As ADEO, we conduct Cyber Security Analysis and Penetration Testing studies for ICS/SCADA systems, in which we primarily determine the security status of existing systems and offer solutions for improvement.
In line with the needs of our customers and the regulations to which they are subject it is possible to choose from the following services.
Segmentation Analysis
In order to reduce the impact of a possible cyber attack on the network and to realize an easier and more manageable incident response, it is possible to divide the existing network into sub-networks and monitor and control both the communication between the systems within the network and the communication between networks. In this way, a cyber-attack occurring in one part of the network or a malicious code infecting a component in that network can be prevented from spreading to other parts of the network.
For example, to a cyber-attack against a nuclear facility responded by ICS-CERT3, it was determined that the facility was not scanned for viruses before it was started to use; it was determined that malicious codes infected the system via USB memory, but as a result of the successful implementation of segmentation in the relevant facility, it was determined that the malicious code was able to infect not hundreds, but only 6 computers. This situation shows how important segmentation is in reducing the impact of a possible cyber attack.
In this part of the analysis, ADEO experts and OT and IT experts of the organization or company will conduct both passive and active analyzes on the existing network topology, including field inspections, to extract the segmentation details of the OT network. The goal is to identify possible risks associated with the segmentation and report them accordingly.
Visibility and Intrusion Detection/Prevention Capability Analysis
The most important condition to protect against modern cyber attacks and to act quickly is to actively monitor the relevant infrastructures. In this context, it is strongly recommended to monitor the following five key points:
1- Network traffic at the ingress and egress points of IP traffic in industrial control systems for the detection of abnormal and suspicious communications
2- IP traffic within the industrial control system for detection of malicious connections and content
3- Logs of malicious code protection applications to be installed on systems to detect suspicious codes and attack attempts on computers
4- Login details of the accounts used to access the systems (such as logged in system, login time and location)
5- Details of account management actions to detect access control manipulations
However, it is also recommended to monitor these points on the network with the help of an intrusion detection system (IPS). This way, it may be possible to detect a possible cyber-attack attempt in advance.
At this stage of the analysis, ADEO's expert consultants and OT and IT experts of the institution or company, both by conducting a field inspection and by performing passive and active analysis over the existing network topology, analyze the visibility level of the OT network and whether the technologies that will enable the detection of a possible cyber attack are included in the ICS / SCADA network. The findings obtained are included in detail under the relevant heading of the report.
Authentication Infrastructure Analysis
One of the most common targets of cyber attackers recently has been the username and password for authorized accounts on systems. By capturing authorized account information, attackers are able to hide their identities, act as an ordinary user in the system, and thus leave very few traces during cyber attacks. To eliminate this situation, it is recommended to use multiple authentication methods . This means that access to critical systems requires not only a username and password, but also a third piece of information. In most cases, this information is one-time generated and personalized.
In such a case, even if the username and password are captured, this third information must also be captured for unauthorized access to the systems. In addition, different accounts must be used for OT and IT networks and there must be no trust relationship between the systems where these accounts are kept (such as AD trust).
At this stage of the analysis, ADEO's expert consultants and the OT and IT experts of the institution or company perform analyses such as what are the current authentication methods used in ICS/SCADA systems, whether there is a trust relationship between IT and OT networks, and how authorized accounts are managed. The findings are detailed under the relevant heading of the report.
Patch Analysis
Outdated systems are the mostly vulnerable to cyber-attacks. Therefore, a configuration and patch management approach that allows operators to keep their systems up to date with trusted patches from trusted sources will increase the cyber security of industrial control systems.
In this approach, first of all, an inventory of all components of the system is made and the status of all components is based on a baseline. Then, it is determined which systems will be prioritized in the patching process. The most important point to be considered here is that HMI, database servers and engineering stations in PC architecture are predominantly selected as targets in cyber attacks on industrial control system infrastructures.
In the analysis studies carried out by ADEO experts , it is analyzed and reported whether an inventory is kept within the institution/company for ICS/SCADA components, how the firmware, operating system and applications in these components are updated and patch management is performed.
Remote Access Analysis
It is known that some of the cyber-attacks on industrial control systems have been carried out using methods that provide remote access to these systems. For example, for remote access to OT systems, attackers can detect external modems or applications that provide remote access placed by manufacturers or companies that support these infrastructures for remote access to OT systems and perform access via weak passwords used in these systems . However, enabling manufacturers or support companies to connect directly to the OT network via an external connection is also a risk factor.
