Pacific Northwest train signals disrupted by hacker, says TSA
25 January 2012
infosecurity
Hackers, possibly from abroad, attacked a Pacific Northwest railway company’s computer system, disrupting railway signals in December, according to the US Transportation Security Administration (TSA).
Train service of the unnamed railroad "was slowed for a short while" and rail schedules were delayed about 15 minutes on Dec. 1 as a result of the computer intrusion. The following day, shortly before rush hour, a "second event occurred" that did not affect schedules, according to a TSA document obtained by Nextgov. The memo summarized discussions TSA had with railroad industry representatives on Dec. 20 regarding the incident.
"Some of the possible causes lead to consideration of an overseas cyberattack", the memo stated. TSA investigators discovered two IP addresses used by the intruders on Dec. 1 and a third on Dec. 2, the document noted, but it did not say in which country the IP addresses were located. The TSA sent out notice of the incident, including the three IP addresses, to several hundred railroad companies and public transportation agencies.
However, Holly Arthur, a spokeswoman for the Association of American Railroads, denied that there was a recent computer hack of a US railroad. She told Nextgov that there was “no targeted computer-based attack on a railroad. Railroads closely monitor cyber security as a fully integrated part of both the industry's overall security plan, as well as individual company plans. Continuous coordination on cyber security occurs across the industry and with the federal government.â€
Pacific Northwest train signals disrupted by hacker
- John Ashworth
- Site Admin
- Posts: 23606
- Joined: 24 Jan 2007, 14:38
- Location: Nairobi, Kenya
- Contact:
- John Ashworth
- Site Admin
- Posts: 23606
- Joined: 24 Jan 2007, 14:38
- Location: Nairobi, Kenya
- Contact:
Re: Pacific Northwest train signals disrupted by hacker
SCADA Systems in Railways Vulnerable to Attack
By: Fahmida Y. Rashid
2012-01-25
eWeek.com
Reports of a possible cyber-attack against a rail company highlight the issues of protecting industrial control systems that keep the country's critical infrastructure running.
Government officials initially believed railway signal disruptions in December were tied to a cyber-attack against a Northwest rail company in December, Nextgov reported. But government and railway officials later denied that a U.S. railroad had actually been hit by a cyber-attack.
"There was no targeted computer-based attack on a railroad," said Holly Arthur, a spokeswoman for the Association of American Railroads.
While an attack has been ruled out, the incident highlights the dangers of industrial control systems controlling critical infrastructure.
Train service on the unnamed railway was "slowed for a short while" and schedules delayed for 15 minutes on Dec. 1, according to a Transportation Security Administration memo obtained by Nextgov. A "second event" occurred just before rush hour the next day, but it did not affect schedules, according to the Dec. 20 memo, which summarized the agency's outreach efforts to share threat intelligence with the transportation sector.
"Amtrak and the freight rails needed to have context regarding their information technical centers," the memo said, adding that rail operators were not focused on cyber-threats.
TSA investigators discovered two IP addresses for the intruders associated with the Dec. 1 incident and another for Dec. 2. Investigators considered the possibility of the attackers being based overseas, but did not specify the suspected country, Nextgov reported. Alerts listing the three IP addresses were sent to several hundred railroad firms and public transportation agencies.
Officials at the Department of Homeland Security, which oversees the TSA, told Nextgov on Jan. 23 that further investigation showed it may not have been a targeted attack, but did not explain what may have caused the "anomalous activity."
The railway incident is similar to what happened at an Illinois utility last fall. A government fusion center claimed Russian attackers had remotely destroyed the facility's water pump, but the DHS on further investigation claimed it was not an attack. It later turned out the intrusion had been an American contractor remotely logging in to perform some maintenance tasks.
However, the TSA's railway memo highlights how vulnerable the railways are to an attack on supervisory control and data acquisition (SCADA) systems, according to experts from Casaba Security, a security analysis and consulting company. Just about anything in the railway infrastructure could be controlled by SCADA systems, including track switches, signal and crossing lights, transformers, weather and track sensors, engine monitors, railway car sensors, electronic signs and even turnstiles, said Samuel Bucholtz, Casaba's co-founder. Most of these systems are connected to the network so that they can obtain data collected by the sensors.
"A sensor that can detect the position of a track switch is not helpful unless it can pass that data to an operations center hundreds of miles away," Bucholtz said.
Connecting SCADA systems to the Internet puts the infrastructure at risk because it opens up the possibility of intruders finding a way into the network. However, many organizations take that risk to save money, simplify the infrastructure and ease maintenance. It is usually cheaper to transmit data over the Internet instead of investing in dedicated lines or wireless frequency space, according to Bucholtz.
"The benefit of SCADA being 'online' is that the Internet is cheap, robust, standardized and easily accessible," Bucholtz said.
The downside is that without proper protections, the infrastructure is wide open to anyone looking. Cambridge University researcher Eireann Leverett developed a tool that mapped more than 10,000 industrial control systems accessible from the Internet, including water and sewage plants. While some of the systems could have been demo systems or used in places that wouldn't count as critical infrastructure, such as the heating system in office buildings, some were active systems in water facilities in Ireland and sewage facilities in California.
