Securing SCADA and DCS Systems Inside Refineries and Pipelines New Jersey

While oil and gas companies have made strides to protect the physical security of their plants and infrastructure, two factors have lately moved control system security higher up on the agenda: Supervisory control and data acquisition (SCADA) systems and Distributed Control Systems (DCSs) used within refineries and to control pipelines are vulnerable to cyber threats.

Local Companies

Knowledgeguard Inc
856-309-1177
703 White Horse Road
Voorhees, NJ
IND Corporation
973-227-5020
14 Walsh Drive
Parsippany, NJ
ELWC
(908) 212-7873
PO Box 483
Piscataway, NJ
Adachi Computech Solutions
1-866-607-2321
76 Clifton St
Edison, NJ
Sagemark Consulting
(732) 530-9494
680 Branch Ave
Little Silver, NJ
Boyd Company
(609) 452-0077
Princeton, NJ
Chemlogix
(609) 967-7258
380 24th St
Avalon, NJ
Express Services
(908) 654-6010
200 Sheffield St
Mountainside, NJ
Comcap Corporation
(973) 812-7644
Little Falls, NJ
Sahaba Mangement Llc
(856) 614-1060
Camden, NJ



By Tom Schmidt

While oil and gas companies have made strides to protect the physical security of their plants and infrastructure, two factors have lately moved control system security higher up on the agenda:

  • Supervisory control and data acquisition (SCADA) systems and Distributed Control Systems (DCSs) used within refineries and to control pipelines are vulnerable to cyber threats.
  • The explosive nature of these commodities makes this industry's infrastructure an attractive target.

But while progress has been made to enhance cyber security, oil and gas companies still face some steep challenges, including the need to connect once isolated SCADA and DCSs with business systems and networks; clashing organizational priorities; and the lack of a mandate to comply with cyber security-related standards.

This article examines today's principal SCADA and DCS vulnerabilities before proposing some effective practices that oil and gas companies can adopt to improve the security of these critical systems.

SCADA and DCS vulnerabilities

The oil and gas sector depends upon a vast and highly decentralized infrastructure, consisting of an extensive network of roughly 150 refineries, 200,000 miles of oil pipelines, and 2,000,000 miles of gas pipelines. SCADA and DCS systems used within refineries and to control pipelines form the backbone of most oil and gas industry operations in the United States and worldwide today. To supply corporate decision makers with crucial data, these organizations are increasingly integrating their SCADA and DCS systems with corporate business systems.

It is this development that has raised concerns among security professionals. These systems were originally built for efficiency and reliability -- and often deployed with security features not being implemented because they were intended to be isolated from the outside world. Integrating SCADA and DCS systems with corporate business systems exposes these control systems to cyber threats introduced through the corporate network.

Likewise, many of these control systems use the Modbus protocol to support communications with electronic flow measurement (EFM) devices and remote terminal units (RTUs) scattered throughout the thousands of miles of pipelines. While this interconnectedness provides corporate decision makers with access to critical data, it also leads to widespread availability of information about these control systems and their vulnerabilities.
 
At the same time, partner data sharing (a result of industry mergers and partnership formation) has fostered real-time data-sharing between DCS systems and corporate networks between separate corporate entities. These interconnections must be secured against cyber threats.
 
And some of those threats have been successful. For example, according to FBI director Robert Mueller, hackers in Russia were able to gain control of a gas pipeline for 24 hours by penetrating electronic control systems.

Finally, the nonstop operational requirement of SCADA and DCS systems complicates security implementation and testing because systems can never be taken offline. Many organizations maintain 24x7 operations via remote system access, which introduces additional vulnerability points.

Practices for securing SCADA and DCS systems

Oil and gas companies can benefit from proven practices to safeguard their SCADA and DCS systems within refineries and pipelines. Moreover, the following four-step cyber security process aligns with the recommendations put forth in the Security Guidelines for the Petroleum Industry, published by the American Petroleum Institute in April 2005.

  • Step 1: Security Assessment This includes assessing a company's awareness of electronic threats before they reach the organization, identifying possible regulatory compliance issues, assessing the effectiveness of security and administration tools, and manually validating these security concerns using penetration testing methods.
  • Step 2: Security Policy Creation and Enforcement Here companies establish who is authorized to gain access to what information, as well as who is authorized to perform what functions. To ensure an effective policy, organizations must continually measure compliance with its policies and procedures.
  • Step 3: Security Measure Deployment To combat ever-evolving cyber threats, organizations must utilize proven security technologies and procedures, and that means recognizing that perimeter firewalls alone offer insufficient protection. An Intrusion Detection System (IDS) featuring both protocol anomaly and signature-based detection techniques is a vital element of modern network security. Oil and gas companies must also address inadequately protected networked, mobile, and remote users, protecting them with antivirus, IDS, and personal firewalls. This step also involves implementing recovery procedures and tools to be used in the event that an attack eludes other security measures.
  • Step 4: Security Monitoring and Management This involves real-time, 24/7 monitoring and management of security information resources to prevent disruptions and minimize downtime. And that poses a real challenge. Pipeline and refinery control center personnel must focus on their system operation duties and aren't typically trained in the nuances of effective security monitoring and management. As a result, many organizations are using third parties that have experience providing management and monitoring of security devices. Also, early warning services can provide customized alerts of worldwide cyber attacks -- as well as countermeasures to prevent attacks before they occur.

