Securing SCADA and DCS Systems Inside Refineries and Pipelines Ohio

While oil and gas companies have made strides to protect the physical security of their plants and infrastructure, two factors have lately moved control system security higher up on the agenda: Supervisory control and data acquisition (SCADA) systems and Distributed Control Systems (DCSs) used within refineries and to control pipelines are vulnerable to cyber threats.

Local Companies

NovaCoast Inc.
(513) 583-8625
600 West Loveland Avenue
Loveland, OH
Advanced Computer Graphics Inc.
(513) 936-5060
10895 Indeco Drive
Cincinnati, OH
NextStep Networking Inc.
(513) 792-3400
10865 Indeco Drive
Cincinnati, OH
Data Processing Sciences Corp.
(513) 791-7100
10810 Kenwood Road
Cincinnati, OH
Solutions Guided Technologies, Inc.
(513) 753-3323
33 East Main Street
Amelia, OH
SCS Technologies
(513) 563-6400
337 West Benson Street
Reading, OH
Zipscene
(513) 477-9090
2118 Saint James Avenue
Cincinnati, OH
Connective Computing Inc.
(513) 475-5660
2200 Victory Parkway
Cincinnati, OH
Apachi Networks
(513) 939-1111
4710 J Interstate Drive
Cincinnati, OH
D L P Technologies Inc.
(513) 232-7791
8080 Reading Road
Cincinnati, OH

 



By Tom Schmidt

While oil and gas companies have made strides to protect the physical security of their plants and infrastructure, two factors have lately moved control system security higher up on the agenda:

  • Supervisory control and data acquisition (SCADA) systems and Distributed Control Systems (DCSs) used within refineries and to control pipelines are vulnerable to cyber threats.
  • The explosive nature of these commodities makes this industry's infrastructure an attractive target.

But while progress has been made to enhance cyber security, oil and gas companies still face some steep challenges, including the need to connect once isolated SCADA and DCSs with business systems and networks; clashing organizational priorities; and the lack of a mandate to comply with cyber security-related standards.

This article examines today's principal SCADA and DCS vulnerabilities before proposing some effective practices that oil and gas companies can adopt to improve the security of these critical systems.

SCADA and DCS vulnerabilities

The oil and gas sector depends upon a vast and highly decentralized infrastructure, consisting of an extensive network of roughly 150 refineries, 200,000 miles of oil pipelines, and 2,000,000 miles of gas pipelines. SCADA and DCS systems used within refineries and to control pipelines form the backbone of most oil and gas industry operations in the United States and worldwide today. To supply corporate decision makers with crucial data, these organizations are increasingly integrating their SCADA and DCS systems with corporate business systems.

It is this development that has raised concerns among security professionals. These systems were originally built for efficiency and reliability -- and often deployed with security features not being implemented because they were intended to be isolated from the outside world. Integrating SCADA and DCS systems with corporate business systems exposes these control systems to cyber threats introduced through the corporate network.

Likewise, many of these control systems use the Modbus protocol to support communications with electronic flow measurement (EFM) devices and remote terminal units (RTUs) scattered throughout the thousands of miles of pipelines. While this interconnectedness provides corporate decision makers with access to critical data, it also leads to widespread availability of information about these control systems and their vulnerabilities.
 
At the same time, partner data sharing (a result of industry mergers and partnership formation) has fostered real-time data-sharing between DCS systems and corporate networks between separate corporate entities. These interconnections must be secured against cyber threats.
 
And some of those threats have been successful. For example, according to FBI director Robert Mueller, hackers in Russia were able to gain control of a gas pipeline for 24 hours by penetrating electronic control systems.

Finally, the nonstop operational requirement of SCADA and DCS systems complicates security implementation and testing because systems can never be taken offline. Many organizations maintain 24x7 operations via remote system access, which introduces additional vulnerability points.

Practices for securing SCADA and DCS systems

Oil and gas companies can benefit from proven practices to safeguard their SCADA and DCS systems within refineries and pipelines. Moreover, the following four-step cyber security process aligns with the recommendations put forth in the Security Guidelines for the Petroleum Industry, published by the American Petroleum Institute in April 2005.

  • Step 1: Security Assessment This includes assessing a company's awareness of electronic threats before they reach the organization, identifying possible regulatory compliance issues, assessing the effectiveness of security and administration tools, and manually validating these security concerns using penetration testing methods.
  • Step 2: Security Policy Creation and Enforcement Here companies establish who is authorized to gain access to what information, as well as who is authorized to perform what functions. To ensure an effective policy, organizations must continually measure compliance with its policies and procedures.
  • Step 3: Security Measure Deployment To combat ever-evolving cyber threats, organizations must utilize proven security technologies and procedures, and that means recognizing that perimeter firewalls alone offer insufficient protection. An Intrusion Detection System (IDS) featuring both protocol anomaly and signature-based detection techniques is a vital element of modern network security. Oil and gas companies must also address inadequately protected networked, mobile, and remote users, protecting them with antivirus, IDS, and personal firewalls. This step also involves implementing recovery procedures and tools to be used in the event that an attack eludes other security measures.
  • Step 4: Security Monitoring and Management This involves real-time, 24/7 monitoring and management of security information resources to prevent disruptions and minimize downtime. And that poses a real challenge. Pipeline and refinery control center personnel must focus on their system operation duties and aren't typically trained in the nuances of effective security monitoring and management. As a result, many organizations are using third parties that have experience providing management and monitoring of security devices. Also, early warning services can provide customized alerts of worldwide cyber attacks -- as well as countermeasures to prevent attacks before they occur.

