Make Effortless HMI and PLC Modifications from Anywhere

The tiny EZminiWiFi is a godsend for the plant maintenance engineers who need to make a minor modification to the HMI program or, for that matter, the PLC program. It's very easy...

The Benefits of Using American-Made Automation Products

Discover the benefits of American-made automation products, including stable pricing, faster delivery, and innovative features tailored to real-world applications. With superior...

50 Years of Automation Innovation and What to Expect Next

Over the past 50 years, the automation technology landscape has changed dramatically, but many of the underlying industry needs remain unchanged. To learn more about what’s changed...

Manufacturing Marvels Highlights Why EZAutomation Is a Force to Be Reckoned With

Watch EZAutomation's recent feature on the popular FOX Network series "Manufacturing Marvels" and discover what makes them a force to be reckoned with in industrial automation...