Securing SCADA and DCS Systems Inside Refineries and Pipelines Massachusetts

While oil and gas companies have made strides to protect the physical security of their plants and infrastructure, two factors have lately moved control system security higher up on the agenda: Supervisory control and data acquisition (SCADA) systems and Distributed Control Systems (DCSs) used within refineries and to control pipelines are vulnerable to cyber threats.

Local Companies

Consultants - Information Security
(781)6411511
391 Totten Pond Road, Suite 101
Waltham, MA
Automation Concetps & Technologies, Inc.
508.285.5080
91 Main Street
Marlborough, MA
EMC Corporation
(508) 435-1000
176 South Street
Hopkinton, MA
Cisco
(978) 244-8000
1414 Massachusetts Avenue
Boxborough, MA
Globoforce
(508) 898-9988
112 Turnpike Rd
Westborough, MA
Indirect Consulting Services
(781) 826-0775
64 Schoosett St
Pembroke, MA
Outward Insights
(781) 359-9700
1 Mountain Rd
Burlington, MA
Turnaround Management Association of NE
(978) 462-2665
82 Water St
Newburyport, MA
Cape Cod Attractions
(508) 240-6617
Orleans, MA
Cambridge Planning & Analytics Inc
(617) 576-6465
87 Blanchard Rd
Cambridge, MA



By Tom Schmidt

While oil and gas companies have made strides to protect the physical security of their plants and infrastructure, two factors have lately moved control system security higher up on the agenda:

  • Supervisory control and data acquisition (SCADA) systems and Distributed Control Systems (DCSs) used within refineries and to control pipelines are vulnerable to cyber threats.
  • The explosive nature of these commodities makes this industry's infrastructure an attractive target.

But while progress has been made to enhance cyber security, oil and gas companies still face some steep challenges, including the need to connect once isolated SCADA and DCSs with business systems and networks; clashing organizational priorities; and the lack of a mandate to comply with cyber security-related standards.

This article examines today's principal SCADA and DCS vulnerabilities before proposing some effective practices that oil and gas companies can adopt to improve the security of these critical systems.

SCADA and DCS vulnerabilities

The oil and gas sector depends upon a vast and highly decentralized infrastructure, consisting of an extensive network of roughly 150 refineries, 200,000 miles of oil pipelines, and 2,000,000 miles of gas pipelines. SCADA and DCS systems used within refineries and to control pipelines form the backbone of most oil and gas industry operations in the United States and worldwide today. To supply corporate decision makers with crucial data, these organizations are increasingly integrating their SCADA and DCS systems with corporate business systems.

It is this development that has raised concerns among security professionals. These systems were originally built for efficiency and reliability -- and often deployed with security features not being implemented because they were intended to be isolated from the outside world. Integrating SCADA and DCS systems with corporate business systems exposes these control systems to cyber threats introduced through the corporate network.

Likewise, many of these control systems use the Modbus protocol to support communications with electronic flow measurement (EFM) devices and remote terminal units (RTUs) scattered throughout the thousands of miles of pipelines. While this interconnectedness provides corporate decision makers with access to critical data, it also leads to widespread availability of information about these control systems and their vulnerabilities.
 
At the same time, partner data sharing (a result of industry mergers and partnership formation) has fostered real-time data-sharing between DCS systems and corporate networks between separate corporate entities. These interconnections must be secured against cyber threats.
 
And some of those threats have been successful. For example, according to FBI director Robert Mueller, hackers in Russia were able to gain control of a gas pipeline for 24 hours by penetrating electronic control systems.

Finally, the nonstop operational requirement of SCADA and DCS systems complicates security implementation and testing because systems can never be taken offline. Many organizations maintain 24x7 operations via remote system access, which introduces additional vulnerability points.

Practices for securing SCADA and DCS systems

Oil and gas companies can benefit from proven practices to safeguard their SCADA and DCS systems within refineries and pipelines. Moreover, the following four-step cyber security process aligns with the recommendations put forth in the Security Guidelines for the Petroleum Industry, published by the American Petroleum Institute in April 2005.

