US industrial control systems attacked 245 times in 12 months
19/03/2015 MWR InfoSecurity
US industrial control systems were hit by cyber attacks at least 245 times over a 12-month period, the US Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) has revealed.The figure was included in a report by the ICS-CERT, which operates within the National Cybersecurity and Integration Center, itself a part of the Department of Homeland Security.
The report is classed as covering the 2014 fiscal year which, under US government dates, was between 1 October 2013 and 30 September 2014.
"ICS-CERT received and responded to 245 incidents reported by asset owners and industry partners," the report said.
The energy sector accounted for the most incidents at 79, but perhaps the more alarming figure is that 65 incidents concerned cyber infiltration of the manufacturers of ICS hardware.
"The ICS vendor community may be a target for sophisticated threat actors for a variety of reasons, including economic espionage and reconnaissance," the report said.
The group said that 55 percent of investigated incidents showed signs that advanced persistent threats had been used to breach systems.
"Other actor types included hacktivists, insider threats and criminals. In many cases, the threat actors were unknown due to a lack of attributional data," it added.
The ICS-CERT did reveal, however, that some of its work related to hacks that used the Havex and Black Energy malware revealed during 2014.
"ICS-CERT has provided onsite and remote assistance to various critical infrastructure companies to perform forensic analysis of their control systems and conduct a deep dive analysis into Havex and Black Energy malware," it said.
The ICS-CERT also acknowledged that it is highly likely that it was unaware of other incidents that will have occurred during the period.
"The 245 incidents are only what was reported to ICS-CERT, either by the asset owner or through relationships with trusted third-party agencies and researchers. Many more incidents occur in critical infrastructure that go unreported," the report said.
The report comes amid rising concerns that industrial control systems are being targeted by Russian hackers, who are seen as new and highly sophisticated players in the cyber arena.
Responding to this report, Rob Miller, security consultant at MWR InfoSecurity, said:
"Many organisations we work with are taking these reports very seriously. The report shows that the rate of new vulnerabilities being discovered in ICS equipment has remained steady for the last four years. ICS operators cannot therefore rely on vendors taking care of their security for them.
"Organisations may feel that their ICS systems are beyond the reach of attackers, but attacks like those against the Norwegian oil sector last year have demonstrated these assumptions to be false. ICS, far from being an air-gapped, proprietary system, is now often integrated to our IT networks as companies strive to improve performance and reduce costs. This can be done without impacting security, but only if security is considered during its design.
"Ultimately better ICS security comes from not only controlling the borders of an ICS system, but by also introducing the ability to monitor and detect attacks, and through training of staff to respond appropriately."
For more information, please contact:
Rob Miller
MWR InfoSecurity
Matrix House
Basing View
Basingstoke
RG21 4DZ
Tel: +44 1256 300920
Web: www.mwrinfosecurity.com
Share article:
Process and Control Today are not responsible for the content of submitted or externally produced articles and images. Click here to email us about any errors or omissions contained within this article.

