Connect with us

Hi, what are you looking for?

HEADLINES

91.1% of ICS hosts have vulnerabilities that can be exploited remotely

Exposing ICS components to the Internet provides a lot of opportunities, but also many concerns around security.

To minimize the possibility of a cyber-attack, Industrial Control Systems (ICS) are supposed to be run in a physically isolated environment. However, this is not always the case. In its report on the ICS threats landscape, Kaspersky Lab experts revealed 13,698 ICS hosts exposed to the Internet that more than likely belong to large organizations.

Kaspersky

These organizations include energy, transportation, aerospace, oil and gas, chemicals, automotive and manufacturing, food and drink, governmental, financial and medical institutions. 91.1% of these ICS hosts have vulnerabilities that can be exploited remotely.

Worse, 3.3% of ICS hosts located in these organizations contain critical and remotely executable vulnerabilities.

Exposing ICS components to the Internet provides a lot of opportunities, but also many concerns around security. On the one hand, connected systems are more flexible in terms of a fast reaction to critical situations and implementation of updates. But on the other, the expansion of the Internet gives cybercriminals a chance to remotely control critical ICS components, which can result in physical harm to the equipment as well as potential danger to the whole critical infrastructure.

Sophisticated attacks on ICS systems are not new. In 2015, an organized group of hackers called BlackEnergy APT attacked a power company in Ukraine. In the same year two more incidents, supposedly connected with cyber-attacks, were reported in Europe: on a steel mill in Germany and on the Frederic Chopin Airport in Warsaw.

Advertisement. Scroll to continue reading.

More attacks of this kind will emerge in the future since the attack surface is big. Those 13,698 hosts, located in 104 countries are only a small part of the total number of hosts with ICS components available through the Internet.

To help organizations working with ICS to identify their possible weak points, Kaspersky Lab experts conducted an investigation into ICS threats. Their analysis was based on OSINT (Open Source Intelligence) and information from public sources like ICS CERT, with the research period limited to 2015.

The major findings of the Industrial Control Systems Threats Landscape report are:

  • In total, 188,019 hosts with ICS components available via the Internet have been identified in 170 countries.
  • Most of the remotely available hosts with ICS components installed are located in the United States of America (30.5% – 57,417) and Europe. In Europe, Germany has a leading position (13.9% – 26,142 hosts), followed by Spain (5.9% – 11,264 hosts), and France (5.6% – 10,578 hosts).
  • 92% (172,982) of remotely available ICS hosts have vulnerabilities. 87% of these hosts contain medium risk vulnerabilities and 7% of them have critical vulnerabilities.
  • The number of vulnerabilities in ICS components has increased tenfold during the past five years: from 19 vulnerabilities in 2010 to 189 vulnerabilities in 2015. The most vulnerable ICS components were Human Machine Interfaces (HMI), Electric Devices and SCADA systems.
  • 91.6% (172,338 different hosts) of all the externally available ICS devices use weak Internet connection protocols, which opens the opportunity for attackers to conduct ’man in the middle’ attacks.

“Our research shows that the larger the ICS infrastructure, the bigger the chance that it will have severe security holes. This is not the fault of a single software or hardware vendor. By its very nature, the ICS environment is a mix of different interconnected components, many of which are connected to the Internet and contain security issues. There is no 100% guarantee that a particular ICS installation won’t have at least one vulnerable component at any single moment in time. However, this doesn’t mean that there is no way to protect a factory, a power plant, or even a block in a smart city from cyber-attacks. Simple awareness of vulnerabilities in the components used inside a particular industrial facility is the basic requirement for security management of the facility. That was one of the goals behind our report: to bring awareness to interested audiences,” said Andrey Suvorov, head of critical infrastructure protection, Kaspersky Lab.

In order to protect the ICS environment from possible cyber-attacks, Kaspersky Lab security experts advise the following:

  • Conduct a security audit: inviting experts who specialize in industrial security is probably the quickest way to identify and remove the security loopholes described in the report.
  • Request external intelligence: today IT security relies on knowledge of potential attack vectors. Obtaining such intelligence from reputable vendors helps organizations to predict future attacks on the company’s industrial infrastructure.
  • Provide protection inside and outside the perimeter. Mistakes happen. A proper security strategy has to devote significant resources to attack detection and response, to block an attack before it reaches critically important objects.
  • Evaluate advanced methods of protection: A Default Deny scenario for SCADA systems, regular integrity checks for controllers, and specialized network monitoring to increase the overall security of a company and reduce the chances of a successful breach, even if some inherently vulnerable nodes cannot be patched or removed.
Advertisement
Advertisement
Advertisement

Like Us On Facebook

You May Also Like

HEADLINES

From January to December 2024, Kaspersky solutions used by businesses here detected and blocked more than 53 million bruteforce attacks. 

HEADLINES

According to Kaspersky experts, 2024 saw over 3 billion malware attacks globally, with a daily average of 467,000 malicious files detected. Windows systems were...

HEADLINES

Cybercriminals target SMBs, schools, and other smaller organizations because they often have less robust security compared to large corporations and other institutions. 

HEADLINES

Sophos Counter Threat Unit revealed the NICKEL TAPESTRY threat group’s scheme involving fraudulent workers operating on behalf of North Korea (formally known as the...

HEADLINES

PRSP is a staunch advocate of communication based on honesty and integrity. While our role is to uphold and strengthen the reputation of our...

HEADLINES

Poor password management is compounded by a reliance on common combinations of names, dictionary words and numerals. Not only are these passwords relatively easy...

White Papers

This demonstrates that despite a slight improvement from last year, cybersecurity preparedness remains low as hyperconnectivity and AI introduce new complexities for security practitioners.

HEADLINES

The Fraud Bureau is a collaborative initiative that unites banks, fintechs, and financial institutions to share data on potentially deceptive applicant activity securely. This...

Advertisement