Top Ten SCADA Security Stories of 2008

Here is our list of the top ten control system stories for 2008. 1. Vulnerabilities Discovered by Non-Control System Company Core Security and others outside of the control system community started testing freely available demo versions of control system applications...

Control System Vendor Bailout

Bill Gross has an interesting comment on Jason’s regulation post. Here is the key excerpt: To that end, you would see the virtual elimination of security flaws in systems if you target you regulation in a way that:1) Makes vendors accountable for financial...

Would the CSIS Suggestions To Obama Make a Difference?

I finally had a chance to read through the Center for Strategic and International Studies [CSIS] paper on Securing Cyberspace for the 44th Presidency. This group appears to have some clout so some of the recommendations may come to pass. Still mulling the...

More Thoughts on Application Whitelisting

Let’s get this out of the way application whitelisting does not equal perfect security. But neither do any of the other host-based security products that are competing to get on your control system servers and workstations. The bloated AV programs that do...

Finding The Fox In The Hen House – Practical Tips

Let’s face it, no matter how hard we try, or how elaborate the defense, sometimes the fox gets in the hen house (Or sometimes it just eats at McDonald’s). When I was in college taking a computer systems design course my professor stated that computer...

Honeywell C300 Controller Achilles Certified . . . with Firewall

I was first encouraged and then disappointed to read the press release announcing Honeywell’s Experion C300 Controller had achieved Achilles Level 1 Certification. I was pleased to see another vendor stepping up to get their controller protocol stack tested....

Does application whitelisting have a chance in control systems?

Last month I ran across the CoreTrace booth at the ISA Expo. Ever since that happenstance introduction, their name and the concept behind their Bouncer product keep popping up in conversations, news feeds, and even Google advertising — mostly in the context of...

Reexamining AV in the control system

Antivirus is one of those things that is a standard recommendation on almost any assessment you’ll find, but maybe this is something we need to start rethinking.  We all know that for the most part the current AV model is an arms race that’s not very...

Safer, Faster, More Accurate Nessus Scanning

Last month I mentioned briefly that there are additional functions of Nessus credential checks beyond the policy compliance plugins we’re using for Bandolier. The example in that blog post allowed you to “scan” all 65,535 ports safely and with...

A Few Ideas for a More Secure Future

Having been involved in this industry (control system security) for the last five years, a quick examination of what progress has been made in securing critical infrastructure leads me to the conclusion of “not very much”. The industry if still...