Securing SCADA and DCS Systems Inside Refineries and Pipelines Illinois

While oil and gas companies have made strides to protect the physical security of their plants and infrastructure, two factors have lately moved control system security higher up on the agenda: Supervisory control and data acquisition (SCADA) systems and Distributed Control Systems (DCSs) used within refineries and to control pipelines are vulnerable to cyber threats.

Local Companies

Advanced System Designs
(309) 263-7944
100 Yordy
Morton, IL
Netneering LLC
(773) 655-9173
4827 N. Sheridan Rd.
Chicago, IL
Network Sentry
630 715 5662
PO Box 1234
Chicago, IL
Swift Technologies, Inc.
847-289-8339
920 Davis Rd
Elgin, IL
Network Sentry
224-330-7573
PO Box 123
Schaumburg, IL
CIAN, Inc.
(309) 691-3000
1717 Candletree Drive
Peoria, IL
Novanis Enterprise Solutions
(217) 698-0999
3161 W. White Oaks Drive
Springfield, IL
CIAN, Inc
309-691-3000
1717 W. Candletree Drive
Peoria, IL
FHS3 Tech Service
309-310-3576
30 Waterside Circle
Bloomington, IL
NETPLATFORM, Inc.
(309) 685-9700
2216 W. Altorfer Drive
Peoria, IL



By Tom Schmidt

While oil and gas companies have made strides to protect the physical security of their plants and infrastructure, two factors have lately moved control system security higher up on the agenda:

  • Supervisory control and data acquisition (SCADA) systems and Distributed Control Systems (DCSs) used within refineries and to control pipelines are vulnerable to cyber threats.
  • The explosive nature of these commodities makes this industry's infrastructure an attractive target.

But while progress has been made to enhance cyber security, oil and gas companies still face some steep challenges, including the need to connect once isolated SCADA and DCSs with business systems and networks; clashing organizational priorities; and the lack of a mandate to comply with cyber security-related standards.

This article examines today's principal SCADA and DCS vulnerabilities before proposing some effective practices that oil and gas companies can adopt to improve the security of these critical systems.

SCADA and DCS vulnerabilities

The oil and gas sector depends upon a vast and highly decentralized infrastructure, consisting of an extensive network of roughly 150 refineries, 200,000 miles of oil pipelines, and 2,000,000 miles of gas pipelines. SCADA and DCS systems used within refineries and to control pipelines form the backbone of most oil and gas industry operations in the United States and worldwide today. To supply corporate decision makers with crucial data, these organizations are increasingly integrating their SCADA and DCS systems with corporate business systems.

It is this development that has raised concerns among security professionals. These systems were originally built for efficiency and reliability -- and often deployed with security features not being implemented because they were intended to be isolated from the outside world. Integrating SCADA and DCS systems with corporate business systems exposes these control systems to cyber threats introduced through the corporate network.

Likewise, many of these control systems use the Modbus protocol to support communications with electronic flow measurement (EFM) devices and remote terminal units (RTUs) scattered throughout the thousands of miles of pipelines. While this interconnectedness provides corporate decision makers with access to critical data, it also leads to widespread availability of information about these control systems and their vulnerabilities.
 
At the same time, partner data sharing (a result of industry mergers and partnership formation) has fostered real-time data-sharing between DCS systems and corporate networks between separate corporate entities. These interconnections must be secured against cyber threats.
 
And some of those threats have been successful. For example, according to FBI director Robert Mueller, hackers in Russia were able to gain control of a gas pipeline for 24 hours by penetrating electronic control systems.

Finally, the nonstop operational requirement of SCADA and DCS systems complicates security implementation and testing because systems can never be taken offline. Many organizations maintain 24x7 operations via remote system access, which introduces additional vulnerability points.

Practices for securing SCADA and DCS systems

Oil and gas companies can benefit from proven practices to safeguard their SCADA and DCS systems within refineries and pipelines. Moreover, the following four-step cyber security process aligns with the recommendations put forth in the Security Guidelines for the Petroleum Industry, published by the American Petroleum Institute in April 2005.

