Securing SCADA and DCS Systems Inside Refineries and Pipelines Georgia

While oil and gas companies have made strides to protect the physical security of their plants and infrastructure, two factors have lately moved control system security higher up on the agenda: Supervisory control and data acquisition (SCADA) systems and Distributed Control Systems (DCSs) used within refineries and to control pipelines are vulnerable to cyber threats.

Local Companies

Infinity Network Solutions
478-475-9500
93 Gateway Drive
Macon, GA
EDTS, LLC
706-722-6604
933 Broad Street
Augusta, GA
E Elfe James Management Llc
(706) 745-7247
71 Blue Ridge St
Blairsville, GA
92 Solutions Llc
(770) 992-9252
1775 Woodstock Rd
Roswell, GA
US Small Business Admin (Score)
(706) 279-3383
524 Holiday Ave
Dalton, GA
Manhattan Associates
(770) 955-1365
3101 Towercreek Pkwy SE Ste 300
Atlanta, GA
Horrigan George R
(770) 642-4220
10902 Crabapple Rd
Roswell, GA
Apiscor Inc
(770) 614-4656
4860 S Lee St
Buford, GA
The Solution Center
(404) 705-8668
310 Sologne Ct NW
Atlanta, GA
Redland Holding Llc
(478) 475-4909
5400 Riverside Dr
MacOn, GA



By Tom Schmidt

While oil and gas companies have made strides to protect the physical security of their plants and infrastructure, two factors have lately moved control system security higher up on the agenda:

  • Supervisory control and data acquisition (SCADA) systems and Distributed Control Systems (DCSs) used within refineries and to control pipelines are vulnerable to cyber threats.
  • The explosive nature of these commodities makes this industry's infrastructure an attractive target.

But while progress has been made to enhance cyber security, oil and gas companies still face some steep challenges, including the need to connect once isolated SCADA and DCSs with business systems and networks; clashing organizational priorities; and the lack of a mandate to comply with cyber security-related standards.

This article examines today's principal SCADA and DCS vulnerabilities before proposing some effective practices that oil and gas companies can adopt to improve the security of these critical systems.

SCADA and DCS vulnerabilities

The oil and gas sector depends upon a vast and highly decentralized infrastructure, consisting of an extensive network of roughly 150 refineries, 200,000 miles of oil pipelines, and 2,000,000 miles of gas pipelines. SCADA and DCS systems used within refineries and to control pipelines form the backbone of most oil and gas industry operations in the United States and worldwide today. To supply corporate decision makers with crucial data, these organizations are increasingly integrating their SCADA and DCS systems with corporate business systems.

It is this development that has raised concerns among security professionals. These systems were originally built for efficiency and reliability -- and often deployed with security features not being implemented because they were intended to be isolated from the outside world. Integrating SCADA and DCS systems with corporate business systems exposes these control systems to cyber threats introduced through the corporate network.

Likewise, many of these control systems use the Modbus protocol to support communications with electronic flow measurement (EFM) devices and remote terminal units (RTUs) scattered throughout the thousands of miles of pipelines. While this interconnectedness provides corporate decision makers with access to critical data, it also leads to widespread availability of information about these control systems and their vulnerabilities.
 
At the same time, partner data sharing (a result of industry mergers and partnership formation) has fostered real-time data-sharing between DCS systems and corporate networks between separate corporate entities. These interconnections must be secured against cyber threats.
 
And some of those threats have been successful. For example, according to FBI director Robert Mueller, hackers in Russia were able to gain control of a gas pipeline for 24 hours by penetrating electronic control systems.

Finally, the nonstop operational requirement of SCADA and DCS systems complicates security implementation and testing because systems can never be taken offline. Many organizations maintain 24x7 operations via remote system access, which introduces additional vulnerability points.

Practices for securing SCADA and DCS systems

Oil and gas companies can benefit from proven practices to safeguard their SCADA and DCS systems within refineries and pipelines. Moreover, the following four-step cyber security process aligns with the recommendations put forth in the Security Guidelines for the Petroleum Industry, published by the American Petroleum Institute in April 2005.

  • Step 1: Security Assessment This includes assessing a company's awareness of electronic threats before they reach the organization, identifying possible regulatory compliance issues, assessing the effectiveness of security and administration tools, and manually validating these security concerns using penetration testing methods.
  • Step 2: Security Policy Creation and Enforcement Here companies establish who is authorized to gain access to what information, as well as who is authorized to perform what functions. To ensure an effective policy, organizations must continually measure compliance with its policies and procedures.
  • Step 3: Security Measure Deployment To combat ever-evolving cyber threats, organizations must utilize proven security technologies and procedures, and that means recognizing that perimeter firewalls alone offer insufficient protection. An Intrusion Detection System (IDS) featuring both protocol anomaly and signature-based detection techniques is a vital element of modern network security. Oil and gas companies must also address inadequately protected networked, mobile, and remote users, protecting them with antivirus, IDS, and personal firewalls. This step also involves implementing recovery procedures and tools to be used in the event that an attack eludes other security measures.
  • Step 4: Security Monitoring and Management This involves real-time, 24/7 monitoring and management of security information resources to prevent disruptions and minimize downtime. And that poses a real challenge. Pipeline and refinery control center personnel must focus on their system operation duties and aren't typically trained in the nuances of effective security monitoring and management. As a result, many organizations are using third parties that have experience providing management and monitoring of security devices. Also, early warning services can provide customized alerts of worldwide cyber attacks -- as well as countermeasures to prevent attacks before they occur.

