Securing SCADA and DCS Systems Inside Refineries and Pipelines Maryland

While oil and gas companies have made strides to protect the physical security of their plants and infrastructure, two factors have lately moved control system security higher up on the agenda: Supervisory control and data acquisition (SCADA) systems and Distributed Control Systems (DCSs) used within refineries and to control pipelines are vulnerable to cyber threats.

Local Companies

J Timothy Sprehe Dba Sprehe Information Mgmt & Assoc
(301) 657-2481
5504 Surrey St
Chevy Chase, MD
Capitol Financial Services
(410) 641-8229
6 Warbler Ct
Ocean Pines, MD
The Business Side
(301) 854-5145
14700 Frederick Rd
Cooksville, MD
Focus Technology Consulting
(240) 683-3925
1355 Piccard Dr
Rockville, MD
Technical Resources Inc
(301) 695-4968
5712 Industry Ln
Frederick, MD
Dale Carnegie Training
(410) 560-2188
2331 York Rd Ste 202
Lutherville Timonium, MD
The Ken Blanchard Company
(410) 988-8129
Dayton, MD
P L F Ilc
(301) 663-3326
1791 Amber Ct
Frederick, MD
Century Pool Management Inc
(301) 798-0077
4937D Green Valley Rd
Monrovia, MD
Lenkin Company Management
(202) 466-8475
1818 N St
Bethesda, MD



By Tom Schmidt

While oil and gas companies have made strides to protect the physical security of their plants and infrastructure, two factors have lately moved control system security higher up on the agenda:

  • Supervisory control and data acquisition (SCADA) systems and Distributed Control Systems (DCSs) used within refineries and to control pipelines are vulnerable to cyber threats.
  • The explosive nature of these commodities makes this industry's infrastructure an attractive target.

But while progress has been made to enhance cyber security, oil and gas companies still face some steep challenges, including the need to connect once isolated SCADA and DCSs with business systems and networks; clashing organizational priorities; and the lack of a mandate to comply with cyber security-related standards.

This article examines today's principal SCADA and DCS vulnerabilities before proposing some effective practices that oil and gas companies can adopt to improve the security of these critical systems.

SCADA and DCS vulnerabilities

The oil and gas sector depends upon a vast and highly decentralized infrastructure, consisting of an extensive network of roughly 150 refineries, 200,000 miles of oil pipelines, and 2,000,000 miles of gas pipelines. SCADA and DCS systems used within refineries and to control pipelines form the backbone of most oil and gas industry operations in the United States and worldwide today. To supply corporate decision makers with crucial data, these organizations are increasingly integrating their SCADA and DCS systems with corporate business systems.

It is this development that has raised concerns among security professionals. These systems were originally built for efficiency and reliability -- and often deployed with security features not being implemented because they were intended to be isolated from the outside world. Integrating SCADA and DCS systems with corporate business systems exposes these control systems to cyber threats introduced through the corporate network.

Likewise, many of these control systems use the Modbus protocol to support communications with electronic flow measurement (EFM) devices and remote terminal units (RTUs) scattered throughout the thousands of miles of pipelines. While this interconnectedness provides corporate decision makers with access to critical data, it also leads to widespread availability of information about these control systems and their vulnerabilities.
 
At the same time, partner data sharing (a result of industry mergers and partnership formation) has fostered real-time data-sharing between DCS systems and corporate networks between separate corporate entities. These interconnections must be secured against cyber threats.
 
And some of those threats have been successful. For example, according to FBI director Robert Mueller, hackers in Russia were able to gain control of a gas pipeline for 24 hours by penetrating electronic control systems.

Finally, the nonstop operational requirement of SCADA and DCS systems complicates security implementation and testing because systems can never be taken offline. Many organizations maintain 24x7 operations via remote system access, which introduces additional vulnerability points.

Practices for securing SCADA and DCS systems

Oil and gas companies can benefit from proven practices to safeguard their SCADA and DCS systems within refineries and pipelines. Moreover, the following four-step cyber security process aligns with the recommendations put forth in the Security Guidelines for the Petroleum Industry, published by the American Petroleum Institute in April 2005.

  • Step 1: Security Assessment This includes assessing a company's awareness of electronic threats before they reach the organization, identifying possible regulatory compliance issues, assessing the effectiveness of security and administration tools, and manually validating these security concerns using penetration testing methods.
  • Step 2: Security Policy Creation and Enforcement Here companies establish who is authorized to gain access to what information, as well as who is authorized to perform what functions. To ensure an effective policy, organizations must continually measure compliance with its policies and procedures.
  • Step 3: Security Measure Deployment To combat ever-evolving cyber threats, organizations must utilize proven security technologies and procedures, and that means recognizing that perimeter firewalls alone offer insufficient protection. An Intrusion Detection System (IDS) featuring both protocol anomaly and signature-based detection techniques is a vital element of modern network security. Oil and gas companies must also address inadequately protected networked, mobile, and remote users, protecting them with antivirus, IDS, and personal firewalls. This step also involves implementing recovery procedures and tools to be used in the event that an attack eludes other security measures.
  • Step 4: Security Monitoring and Management This involves real-time, 24/7 monitoring and management of security information resources to prevent disruptions and minimize downtime. And that poses a real challenge. Pipeline and refinery control center personnel must focus on their system operation duties and aren't typically trained in the nuances of effective security monitoring and management. As a result, many organizations are using third parties that have experience providing management and monitoring of security devices. Also, early warning services can provide customized alerts of worldwide cyber attacks -- as well as countermeasures to prevent attacks before they occur.

