To minimize the likelihood of a digital attack, Industrial Control Systems (ICS) are assumed to «run» in a physically isolated environment. However, this is not always the case. In their report on the threat landscape facing ICS, Kaspersky Lab experts revealed 13,698 central ICS computers exposed to the Internet and it appears that they most likely belong to large organizations. 
These organizations belong to sectors such as: energy, transportation, aerospace, oil and natural gas, chemicals, automotive, manufacturing, food and beverages, government agencies, financial institutions, health organizations. 91.1% of these ICS main computers have vulnerabilities that can be exploited remotely.
But that's not the worst: 3.3% of the ICS main computers found in these organizations contain critical and remotely executable vulnerabilities.
The exposure of ICS components on the Internet provides many opportunities, but also many security concerns. On one hand, connected systems are more flexible in terms of rapid response to critical situations and the deployment of updated versions. On the other hand, the expansion of the Internet gives digital criminals the chance to remotely control the most critical ICS components, which can lead to physical damage to equipment and potentially endanger the entire critical infrastructure.
Sophisticated attacks on ICS systems are nothing new. In 2015, an organized hacker group called BlackEnergy APT attacked an electricity company in Ukraine. In the same year, two other incidents, allegedly linked to cyberattacks, were reported in Europe: at a steel mill in Germany and at Frederic Chopin Airport in Warsaw.
More attacks of this type will emerge in the future, given that the attack surface is large. These 13.698 central computers, which are located in 104 countries, constitute only a small part of the total number of central computers with ICS data that are available via the Internet.
To help organizations working with ICS systems identify potential vulnerabilities, Kaspersky Lab experts conducted a study on ICS threats. Their analysis was based on the OSINT (Open Source Intelligence) system and information from public sources, such as the ICS CERT, with the research period limited to 2015.
The main findings of the report «The Threat Landscape in Industrial Control Systems» are:
- Overall, 188.019 central computers with ICS data have been identified as available via the Internet in 170 countries.
- The majority of remotely available central computers with ICS data are located in the USA (30,5% – 57.417) and in Europe. In Europe, Germany holds the leading position (13,9% – 26.142 central computers), followed by Spain (5,9% – 11.264 central computers) and France (5,6% – 10.578 central computers).
- 92% (172.982) of remotely available ICS mainframes have vulnerabilities. 87% of these mainframes contain medium-risk vulnerabilities and 7% contain critical vulnerabilities.
- The number of vulnerabilities in ICS components has increased tenfold over the past five years: from 19 vulnerabilities in 2010 to 189 in 2015. The most vulnerable ICS components were Human-Machine Interface (HMI) systems, Electrical Devices, and SCADA systems.
- 91.6% (172.338 different central computers) of all externally available ICS devices use weak Internet connection protocols, a fact that gives attackers the ability to carry out attacks of type «man-in-the-middle».
“Our research shows that the larger the ICS infrastructure, the greater the likelihood that it will have serious security holes. This is not the fault of the software or the hardware. By its nature, the ICS environment is a mix of different, but interconnected components, many of which are connected to the Internet and contain security issues. There is no 100% guarantee that a given ICS installation will not present at least one vulnerable element at some point in time. However, this does not mean that there is no way to protect a factory, a power plant or even a block in a “smart” city from digital attacks.
Simply being aware of the vulnerabilities of the components used within a given industrial facility is the basic prerequisite for managing the security of the facilities. This was one of the reasons that led us to develop our report: to contribute to raising awareness of all stakeholders on the issue,” said Andrey Suvorov, Head of Critical Infrastructure Protection at Kaspersky Lab.
To protect the ICS environment from potential digital attacks, security experts at Kaspersky Lab recommend the following:
- Conduct a security audit: inviting experts in industrial security is perhaps the fastest way to identify and eliminate the security gaps described in the report.
- Request external expertise: Today, the security of IT infrastructure is based on knowledge of potential attack actors. Access to information from reliable suppliers helps organizations predict future attacks on the company's industrial infrastructure.
- Provide protection inside and outside the perimeter: Mistakes happen. A proper security strategy must have significant resources for detecting attacks and responding to them, as well as preventing an attack before it reaches extremely critical and important assets.
- Evaluate advanced protection methods: A Default Deny scenario for SCADA systems, performing regular integrity checks for controllers, and specialized network monitoring can help increase the company's overall security and reduce the chances of a successful breach, even if some inherently vulnerable nodes cannot be patched or removed.
The full report on “The Threat Landscape in Industrial Control Systems” is available on the Securelist.com.