Conclusion

The increasingly interconnected nature of SCADA, DCS, corporate networks, remote workers, and other networks means the industry must move to enhance security of this critical infrastructure -- in spite of a current lack of industry-mandated cyber security regulations.
 
The good news is that a growing number of technologies and services are available to help companies secure not only their SCADA and DCS networks but also the networks to which they are connected. For oil and gas companies looking to protect their refineries and pipelines from constantly evolving cyber threats, that can mean the difference between a costly disruption and business continuity.

Tom Schmidt writes frequently about information security topics. He has more than 15 years' experience as a writer and editor in high-tech publishing.

Featured Local Company

Knowledgeguard Inc

856-309-1177
703 White Horse Road
Voorhees, NJ
http://www.knowledgeguard.com

Related Articles
- Protection for Small Companies New Jersey
In an era when growth is critical to survival, small and midsize financial institutions are under pressure to provide greater access to valuable information assets across an expanding universe of customers, content providers, employees, and access devices.
- IP PBX VoIP Phone Systems New Jersey
- Hosted VoIP Systems New Jersey
- The DoD's IT Dilemma New Jersey
- Automating NERC CIP Compliance New Jersey
- Looking Out for Insider Threats New Jersey
- The Strategic Advantage of VoIP New Jersey
- Electric Utilities: Securing the Perimeter New Jersey
- Effective Filing System New Jersey
- Stepping Up to Security Compliance New Jersey
Regional Articles
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Absecon NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Asbury Park NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Atlantic City NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Barnegat NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Basking Ridge NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Bayonne NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Bayville NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Belle Mead NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Belleville NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Belmar NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Bergenfield NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Blackwood NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Bloomfield NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Boonton NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Bordentown NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Brick NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Bridgeton NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Bridgewater NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Browns Mills NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Burlington NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Caldwell NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Camden NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Cape May Court House NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Cape May NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Carteret NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Cherry Hill NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Clark NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Clementon NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Cliffside Park NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Clifton NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Collingswood NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Colonia NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Cranford NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Denville NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Deptford NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Dumont NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines East Brunswick NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines East Orange NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Eatontown NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Edison NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Egg Harbor Township NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Elizabeth NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Englewood NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Englishtown NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Ewing NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Fair Lawn NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Flemington NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Forked River NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Fort Lee NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Freehold NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Garfield NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Glassboro NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Hackensack NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Hackettstown NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Haddon Township NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Haddonfield NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Haledon NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Hammonton NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Hazlet NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Hightstown NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Hillside NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Hoboken NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Holmdel NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Howell NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Irvington NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Iselin NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Jackson NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Jersey City NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Kearny NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Keyport NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Lakehurst NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Lakewood NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Linden NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Livingston NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Long Branch NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Lyndhurst NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Madison NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Mahwah NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Manahawkin NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Manchester Township NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Maple Shade NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Maplewood NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Marlboro NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Marlton NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Matawan NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Mays Landing NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Medford NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Merchantville NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Metuchen NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Middletown NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Millville NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Monroe Township NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Montclair NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Moorestown NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Morganville NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Morris Plains NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Morristown NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Mount Holly NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Mount Laurel NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Neptune NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines New Brunswick NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Newark NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Newton NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines North Arlington NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines North Bergen NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines North Brunswick NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Nutley NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Ocean City NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Old Bridge NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Orange NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Palisades Park NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Paramus NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Parlin NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Parsippany NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Passaic NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Paterson NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Pennsauken NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Perth Amboy NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Phillipsburg NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Piscataway NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Plainfield NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Plainsboro NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Pleasantville NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Point Pleasant Beach NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Princeton Junction NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Princeton NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Rahway NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Ramsey NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Red Bank NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Rockaway NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Rutherford NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Sayreville NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Scotch Plains NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Secaucus NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Sewell NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Sicklerville NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Somerset NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Somerville NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines South Amboy NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines South Orange NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines South Plainfield NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines South River NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Summit NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Teaneck NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Toms River NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Trenton NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Tuckerton NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Union City NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Union NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Vincentown NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Vineland NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Voorhees NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Wayne NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines West Milford NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines West New York NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines West Orange NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Westfield NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Westwood NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Williamstown NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Willingboro NJ
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Wyckoff NJ
Related Articles
- The DoD's IT Dilemma New Jersey
A resilient infrastructure approach recognizes that information security and information availability are much more effective when addressed together instead of separately. In this approach, IT and security groups within the Department of Defense would use the same tools, speak the same language, and work from the same base of information no matter where they are located.
- Protection for Small Companies New Jersey
- Looking Out for Insider Threats New Jersey
- The Strategic Advantage of VoIP New Jersey
- Electric Utilities: Securing the Perimeter New Jersey
- Hosted VoIP Systems New Jersey
- Automating NERC CIP Compliance New Jersey
- IP PBX VoIP Phone Systems New Jersey
- Stepping Up to Security Compliance New Jersey
- Effective Filing System New Jersey

Rss   Delicious   Digg   Add To My Yahoo   Add To My Google   Bookmark   Search Plugin

Topics:
Advertising Family Home Services Real Estate Resources
Business Services Fashion Industrial Goods & Services Retail & Consumer Services
Career Financial Services Insurance Software
Cars Food & Beverage Internet Technology
Computer Hardware Franchise Legal Telecommunications
Construction Health Miscellaneous Trade Shows
Education Holidays Nightlife Travel
Entertainment Home Appliances Online Database Weddings
Environmental Home Electronics Pets World History