Conclusion

The increasingly interconnected nature of SCADA, DCS, corporate networks, remote workers, and other networks means the industry must move to enhance security of this critical infrastructure -- in spite of a current lack of industry-mandated cyber security regulations.
 
The good news is that a growing number of technologies and services are available to help companies secure not only their SCADA and DCS networks but also the networks to which they are connected. For oil and gas companies looking to protect their refineries and pipelines from constantly evolving cyber threats, that can mean the difference between a costly disruption and business continuity.

Tom Schmidt writes frequently about information security topics. He has more than 15 years' experience as a writer and editor in high-tech publishing.

Related Articles
- The Strategic Advantage of VoIP Maryland
The benefits of VoIP include the obvious factor of its much reduced cost, but it is also a very flexible system that allows for the creation of new services to streamline costs and offer better services to customers, creating strategic tools to better compete.
- The DoD's IT Dilemma Maryland
- Protection for Small Companies Maryland
- Looking Out for Insider Threats Maryland
- Effective Filing System Maryland
- Automating NERC CIP Compliance Maryland
- IP PBX VoIP Phone Systems Maryland
- Stepping Up to Security Compliance Maryland
- Hosted VoIP Systems Maryland
- Electric Utilities: Securing the Perimeter Maryland
Regional Articles
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Annapolis MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Baltimore MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Bel Air MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Beltsville MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Bethesda MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Bowie MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Brooklyn MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Capitol Heights MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Catonsville MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Chevy Chase MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Clinton MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Cockeysville MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines College Park MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Columbia MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Crofton MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Cumberland MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Derwood MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines District Heights MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Dundalk MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Edgewood MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Elkridge MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Elkton MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Ellicott City MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Essex MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Forest Hill MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Fort Washington MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Frederick MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Frostburg MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Gaithersburg MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Germantown MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Glen Burnie MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Greenbelt MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Gwynn Oak MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Hagerstown MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Halethorpe MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Havre De Grace MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Hyattsville MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Jessup MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Joppa MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Kensington MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines La Plata MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Lanham MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Laurel MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Lexington Park MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Lusby MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Lutherville Timonium MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Middle River MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Millersville MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Montgomery Village MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Mount Airy MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Nottingham MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Odenton MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Olney MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Owings Mills MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Oxon Hill MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Parkville MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Pasadena MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Pikesville MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Potomac MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Randallstown MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Reisterstown MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Rockville MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Rosedale MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Salisbury MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Severn MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Severna Park MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Silver Spring MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Suitland MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Sykesville MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Takoma Park MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Temple Hills MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Towson MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Upper Marlboro MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Waldorf MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Westminster MD
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Windsor Mill MD
Related Articles
- Looking Out for Insider Threats Maryland
If the topic of protecting against insider threats makes many a government IT worker shudder, it's for good reason. Besides the millions of people employed by government agencies, the number of federal civil servants is on the rise, as is the number of people working for government-funded contractors and organizations that receive government grants. Add to that the number of postal workers and military personnel, and the "true size" of the federal government is around 14.6 million employees, according to Paul C. Light, government professor at New York University.
- Automating NERC CIP Compliance Maryland
- Hosted VoIP Systems Maryland
- IP PBX VoIP Phone Systems Maryland
- Protection for Small Companies Maryland
- Electric Utilities: Securing the Perimeter Maryland
- Stepping Up to Security Compliance Maryland
- The DoD's IT Dilemma Maryland
- The Strategic Advantage of VoIP Maryland
- Effective Filing System Maryland
Related Local Events
ICC - International Code Council Annual Conference
Dates: 11/1/2009 - 11/4/2009
Location: Baltimore Convention Center
Baltimore, MD
View Details

MID-ATLANTIC ALL HAZARDS FORUM & EXHIBITION 2009
Dates: 11/1/2009 - 11/1/2009
Location: Baltimore Convention Center
Baltimore, MD
View Details

Gartner IT Security Summit Washington
Dates: 6/27/2009 - 6/28/2009
Location: Gaylord National Hotel & Convention Center
National Harbor, MD
View Details

First Look: Windows Vista for IT Professionals
Dates: 6/11/2009 - 6/11/2009
Location: Source - Hunt Valley
Hunt Valley, MD
View Details
Rate Article
     
Articles Insider

Rss   Delicious   Digg   Add To My Yahoo   Add To My Google   Bookmark   Search Plugin

Topics:
Advertising Family Home Services Real Estate Resources
Business Services Fashion Industrial Goods & Services Retail & Consumer Services
Career Financial Services Insurance Software
Cars Food & Beverage Internet Technology
Computer Hardware Franchise Legal Telecommunications
Construction Health Miscellaneous Trade Shows
Education Holidays Nightlife Travel
Entertainment Home Appliances Online Database Weddings
Environmental Home Electronics Pets World History