Conclusion

The increasingly interconnected nature of SCADA, DCS, corporate networks, remote workers, and other networks means the industry must move to enhance security of this critical infrastructure -- in spite of a current lack of industry-mandated cyber security regulations.
 
The good news is that a growing number of technologies and services are available to help companies secure not only their SCADA and DCS networks but also the networks to which they are connected. For oil and gas companies looking to protect their refineries and pipelines from constantly evolving cyber threats, that can mean the difference between a costly disruption and business continuity.

Tom Schmidt writes frequently about information security topics. He has more than 15 years' experience as a writer and editor in high-tech publishing.

Featured Local Company

NovaCoast Inc.

(513) 583-8625
600 West Loveland Avenue
Loveland, OH

Related Articles
- Looking Out for Insider Threats Ohio
If the topic of protecting against insider threats makes many a government IT worker shudder, it's for good reason. Besides the millions of people employed by government agencies, the number of federal civil servants is on the rise, as is the number of people working for government-funded contractors and organizations that receive government grants. Add to that the number of postal workers and military personnel, and the "true size" of the federal government is around 14.6 million employees, according to Paul C. Light, government professor at New York University.
- The DoD's IT Dilemma Ohio
- Hosted VoIP Systems Ohio
- Stepping Up to Security Compliance Ohio
- Effective Filing System Ohio
- The Strategic Advantage of VoIP Ohio
- IP PBX VoIP Phone Systems Ohio
- Automating NERC CIP Compliance Ohio
- Protection for Small Companies Ohio
- Electric Utilities: Securing the Perimeter Ohio
Regional Articles
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Akron OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Alliance OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Amelia OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Ashland OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Ashtabula OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Athens OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Avon Lake OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Barberton OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Batavia OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Bay Village OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Beachwood OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Bedford OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Bellefontaine OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Bowling Green OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Broadview Heights OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Brook Park OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Brunswick OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Bucyrus OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Canal Winchester OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Canfield OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Canton OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Celina OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Chagrin Falls OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Chardon OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Chillicothe OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Cincinnati OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Circleville OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Cleveland OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Columbus OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Conneaut OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Coshocton OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Cuyahoga Falls OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Dayton OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Defiance OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Delaware OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Dublin OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines East Liverpool OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Eastlake OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Eaton OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Elyria OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Euclid OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Fairborn OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Fairfield OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Findlay OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Fostoria OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Franklin OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Fremont OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Galion OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Gallipolis OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Galloway OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Girard OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Grove City OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Hamilton OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Heath OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Hilliard OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Hubbard OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Ironton OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Kent OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Lakewood OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Lancaster OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Lebanon OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Lima OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Lorain OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Loveland OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Madison OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Maineville OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Mansfield OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Maple Heights OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Marion OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Marysville OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Mason OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Massillon OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Maumee OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Medina OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Mentor OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Miamisburg OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Middletown OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Milford OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Millersburg OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Mount Vernon OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Napoleon OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines New Carlisle OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines New Philadelphia OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Newark OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines North Olmsted OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines North Ridgeville OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines North Royalton OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Olmsted Falls OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Oregon OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Oxford OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Painesville OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Pataskala OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Perrysburg OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Pickerington OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Piqua OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Portsmouth OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Ravenna OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Reynoldsburg OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Rocky River OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Salem OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Sandusky OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Sidney OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Solon OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Springboro OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Springfield OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Steubenville OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Stow OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Strongsville OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Sylvania OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Tallmadge OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Tiffin OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Tipp City OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Toledo OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Troy OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Twinsburg OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Van Wert OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Vandalia OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Vermilion OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Wadsworth OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Wapakoneta OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Warren OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Washington Court House OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines West Chester OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Westerville OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Westlake OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Wickliffe OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Willoughby OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Wooster OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Xenia OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Youngstown OH
- Securing SCADA and DCS Systems Inside Refineries and Pipelines Zanesville OH
Related Articles
- Electric Utilities: Securing the Perimeter Ohio
As part of their effort to meet pending NERC CIP compliance requirements, and to mitigate the risk of potential service disruptions, electric utility companies would do well to follow the perimeter security best practices outlined in this article.
- The Strategic Advantage of VoIP Ohio
- Looking Out for Insider Threats Ohio
- Effective Filing System Ohio
- Protection for Small Companies Ohio
- IP PBX VoIP Phone Systems Ohio
- Hosted VoIP Systems Ohio
- The DoD's IT Dilemma Ohio
- Stepping Up to Security Compliance Ohio
- Automating NERC CIP Compliance Ohio

Rss   Delicious   Digg   Add To My Yahoo   Add To My Google   Bookmark   Search Plugin

Topics:
Advertising Family Home Services Real Estate Resources
Business Services Fashion Industrial Goods & Services Retail & Consumer Services
Career Financial Services Insurance Software
Cars Food & Beverage Internet Technology
Computer Hardware Franchise Legal Telecommunications
Construction Health Miscellaneous Trade Shows
Education Holidays Nightlife Travel
Entertainment Home Appliances Online Database Weddings
Environmental Home Electronics Pets World History