SCADA ATTACK SCENARIOS
SCADA or Supervisory Control and Data Acquisition mean an industrial control system for a particular procedure. We, Jinnicore have years of experience in performing evaluations on various industrial system parts; ranging from electrical utilities to chemical plants, grease refineries, etc.
Our team can identify and evaluate security OT and IT threats. We can evaluate the logical and physical security besides intrusion prevention systems, video surveillance, encryption, source code, passwords, access control, and logical security.
3 Major SCADA Network Compartments
1. Enterprise Network
- Provides Services for all enterprise business operations such as Web/Email Servers, Application Servers, Workstations, etc.
- Regular access to the Internet or Intranet.
- Firewall Protected. (Tier I Security)
2. Process Network
- Consist of Master Terminal Unit, HMIs, and the Database Historian.
- Provides an interface where the operator administers control and supervisory actions on all other subcomponents and field devices for efficient operation of the SCADA system.
- Firewall Protected. (Tier II Security)
3. Control Network
- Comprises the field instrumentation devices such as the Remote Telemetry Unit (RTU), the Sensors/IEDs and Actuators.
- Modern SCADA incorporates an Intelligent Electronic Device (IED) which is an intelligent sensor capable of functioning in place of the Programmable Logic Controller (PLC)
- Secured WAN Link. (Tier III Security)
SECURITY ISSUES OF SCADA
MTU (Master Terminal Unit)
Outdated OS, Apps, AntiVirus; operational instability when updating; SQL Injection, Buffer Overflow, Lack of Privilege separation; Physical/Insider compromise.
HMI (Human Machine Interface)
Input Validation Vulnerability, System Level Access default risks allowing complete control of industrial functionality.
Database Historian
Deprecated software, lack of patch management, SQL Injection, Buffer Overflow, XSS cookie credential theft.
Sensors & IEDs
Signal jamming/interference, Man-In-The-Middle (MiTM), Flooding, Tampering, DoS, Replay attacks on Modbus protocol.
RTU (Remote Telemetry Unit)
Packet Modification (Modbus in plain text), Buffer Overflow fixed memory allocation, Replay Attacks, Privilege Escalation.
Communication Protocols
Modbus and DNP3 lack inherent Cryptography and message authentication.
Stuxnet Malware Analysis
Stuxnet targets Microsoft Windows operating systems seeking Siemens Step7 software controlling Iranian PLCs centrifuges. It comprises three modules: a WORM that executes main attack routines; a LINK FILE that automatically propagates copies; and a ROOTKIT component hiding malicious files. Introduced via infected USB flash drives, it executes Man-in-the-Middle sensor spoofing to prevent automated shutdown during destructive over-rotation.
Industroyer (Crashoverride)
Industroyer is the first known malware framework specifically designed to attack electrical power grids (used in Ukraine's power grid cyberattack on Dec 17, 2016). Alongside Stuxnet, Havex, and BlackEnergy, it launches targeted DoS attacks on Siemens SIPROTEC devices by exploiting CVE-2015-5374 to force devices into continuous firmware update mode.
SCADA Penetration Testing Checklist
Are all factory default credentials changed?
Is access to PLCs whitelisted to authorised machines only? They should not be reachable from everywhere.
Is the SCADA network separated from the rest of the network? If not, try reaching the PLCs from corporate workstations.
Is physical access to the SCADA control centre restricted?
Can you access the internet from the controller machine?
Are there any clear text services running on the SCADA network?
Does the organisation follow a strict password policy?
Are the controller machines, workstations and servers patched? Are they running anti-virus software and have application whitelisting enforced?
Recommended SCADA Assessment Tools
ModBus penetration testing framework
Python script for scanning PLC devices
NMAP script to scan PLC devices
Network sniffer
Perl script to read data from PLC
Tool to inject code into PLCs
Protect Your SCADA & ICS Infrastructure
Consult with Jinnicore's OT/ICS security specialists for SCADA vulnerability assessments, PLC/RTU attack scenario simulations, and MITRE ATT&CK threat metrics auditing.