  • Step 1: Security Assessment This includes assessing a company's awareness of electronic threats before they reach the organization, identifying possible regulatory compliance issues, assessing the effectiveness of security and administration tools, and manually validating these security concerns using penetration testing methods.
  • Step 2: Security Policy Creation and Enforcement Here companies establish who is authorized to gain access to what information, as well as who is authorized to perform what functions. To ensure an effective policy, organizations must continually measure compliance with its policies and procedures.
  • Step 3: Security Measure Deployment To combat ever-evolving cyber threats, organizations must utilize proven security technologies and procedures, and that means recognizing that perimeter firewalls alone offer insufficient protection. An Intrusion Detection System (IDS) featuring both protocol anomaly and signature-based detection techniques is a vital element of modern network security. Oil and gas companies must also address inadequately protected networked, mobile, and remote users, protecting them with antivirus, IDS, and personal firewalls. This step also involves implementing recovery procedures and tools to be used in the event that an attack eludes other security measures.
  • Step 4: Security Monitoring and Management This involves real-time, 24/7 monitoring and management of security information resources to prevent disruptions and minimize downtime. And that poses a real challenge. Pipeline and refinery control center personnel must focus on their system operation duties and aren't typically trained in the nuances of effective security monitoring and management. As a result, many organizations are using third parties that have experience providing management and monitoring of security devices. Also, early warning services can provide customized alerts of worldwide cyber attacks -- as well as countermeasures to prevent attacks before they occur.

Conclusion

The increasingly interconnected nature of SCADA, DCS, corporate networks, remote workers, and other networks means the industry must move to enhance security of this critical infrastructure -- in spite of a current lack of industry-mandated cyber security regulations.
 
The good news is that a growing number of technologies and services are available to help companies secure not only their SCADA and DCS networks but also the networks to which they are connected. For oil and gas companies looking to protect their refineries and pipelines from constantly evolving cyber threats, that can mean the difference between a costly disruption and business continuity.

Tom Schmidt writes frequently about information security topics. He has more than 15 years' experience as a writer and editor in high-tech publishing.