Conclusion

The increasingly interconnected nature of SCADA, DCS, corporate networks, remote workers, and other networks means the industry must move to enhance security of this critical infrastructure -- in spite of a current lack of industry-mandated cyber security regulations.
 
The good news is that a growing number of technologies and services are available to help companies secure not only their SCADA and DCS networks but also the networks to which they are connected. For oil and gas companies looking to protect their refineries and pipelines from constantly evolving cyber threats, that can mean the difference between a costly disruption and business continuity.

Tom Schmidt writes frequently about information security topics. He has more than 15 years' experience as a writer and editor in high-tech publishing.

Featured Local Company

Infinity Network Solutions

478-475-9500
93 Gateway Drive
Macon, GA
www.infinitynetworks.net

Related Articles
- Automating NERC CIP Compliance Georgia
Matching up security policies with NERC CIP regulatory requirements, compiling appropriate NERC CIP compliance documentation, and reporting on current compliance levels are labor- and capital-intensive tasks. A key strategy for reducing the risk and cost associated with implementing IT controls is to automate as many procedures as possible.
- IP PBX VoIP Phone Systems Georgia
- Electric Utilities: Securing the Perimeter Georgia
- The Strategic Advantage of VoIP Georgia
- Hosted VoIP Systems Georgia
- Stepping Up to Security Compliance Georgia
- Protection for Small Companies Georgia
- The DoD's IT Dilemma Georgia
- Effective Filing System Georgia
- Looking Out for Insider Threats Georgia
Regional Articles
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Acworth GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Albany GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Alpharetta GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Americus GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Athens GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Atlanta GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Augusta GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Austell GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Baxley GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Blairsville GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Brunswick GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Buford GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Calhoun GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Canton GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Carrollton GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Cartersville GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Cedartown GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Chatsworth GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Columbus GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Conyers GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Cordele GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Covington GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Cumming GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Dacula GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Dahlonega GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Dallas GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Dalton GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Dawsonville GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Decatur GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Douglas GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Douglasville GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Dublin GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Duluth GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Eatonton GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Elberton GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Ellenwood GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Ellijay GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Evans GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Fairburn GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Fayetteville GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Fitzgerald GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Flowery Branch GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Forest Park GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Fort Benning GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Fort Valley GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Gainesville GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Griffin GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Grovetown GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Hartwell GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Hephzibah GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Hinesville GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Jesup GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Jonesboro GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Kennesaw GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Kingsland GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines La Fayette GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Lagrange GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Lawrenceville GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Lilburn GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Lithia Springs GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Lithonia GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Loganville GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Mableton GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Macon GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Marietta GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Mcdonough GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Milledgeville GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Monroe GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Morrow GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Moultrie GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Newnan GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Norcross GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Peachtree City GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Powder Springs GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Ringgold GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Riverdale GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Rockmart GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Rome GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Rossville GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Roswell GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Saint Simons Island GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Savannah GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Sharpsburg GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Smyrna GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Snellville GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Statesboro GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Stockbridge GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Stone Mountain GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Suwanee GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Thomaston GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Thomasville GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Thomson GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Tifton GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Toccoa GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Tucker GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Valdosta GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Vidalia GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Villa Rica GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Warner Robins GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Waycross GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Winder GA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Woodstock GA
Related Articles
- Looking Out for Insider Threats Georgia
If the topic of protecting against insider threats makes many a government IT worker shudder, it's for good reason. Besides the millions of people employed by government agencies, the number of federal civil servants is on the rise, as is the number of people working for government-funded contractors and organizations that receive government grants. Add to that the number of postal workers and military personnel, and the "true size" of the federal government is around 14.6 million employees, according to Paul C. Light, government professor at New York University.
- Effective Filing System Georgia
- Automating NERC CIP Compliance Georgia
- Electric Utilities: Securing the Perimeter Georgia
- Stepping Up to Security Compliance Georgia
- IP PBX VoIP Phone Systems Georgia
- Protection for Small Companies Georgia
- The DoD's IT Dilemma Georgia
- Hosted VoIP Systems Georgia
- The Strategic Advantage of VoIP Georgia
Related Local Events
The Special Event
Dates: 1/13/2010 - 1/15/2010
Location: Georgia World Congress Center, Atlanta
Atlanta, GA
View Details

2009 Annual Conference: Magnify Your Security
Dates: 11/11/2009 - 11/11/2009
Location: Loudermilk Center
Atlanta, GA
View Details

Elcom Caucasus
Dates: 10/29/2009 - 10/31/2009
Location: Georgia World Congress Center
Atlanta, GA
View Details

Rss   Delicious   Digg   Add To My Yahoo   Add To My Google   Bookmark   Search Plugin

Topics:
Advertising Family Home Services Real Estate Resources
Business Services Fashion Industrial Goods & Services Retail & Consumer Services
Career Financial Services Insurance Software
Cars Food & Beverage Internet Technology
Computer Hardware Franchise Legal Telecommunications
Construction Health Miscellaneous Trade Shows
Education Holidays Nightlife Travel
Entertainment Home Appliances Online Database Weddings
Environmental Home Electronics Pets World History