Practical SCADA Security

Control System Security Threats, Security / Reliability Incidents, Useful Industrial Cyber Security Tips

submitted by: Eric Byres
on: Mon, 2011-03-21 10:23

There has been a lot of media coverage and discussion of the Stuxnet malware, and its impact on industrial control system (ICS) and SCADA security. We are one of the groups guilty of creating a Stuxnet publishing industry.

submitted by: Eric Byres
on: Wed, 2011-03-09 10:22

Last week the International Society of Automation (ISA) announced that a new committee, ISA99 WG5 TG2, has been struck to conduct a gap analysis of the current ANSI/ISA-99 standards with respect to Stuxnet. The goal is to determine if companies following the standards would have been protected from advanced persistent threats (APTs) such as Stuxnet. If not, then the committee will identify what changes are needed.

I have been asked to Chair the committee and I am writing today to let you know about its work, to explain why it is important, and to ask for your participation.

submitted by: Eric Byres
on: Thu, 2011-03-03 12:23

The Oscars are over and the film about Facebook, The Social Network, won three awards. Pretty good – I saw the movie and thought it deserved a few gold statues.

But just as I was getting ready for the Oscar weekend, I received the following email from Facebook:

From: Facebook
Sent: Friday, February 25, 2011 1:17 PM
To: Eric Byres
Subject: Joe Smith posted on your Wall.

submitted by: Eric Byres
on: Tue, 2011-02-22 16:27

Over the past four months, Joel Langill, Andrew Ginter and I have been working on a really cool research project. We have been investigating how Stuxnet would infect an industrial site protected by a “high security architecture.”

submitted by: Eric Byres
on: Fri, 2011-02-18 09:34

February has not been a good month for ICS and SCADA security, at least not if you want to feel secure.