10,358 Industrial Control Systems Connected to the Internet

Friday, January 27, 2012

Joel Harding

94ae16c30d35ee7345f3235dfb11113c

For years, there was no call for security testing for Industrial Control Systems which connected much of our critical infrastructure, because they did not connect to the internet. 

Now, Eireann Leverett, a doctoral student in Computer Science at Cambridge University, has demonstrated that this claim is patently false, according to an article at Wired.com.

Using the Shodan search engine, Mr. Leverett spent two years poring over the data he found, exposing water and sewage plants physically connected to the internet.

SCADA devices are widely known for their vulnerabilities, with them connected to the internet, any nation state or rogue groups of hackers could easily bring portions of a country to its knees.

We are vulnerable to cyber attacks, perhaps even a cyberwar.  Will this new cyber threat be properly addressed by our governments?

Wisely, Mr. Leverett shared his findings with DHS and others before publishing his findings and briefing them at the S4 Conference

Hackers, however, rely upon human error to allow them to penetrate many systems because systems administrators fail to secure their systems. Many of the owners of the systems were not even aware their system was hooked up to the internet.

This should be cause for alarm for governments and citizens alike. The critical infrastructure upon which we rely for many of our basic needs has been wide open for years, vulnerable to nefarious elements.

I am certain not all the connected systems were found.  How long will we accept “we don’t need to upgrade our security because we’re not connected"?

Cross-posted from To Inform is to Influence

Possibly Related Articles:
4500
SCADA
Industrial Control Systems
SCADA Shodan Cyberwar internet Infrastructure National Security ICS Industrial Control Systems Joel Harding S4 Conference Eireann Leverett
Post Rating I Like this!
The views expressed in this post are the opinions of the Infosec Island member that posted this content. Infosec Island is not responsible for the content or messaging of this post.

Unauthorized reproduction of this article (in part or in whole) is prohibited without the express written permission of Infosec Island and the Infosec Island member that posted this content--this includes using our RSS feed for any purpose other than personal use.


Latest Survey Results
2011 will be most likely be remembered for:
results