Jinnicore LogoJinnicore
Home/Cybersecurity/SCADA Security Testing & Attack Scenarios
OT & ICS Industrial DefenseMITRE ATT&CK Alignment

SCADA ATTACK SCENARIOS

SCADA or Supervisory Control and Data Acquisition mean an industrial control system for a particular procedure. We, Jinnicore have years of experience in performing evaluations on various industrial system parts; ranging from electrical utilities to chemical plants, grease refineries, etc.

Our team can identify and evaluate security OT and IT threats. We can evaluate the logical and physical security besides intrusion prevention systems, video surveillance, encryption, source code, passwords, access control, and logical security.

Architecture Model

3 Major SCADA Network Compartments

Tier I SecurityFirewall Protected

1. Enterprise Network

  • Provides Services for all enterprise business operations such as Web/Email Servers, Application Servers, Workstations, etc.
  • Regular access to the Internet or Intranet.
  • Firewall Protected. (Tier I Security)
Tier II SecurityHMI & Historian

2. Process Network

  • Consist of Master Terminal Unit, HMIs, and the Database Historian.
  • Provides an interface where the operator administers control and supervisory actions on all other subcomponents and field devices for efficient operation of the SCADA system.
  • Firewall Protected. (Tier II Security)
Tier III SecurityField Instrumentation

3. Control Network

  • Comprises the field instrumentation devices such as the Remote Telemetry Unit (RTU), the Sensors/IEDs and Actuators.
  • Modern SCADA incorporates an Intelligent Electronic Device (IED) which is an intelligent sensor capable of functioning in place of the Programmable Logic Controller (PLC)
  • Secured WAN Link. (Tier III Security)

SECURITY ISSUES OF SCADA

Component Vulnerability

MTU (Master Terminal Unit)

Outdated OS, Apps, AntiVirus; operational instability when updating; SQL Injection, Buffer Overflow, Lack of Privilege separation; Physical/Insider compromise.

Component Vulnerability

HMI (Human Machine Interface)

Input Validation Vulnerability, System Level Access default risks allowing complete control of industrial functionality.

Component Vulnerability

Database Historian

Deprecated software, lack of patch management, SQL Injection, Buffer Overflow, XSS cookie credential theft.

Component Vulnerability

Sensors & IEDs

Signal jamming/interference, Man-In-The-Middle (MiTM), Flooding, Tampering, DoS, Replay attacks on Modbus protocol.

Component Vulnerability

RTU (Remote Telemetry Unit)

Packet Modification (Modbus in plain text), Buffer Overflow fixed memory allocation, Replay Attacks, Privilege Escalation.

Component Vulnerability

Communication Protocols

Modbus and DNP3 lack inherent Cryptography and message authentication.

Case Analysis 01

Stuxnet Malware Analysis

Stuxnet targets Microsoft Windows operating systems seeking Siemens Step7 software controlling Iranian PLCs centrifuges. It comprises three modules: a WORM that executes main attack routines; a LINK FILE that automatically propagates copies; and a ROOTKIT component hiding malicious files. Introduced via infected USB flash drives, it executes Man-in-the-Middle sensor spoofing to prevent automated shutdown during destructive over-rotation.

Case Analysis 02

Industroyer (Crashoverride)

Industroyer is the first known malware framework specifically designed to attack electrical power grids (used in Ukraine's power grid cyberattack on Dec 17, 2016). Alongside Stuxnet, Havex, and BlackEnergy, it launches targeted DoS attacks on Siemens SIPROTEC devices by exploiting CVE-2015-5374 to force devices into continuous firmware update mode.

Audit Checklist

SCADA Penetration Testing Checklist

1

Are all factory default credentials changed?

2

Is access to PLCs whitelisted to authorised machines only? They should not be reachable from everywhere.

3

Is the SCADA network separated from the rest of the network? If not, try reaching the PLCs from corporate workstations.

4

Is physical access to the SCADA control centre restricted?

5

Can you access the internet from the controller machine?

6

Are there any clear text services running on the SCADA network?

7

Does the organisation follow a strict password policy?

8

Are the controller machines, workstations and servers patched? Are they running anti-virus software and have application whitelisting enforced?

Recommended SCADA Assessment Tools

smod

ModBus penetration testing framework

plcscan

Python script for scanning PLC devices

NMAP Scripts

NMAP script to scan PLC devices

Wireshark

Network sniffer

mbtget

Perl script to read data from PLC

plcinject

Tool to inject code into PLCs

Protect Your SCADA & ICS Infrastructure

Consult with Jinnicore's OT/ICS security specialists for SCADA vulnerability assessments, PLC/RTU attack scenario simulations, and MITRE ATT&CK threat metrics auditing.