SCADA (Supervisory Control and Data Acquisitions, the usual term for industrial control) systems until, at the least, 9/11/01, were not typically designed with security in mind.
Symptoms of problems include the ability to DOS a SCADA network simply by flooding it with packets and the lack of authentication/ encryption embedded in protocols such as IEC 61850 (an increasingly popular SCADA standard).
There are two halves to the problem of hacking a SCADA system.
First, you must be able to exploit the software. E.g., Siemens Step 7. That is standard IT hacking. Not a "problem".
Second, you must be able to exploit the installation. Let me explain a bit more.
In software terms, what you are given to work with is a list of hex values denoting inputs, and then a list of hex values denoting outputs.
So - without knowledge - what you will see is conceptually like this:
READ 0x1
READ 0x2
IF 0x1 + 0x2 > 314159 THEN
WRITE 0xA, 100
ENDIF
What do those numbers mean? There's no context until you know what those read/write registers are plugged into. And those could be different for each installation.
The second part isn't always brought out in the Stuxnet discussions. Part of the search for understanding for Stuxnet was decoding how the registers mapped to the installation.
For the interested reader, I refer you to the Symantec white paper. It is of quite high quality and good technical detail. The SCADASEC mailing list contains useful discussion by people involved in the industry, and they really bring out the differences between SCADA security and IT security. And for the really interested reader, I recommend reading up on PLC programming and digging up protocol standards for MODBUS and DNP3.
Symptoms of problems include the ability to DOS a SCADA network simply by flooding it with packets and the lack of authentication/ encryption embedded in protocols such as IEC 61850 (an increasingly popular SCADA standard).
There are two halves to the problem of hacking a SCADA system.
First, you must be able to exploit the software. E.g., Siemens Step 7. That is standard IT hacking. Not a "problem".
Second, you must be able to exploit the installation. Let me explain a bit more.
In software terms, what you are given to work with is a list of hex values denoting inputs, and then a list of hex values denoting outputs.
So - without knowledge - what you will see is conceptually like this:
What do those numbers mean? There's no context until you know what those read/write registers are plugged into. And those could be different for each installation.The second part isn't always brought out in the Stuxnet discussions. Part of the search for understanding for Stuxnet was decoding how the registers mapped to the installation.
For the interested reader, I refer you to the Symantec white paper. It is of quite high quality and good technical detail. The SCADASEC mailing list contains useful discussion by people involved in the industry, and they really bring out the differences between SCADA security and IT security. And for the really interested reader, I recommend reading up on PLC programming and digging up protocol standards for MODBUS and DNP3.