By Gregory Hale
While it is often not thought of in this era of ransomware attacks hitting various computers and forcing networks to shut down, but embedded devices in critical infrastructure organizations can fall victim to ransomware attacks as well – and it is not that difficult.

The industry is just starting to wrap its arms around the idea of protecting against a network ransomware attack, but embedded device security provider Red Balloon Security just released research to show companies need to also think about protecting embedded devices.

“Looking at all the evidence we have collected, there will be exploitation on embedded controllers and there is nothing stopping someone from pulling off a ransomware attack,” said Ang Cui, chief executive at Red Balloon Security. “It was much easier to write ransomware for switches, fault protection relays and RTUs, than writing for a Windows 10 machine. It is basically like writing ransomware for a Windows XP computer unpatched in 2022.”

Not only is it possible to implement ransomware on protection relay devices used in power grids to detect grid failures and trigger circuit breakers, the process is repeatable to other embedded systems, according to research conducted by embedded device security provider Red Balloon Security.

Schneider Bold

Embedded Attack
While ransomware attacks have hit critical infrastructure providers’ IT systems and networks, ransomware on OT embedded devices can be far more damaging and shut major parts of the grid down. To date, Red Balloon officials have not seen this type of attack yet, but they said it is possible and companies should start looking at how to protect against this type of attack.

“We know in some of the ransomware attacks they got into the SCADA workstations and HMI and it is a quick jump to get into embedded devices,” said David Doggett, senior strategist at Red Balloon. “It is definitely possible, has anyone done it yet, not that we know of, but it is an important discussion to start having. The defenders don’t get to choose when an attack comes.”

The most serious threats concern the availability and integrity of mission-critical devices, such as protective relays in electricity grids or safety shut-off valves in oil and gas processing plants, according to a Red Balloon post. With these devices, threat of disablement can be an extremely effective ransomware tactic. Malware that modifies the device’s behavior can be even more devastating, since bypassing safety-critical protection algorithms can result in extensive physical damage.

Red Balloon research uncovered a number of serious vulnerabilities within ubiquitous embedded devices like Cisco routers and HP printers. Red Balloon provided a demo that exploited market-leading protection relay devices, but vulnerabilities extend to embedded devices across the grid. Because these devices have life cycles as long as 30 years, replacement is slow, necessitating security mechanisms added to the firmware of existing devices and as an enhancement to new device security before deployment.

Another Area to Review
In an industry that is just starting to protect their manufacturing enterprise, this is another aspect that can seem overwhelming.

“People’s heads are exploding because they are seeing the ‘amount of things I have to protect’ and it is very tough to get to these devices,” Doggett said. “We have system level protections around these things so some people are saying this shouldn’t happen. But people are now seeing you can have ransomware code running on embedded devices. The Ukraine attack reached the protection relays. In the Maine water attacks, they reached the HMI workstations which has direct comms to the protection devices.”

When it comes to protecting embedded devices, network monitoring and isolation of network management and critical devices are not enough. Utilities, oil & gas, and water treatment plants, among others must demand more transparency from device supply chain vendors to be able to monitor the embedded devices as well as the security of the code and processes, enabling the devices to better protect themselves.

“It is easier to get code execution to live inside your perimeter firewall than it is for it to live in a Windows 10 PC,” Cui said. “The security inside today’s latest and greatest firewall is less than the security in a consumer Windows 10 PC. The security inside a firewall today is also probably better than fault protection relays or RTUs.”

In terms of network isolation, Cui said they have air gaps to help protect them, but if they are relying on perimeter air gaps for protection there is a problem.

“In the history of looking at air gaps, I have yet to see one that is truly air gapped,” Cui said.

Industrial Knowledge
An embedded device attack is not as easy in terms of knowledge of the environment.

“There is a level of knowledge the attacker needs to know to deploy this,” Doggett said. “You are going below the IT networks where you have crossed the IT to OT boundary, and you have to map out the OT networks. There is more effort to deploy this if somebody wanted to, but the actual technical aspect of when it comes down to the devices it is easier to do than at the Windows level. If you are going after the embedded devices you have to understand the industrial process versus going after Windows PCs, you just encrypt the PC and grab all the data off it.”

Red Balloon conducted this research to educate the industry on a new type of attack that is not front and center.

“This is a new area, and they have to think about: What can attacker do on these devices? What can they do to the plant? How do you keep the plant up and running? How do you get your plant back up?” Doggett said.

Not to be all gloom and doom, there are ways to start working on fixes.

“We have not built the same kind of security features into our firmware, then we have in other devices like iPhones,” Cui said. We have to demand suppliers build security features into the firmware.”

In addition, there are companies out there that can automate the process of adding security into firmware, he said.

“Right now, operators in the field are not prepared for ransomware attack with this capability,” Cui said.

ISSSource

Pin It on Pinterest

Share This