Cyber security

Stuxnet News Coverage

A summary of news articles on the game changing Stuxnet malware.

Note: Visit Stuxnet Central for more information on Stuxnet.

Tiny Tofino Logo indicates articles that contain news about Tofino Security, the Tofino Industrial Security Solution or that contain quotes from Eric Byres. 

Telvent Hack

A summary of news articles on the Telvent hack where Chinese attackers allegedly stole data from the global energy equipment supplier.

Tiny Tofino Logo indicates articles that contain news about Tofino Security, the Tofino Industrial Security Solution or that contain quotes from Eric Byres.

SCADA Security Issues – A Virtual Panel Discussion

Article from: EngineerIT, September 2012

EngineerIT invited a group of experts representing a number of companies to contribute to a virtual panel discussion on security issues in supervisory control and data acquisition (SCADA) systems, including a debate around the Air Gap principle.

ICSJWG Fall 2010 Conference

Seattle, Washington

October 25 - 28, 2010

 

Tofino Security speaker:

Eric Byres, CTO

 

Date: Wednesday, October 27, 2010

Time: 14:15 - 15:00

Session: Track 2

 

Topic: SCADA and Control Systems Security: New Standards Protecting Old Technology

 

Joann Byres, CEO, also attended the conference.

 

Siemens PCS7 WinCC Malware

New Stuxnet White Paper: Analysis of the Siemens WinCC / PCS7 “Stuxnet” Malware for Industrial Control System Professionals.

Stuxnet is a computer worm designed to take advantage of a number of previously unknown vulnerabilities present in the Windows operating system and Siemens SIMATIC WinCC, PCS7 and S7 product lines.

It was designed to target one or more industrial systems that use Siemens PLCs with the apparent objective of sabotaging industrial processes.

This White Paper summarizes the current known facts about the Stuxnet worm and the actions that operators of SCADA and ICS systems can take to protect critical operations.

Also included is Joel Langill's excellent video that shows in detail how Stuxnet infects a system.

Security breakthrough for OPC-based industrial automation

News coverage following the release of the Tofino OPC Enforcer.

Belden releases new Plug-n-Protect OPC firewall to provide robust cyber security for automation facilities

Belden has recently introduced version 1.6.0 of its Hirschmann™ EAGLE20 Tofino industrial network security system, including the new EAGLE20 Tofino OPC Enforcer Loadable Software Module (LSM). Developed by Tofino Security for Hirschmann™, the OPC Enforcer locks down any system using the widely installed OPC Classic protocol, providing superior security over what can be achieved with conventional firewall solutions.

Flash drive launches cyber-attack

At the beginning of the year I hosted a podcast interview on cyber security with Eric Byres, chief technology officer of Tofino Security. The interview was conducted to help our audience understand the risks of cyber attacks and learn how to mitigate them.

Securing Your OPC Classic Control System

by Eric Byres, security expert and CTO of Byres Security and Thomas J. Burke, President, OPC Foundation.

OPC Classic is a software interface technology used to facilitate the transfer of data between different industrial control systems. It is widely used to interconnect Human Machine Interface (HMI) workstations, data historians and other hosts on the control network with enterprise databases, Enterprise Resource Planning (ERP) systems and other business-oriented software. Unfortunately, securely deploying OPC Classic has proven to be a challenge until recently.

Control networks are too open to cyber attacks

Most automation specialists are shocked to find out how much traffic is on their production control networks. Find out how installing the latest technology and adopting tighter policies for securing production networks can help to protect the integrity of critical control, safety, and regulatory data and processes.

Segmenting control and automation networks from the business network

Plant facilities from the smallest to the largest should have their business networks separate from their automation or control networks on the production floor.  ControlDesign writes about a common and frightening scenario of what could happen when plant networks are not segmented correctly.

Keep Controls Network Separate From Business Network

ControlDesign.com
July 10, 2010

Could Cyber Terrorists Attack Our Company?

Article in:  ControlGlobal, June 2010

The majority of control system cyber threats are unintentional, as discussed in this article that summarizes data from the Repository of Industrial Security Incidents (RISI).  Tips on how to start reducing the risk of cyber threats are provided.

Could Cyber Terrorists Attack Our Company?

Canvassing the cyber security landscape: Why energy companies need to pay attention

Recent news of a “highly sophisticated and targeted” cyber attack on Google, Yahoo, and perhaps on as many as a dozen other companies has once again brought the issue of cyber security to the top of the news.   The Journey of Energy Security dives into some of the energy industries historical background and outlines some of the key vulnerabilities, threats and risks that energy industry faces.

High Security Integration Using OPC

Invensys  Operations Management LogoByres  Security Inc Logo

 

 

OPC Classic, the popular industrial integration standard based on DCOM, has made the interfacing of different industrial control products significantly easy. Unfortunately, it also brought with it a number of serious security concerns for the designers of control, SCADA and safety systems.

Safety and Security: Two Sides of the Same Coin

Article in:  ControlGlobal, April 2010

The relationship between safety and security is such that a weakness in security creates increased risk, which in turn creates a decrease in safety. As a result, safety and security are directly proportional, but both are inversely proportional to risk.

Pre-Staging Tofino™ for Enhanced Security

Pre-staging or pre-deploying Tofino Security Appliances offers a unique solution offering enhanced security and easy deployment for remote or operational installations. This application note contains information on configuring and using this method of deployment.

 

Securing Control Networks with the Tofino™ VPN

Version 1.4 of the Tofino Industrial Security Solution introduced a new set of Tofino Loadable Security Modules (LSMs) that enable the creation of Virtual Private Network (VPN) connections in control networks. The Tofino VPN is designed specifically for use within an industrial environment, so it has some unique features tailored for use within SCADA and control systems:

Defense in Depth Protection for Honeywell Experion

As Distributed Control System (DCS) architectures integrate more IT-based technologies (such as Ethernet and Windows), it is important to implement a sound security strategy. This application note describes how Honeywell Process Solutions uses the Tofino Security Appliance (SA) to protect a system that is being migrated from an older TDC2000 DCS to modern Ethernet Experion™ PKS system.

Network Security Demands Less Complexity

AutomationWorld writes about the principles of infrastructure network security and the importance of keeping things simple.

Leadership Focus Podcast: Cyber Security

Podcast from: ChemicalProcessing.com, January 2010

 

Each year the damage to critical infrastructure from network incidents and cyber attacks is measured in the billions of dollars.

 

Traci Purdum, senior digital editor, talks to Eric Byres, chief technology officer of Byres Security Inc., to understand the risks and learn how to mitigate them.

 

 

Pages

Subscribe to RSS - Cyber security