It is very important to record what operations are performed from the manufacturer's computer, what configurations are made in order to ensure the security of OT networks.
In the analysis studies carried out by ADEO experts, it is determined how and by whom remote access to ICS/SCADA systems is performed, and whether secure remote access methods are used is analyzed. The findings are reported in detail under the relevant title.
Anti-Malware Analysis
In recent years, a large number of malicious codes have been detected targeting industrial control systems. These codes can affect the systems and interrupt or completely stop production.
The role of mobile computers in the transmission of malicious codes to industrial control systems is also quite high. Untrusted laptops without the necessary protection measures should be prevented from connecting to the control system. If possible, the organization/company itself should provide the laptops to be used in the connections to be made by the manufacturers and guarantee the security of these devices itself.
At this stage of the analysis carried out by ADEO experts, analyzes are carried out to determine whether any anti malware solution is used in ICS/SCADA systems, and if so, in which way the definitions are performed. The findings are reported in detail under the relevant heading.
Cyber Incident Monitoring and Response Analysis
The most basic requirement for detecting and preventing cyber-attacks against critical infrastructures is to monitor and respond to potential attack attempts quickly and accurately. It is important to record the log records generated by the components in the ICS/SCADA systems in a central event recording system and detect suspicious behaviors through monitoring operations. Additionally, predefined policies and procedures should be in place for who, how, and when to respond to detected security violations, and these procedures should be applied consistently in all incident responses.
At this stage, ADEO experts analyze whether any log records from EKS/SCADA systems are recorded in a central log recording system, whether there is a cyber incident response plan to be activated in a possible cyber attack on these infrastructures, and if so, whether it is operated. The results are then reported.
ICS/SCADA Penetration Tests
Companies and organizations periodically perform vulnerability scans and penetration tests to identify potential vulnerabilities in the components of their IT infrastructure and to eliminate these vulnerabilities before they can be exploited by attackers. These security scans can be performed by the companies' own security units or by third-party companies specialized in evaluating the security of system components. During these scans, network components, server components, and application components in IT systems are analyzed using industry-accepted scanning methods and tools.
A similar approach applies to components on the OT side. IP-based components of industrial control systems (Engineering Workstation, HMI, PLC, RTU, etc.) are recommended to undergo vulnerability tests periodically to detect possible security vulnerabilities.
ICS/SCADA penetration tests follow these four steps in order.
- Passive Information Gathering
- Active Information Gathering
- Vulnerability Analysis
- Penetration Testing
Passive Information Gathering
The first stage of penetration tests performed on ICS/SCADA systems involves analyzing the existing industrial control system infrastructure by copying the network traffic with the help of passive network listening devices. This enables mapping of the components, protocols used, and communication map in the infrastructure. The information obtained is then compared with the corporate inventory information obtained in the previous step to determine if there are any components in the industrial control system that the organization or company is unaware of and if the components are working as designed.
Active Information Collection
In this phase of ICS/SCADA penetration tests, the active network mapping method is used to identify the components within the scope. Using this method, information such as whether the components within the scope are live or not, which services are running on the live systems, over which ports these services communicating, and version information of the services are obtained. This information is then reported to be used in the next phase of the tests.
Vulnerability Analysis
In the next stage of the tests performed on ICS/SCADA systems, vulnerability analysis is actively performed on the industrial control system components within the scope. During the vulnerability analysis, ADEO experts test the vulnerabilities that the relevant ICS components may be exposed to from the IT world, as well as vulnerabilities that have been detected on OT components so far. The vulnerabilities detected are reported in detail, specific to the relevant ICS component, including severity level and recommended solutions to eliminate them.
Penetration Testing
In the final stage of the ICS/SCADA penetration tests, specific penetration tests are carried out on these systems. The vulnerabilities identified in the previous stage are tested and attempted to be exploited, unauthorized commands are executed on the system, and unauthorized control elements are attempted to be responded. This testing phase, which can potentially cause interruptions or serious damage to the ICS/SCADA systems, is carried out with special permission within the scope of the agreement with the organization or company. This phase of the tests is only performed with written permission.