Featured Local Company

Advanced System Designs

3092637944
100 Yordy
Morton, IL

Related Articles
- Stepping Up to Security Compliance Illinois
The intent of multiple regulations, industry standards and best-practice frameworks across industries today is unambiguous: the emerging compliance paradigm seeks to ensure the security, availability and integrity of business information.
- Protection for Small Companies Illinois
- Electric Utilities: Securing the Perimeter Illinois
- The DoD's IT Dilemma Illinois
- The Strategic Advantage of VoIP Illinois
- Effective Filing System Illinois
- Hosted VoIP Systems Illinois
- Automating NERC CIP Compliance Illinois
- Looking Out for Insider Threats Illinois
- IP PBX VoIP Phone Systems Illinois
Regional Articles
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Addison IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Algonquin IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Alsip IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Alton IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Arlington Heights IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Aurora IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Barrington IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Bartlett IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Batavia IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Belleville IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Bellwood IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Belvidere IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Bensenville IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Berwyn IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Bloomingdale IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Bloomington IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Blue Island IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Bolingbrook IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Bourbonnais IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Bridgeview IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Buffalo Grove IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Calumet City IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Carbondale IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Carol Stream IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Carpentersville IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Champaign IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Chicago Heights IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Chicago IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Cicero IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Clarendon Hills IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Collinsville IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Country Club Hills IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Crete IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Crystal Lake IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Danville IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Decatur IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Deerfield IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Dekalb IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Des Plaines IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Dolton IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Downers Grove IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines East Moline IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines East Peoria IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines East Saint Louis IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Edwardsville IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Effingham IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Elgin IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Elk Grove Village IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Elmhurst IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Elmwood Park IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Evanston IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Evergreen Park IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Fairview Heights IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Franklin Park IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Freeport IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Galesburg IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Glen Ellyn IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Glendale Heights IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Glenview IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Godfrey IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Granite City IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Grayslake IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Gurnee IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Harvey IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Harwood Heights IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Hazel Crest IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Highland Park IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Hinsdale IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Homewood IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Jacksonville IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Joliet IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Kankakee IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Kewanee IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines La Grange IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Lake Bluff IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Lake Villa IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Lake Zurich IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Lansing IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Lemont IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Libertyville IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Lisle IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Lockport IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Lombard IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Loves Park IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Machesney Park IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Matteson IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Mattoon IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Maywood IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Mchenry IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Melrose Park IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Midlothian IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Mokena IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Moline IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Morris IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Morton Grove IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Morton IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Mount Prospect IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Mundelein IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Murphysboro IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Naperville IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines New Lenox IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Niles IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Normal IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines North Chicago IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Northbrook IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines O Fallon IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Oak Forest IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Oak Lawn IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Oak Park IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Orland Park IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Palatine IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Palos Hills IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Park Forest IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Park Ridge IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Pekin IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Peoria IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Plainfield IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Prospect Heights IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Quincy IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Riverdale IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Rochelle IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Rock Falls IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Rock Island IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Rockford IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Rolling Meadows IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Romeoville IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Roscoe IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Roselle IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Round Lake IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Saint Charles IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Schaumburg IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Skokie IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines South Elgin IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines South Holland IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Springfield IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Streamwood IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Streator IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Sycamore IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Taylorville IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Tinley Park IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Urbana IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Vernon Hills IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Villa Park IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Waukegan IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines West Chicago IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Westchester IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Westmont IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Wheaton IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Wheeling IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Wilmette IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Wood Dale IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Woodridge IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Woodstock IL
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Zion IL
Related Articles
- Protection for Small Companies Illinois
In an era when growth is critical to survival, small and midsize financial institutions are under pressure to provide greater access to valuable information assets across an expanding universe of customers, content providers, employees, and access devices.
- Electric Utilities: Securing the Perimeter Illinois
- The DoD's IT Dilemma Illinois
- Hosted VoIP Systems Illinois
- Stepping Up to Security Compliance Illinois
- Effective Filing System Illinois
- IP PBX VoIP Phone Systems Illinois
- Looking Out for Insider Threats Illinois
- Automating NERC CIP Compliance Illinois
- The Strategic Advantage of VoIP Illinois
Related Local Events
The CIO Agenda - 2010 and Beyond
Dates: 11/5/2009 - 11/5/2009
Location: The Donald E. Stephens Convention Center
Rosemont, IL
View Details

Information Systems Governance Strategies
Dates: 9/24/2009 - 9/24/2009
Location: The Donald E. Stephens Convention Center
Rosemont, IL
View Details

GO SECURE 2009
Dates: 9/17/2009 - 9/17/2009
Location: The Peoria Castle Lodge
Peoria, IL
View Details

WiMAX World Americas
Dates: 9/15/2009 - 9/17/2009
Location: McCormick Place
Chicago, IL
View Details

ANNUAL LEAN SIX SIGMA IN SERVICE & TRANSACTIONAL ENVIRONMENTS CONFERENCE
Dates: 8/18/2009 - 8/23/2009
Location: Chicago Hilton
Chicago, IL
View Details

Rss   Delicious   Digg   Add To My Yahoo   Add To My Google   Bookmark   Search Plugin

Topics:
Advertising Family Home Services Real Estate Resources
Business Services Fashion Industrial Goods & Services Retail & Consumer Services
Career Financial Services Insurance Software
Cars Food & Beverage Internet Technology
Computer Hardware Franchise Legal Telecommunications
Construction Health Miscellaneous Trade Shows
Education Holidays Nightlife Travel
Entertainment Home Appliances Online Database Weddings
Environmental Home Electronics Pets World History