  • Step 1: Security Assessment This includes assessing a company's awareness of electronic threats before they reach the organization, identifying possible regulatory compliance issues, assessing the effectiveness of security and administration tools, and manually validating these security concerns using penetration testing methods.
  • Step 2: Security Policy Creation and Enforcement Here companies establish who is authorized to gain access to what information, as well as who is authorized to perform what functions. To ensure an effective policy, organizations must continually measure compliance with its policies and procedures.
  • Step 3: Security Measure Deployment To combat ever-evolving cyber threats, organizations must utilize proven security technologies and procedures, and that means recognizing that perimeter firewalls alone offer insufficient protection. An Intrusion Detection System (IDS) featuring both protocol anomaly and signature-based detection techniques is a vital element of modern network security. Oil and gas companies must also address inadequately protected networked, mobile, and remote users, protecting them with antivirus, IDS, and personal firewalls. This step also involves implementing recovery procedures and tools to be used in the event that an attack eludes other security measures.
  • Step 4: Security Monitoring and Management This involves real-time, 24/7 monitoring and management of security information resources to prevent disruptions and minimize downtime. And that poses a real challenge. Pipeline and refinery control center personnel must focus on their system operation duties and aren't typically trained in the nuances of effective security monitoring and management. As a result, many organizations are using third parties that have experience providing management and monitoring of security devices. Also, early warning services can provide customized alerts of worldwide cyber attacks -- as well as countermeasures to prevent attacks before they occur.

Conclusion

The increasingly interconnected nature of SCADA, DCS, corporate networks, remote workers, and other networks means the industry must move to enhance security of this critical infrastructure -- in spite of a current lack of industry-mandated cyber security regulations.
 
The good news is that a growing number of technologies and services are available to help companies secure not only their SCADA and DCS networks but also the networks to which they are connected. For oil and gas companies looking to protect their refineries and pipelines from constantly evolving cyber threats, that can mean the difference between a costly disruption and business continuity.

Tom Schmidt writes frequently about information security topics. He has more than 15 years' experience as a writer and editor in high-tech publishing.

Featured Local Company

Consultants - Information Security

(781)6411511
391 Totten Pond Road, Suite 101
Waltham, MA

Regional Articles
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Acton MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Agawam MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Allston MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Amesbury MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Amherst MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Andover MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Arlington MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Attleboro MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Beverly MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Billerica MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Boston MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Braintree MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Bridgewater MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Brighton MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Brockton MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Brookline MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Buzzards Bay MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Cambridge MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Charlestown MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Chelmsford MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Chelsea MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Chicopee MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Danvers MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Dedham MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Dracut MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines East Falmouth MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines East Weymouth MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Easthampton MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Everett MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Fairhaven MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Fall River MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Fitchburg MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Foxboro MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Framingham MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Franklin MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Gardner MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Gloucester MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Haverhill MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Hingham MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Holyoke MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Hyannis MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Hyde Park MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Jamaica Plain MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Lawrence MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Leominster MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Lexington MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Longmeadow MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Lowell MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Ludlow MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Lynn MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Malden MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Marblehead MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Marlborough MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Mattapan MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Medford MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Melrose MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Methuen MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Middleboro MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Milford MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Milton MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Natick MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Needham MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines New Bedford MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Newburyport MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Newton Center MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines North Adams MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines North Andover MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines North Attleboro MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines North Dartmouth MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Northampton MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Norton MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Norwood MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Peabody MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Pittsfield MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Plymouth MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Quincy MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Randolph MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Revere MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Roslindale MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Salem MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Saugus MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Scituate MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Shrewsbury MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Somerville MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines South Hadley MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines South Weymouth MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Southbridge MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Springfield MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Stoneham MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Stoughton MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Swampscott MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Taunton MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Tewksbury MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Walpole MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Waltham MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Watertown MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines West Roxbury MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines West Springfield MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Westborough MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Westfield MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Westford MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Weymouth MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Winthrop MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Woburn MA
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Worcester MA
Related Articles

Rss   Delicious   Digg   Add To My Yahoo   Add To My Google   Bookmark   Search Plugin

Topics:
Advertising Family Home Services Real Estate Resources
Business Services Fashion Industrial Goods & Services Retail & Consumer Services
Career Financial Services Insurance Software
Cars Food & Beverage Internet Technology
Computer Hardware Franchise Legal Telecommunications
Construction Health Miscellaneous Trade Shows
Education Holidays Nightlife Travel
Entertainment Home Appliances Online Database Weddings
Environmental Home Electronics Pets World History