Only 17 percent of the systems mapped asked for authorization to connect, suggesting that administrators either weren't aware the systems were online or had not installed secure gateways, Leverett said. Leverett, a computer science doctoral student at Cambridge, presented the findings at the S4 conference in Miami.
Administrators need to set up secure and isolated networks and use Secure Sockets Layer or a virtual private network to restrict who can talk to the controllers, according to John Michener, chief scientist at Casaba. Since SCADA systems will likely be Internet-accessible, administrators should focus on putting them behind a secure gateway. "Increasingly all the communications are over the Net, so being on the Net is all but inescapable," Michener said.
By: Fahmida Y. Rashid
2012-01-25
eWeek.com
Reports of a possible cyber-attack against a rail company highlight the issues of protecting industrial control systems that keep the country's critical infrastructure running.
Government officials initially believed railway signal disruptions in December were tied to a cyber-attack against a Northwest rail company in December, Nextgov reported. But government and railway officials later denied that a U.S. railroad had actually been hit by a cyber-attack.
"There was no targeted computer-based attack on a railroad," said Holly Arthur, a spokeswoman for the Association of American Railroads.
While an attack has been ruled out, the incident highlights the dangers of industrial control systems controlling critical infrastructure.
Train service on the unnamed railway was "slowed for a short while" and schedules delayed for 15 minutes on Dec. 1, according to a Transportation Security Administration memo obtained by Nextgov. A "second event" occurred just before rush hour the next day, but it did not affect schedules, according to the Dec. 20 memo, which summarized the agency's outreach efforts to share threat intelligence with the transportation sector.
"Amtrak and the freight rails needed to have context regarding their information technical centers," the memo said, adding that rail operators were not focused on cyber-threats.
TSA investigators discovered two IP addresses for the intruders associated with the Dec. 1 incident and another for Dec. 2. Investigators considered the possibility of the attackers being based overseas, but did not specify the suspected country, Nextgov reported. Alerts listing the three IP addresses were sent to several hundred railroad firms and public transportation agencies.
Officials at the Department of Homeland Security, which oversees the TSA, told Nextgov on Jan. 23 that further investigation showed it may not have been a targeted attack, but did not explain what may have caused the "anomalous activity."
The railway incident is similar to what happened at an Illinois utility last fall. A government fusion center claimed Russian attackers had remotely destroyed the facility's water pump, but the DHS on further investigation claimed it was not an attack. It later turned out the intrusion had been an American contractor remotely logging in to perform some maintenance tasks.
However, the TSA's railway memo highlights how vulnerable the railways are to an attack on supervisory control and data acquisition (SCADA) systems, according to experts from Casaba Security, a security analysis and consulting company. Just about anything in the railway infrastructure could be controlled by SCADA systems, including track switches, signal and crossing lights, transformers, weather and track sensors, engine monitors, railway car sensors, electronic signs and even turnstiles, said Samuel Bucholtz, Casaba's co-founder. Most of these systems are connected to the network so that they can obtain data collected by the sensors.
"A sensor that can detect the position of a track switch is not helpful unless it can pass that data to an operations center hundreds of miles away," Bucholtz said.
Connecting SCADA systems to the Internet puts the infrastructure at risk because it opens up the possibility of intruders finding a way into the network. However, many organizations take that risk to save money, simplify the infrastructure and ease maintenance. It is usually cheaper to transmit data over the Internet instead of investing in dedicated lines or wireless frequency space, according to Bucholtz.
"The benefit of SCADA being 'online' is that the Internet is cheap, robust, standardized and easily accessible," Bucholtz said.
The downside is that without proper protections, the infrastructure is wide open to anyone looking. Cambridge University researcher Eireann Leverett developed a tool that mapped more than 10,000 industrial control systems accessible from the Internet, including water and sewage plants. While some of the systems could have been demo systems or used in places that wouldn't count as critical infrastructure, such as the heating system in office buildings, some were active systems in water facilities in Ireland and sewage facilities in California.
Only 17 percent of the systems mapped asked for authorization to connect, suggesting that administrators either weren't aware the systems were online or had not installed secure gateways, Leverett said. Leverett, a computer science doctoral student at Cambridge, presented the findings at the S4 conference in Miami.
Administrators need to set up secure and isolated networks and use Secure Sockets Layer or a virtual private network to restrict who can talk to the controllers, according to John Michener, chief scientist at Casaba. Since SCADA systems will likely be Internet-accessible, administrators should focus on putting them behind a secure gateway. "Increasingly all the communications are over the Net, so being on the Net is all but inescapable," Michener said.
- John Ashworth
- Site Admin
- Posts: 23606
- Joined: 24 Jan 2007, 14:38
- Location: Nairobi, Kenya
- Contact:
Re: Pacific Northwest train signals disrupted by hacker
The H 26 January 2012, 18:02
Hackers may have disrupted railway computers and schedules
Hackers attacked computers that controlled railway signals on a Pacific Northwest rail company's systems and disrupted the schedules of the trains on that line over two days in December. That is, according to a report on US online magazine NextGov which cites a US Transportation Security Administration (TSA) memo on the subject. The memo says that on 1 December 2011 an unnamed railway was "slowed for a short while" and trains delayed for about 15 minutes as a result of the attack. On 2 December, a "second event occurred" which did not affect schedules.
TSA investigators said they had identified three IP addresses as the source of the attacks on the unnamed railway but did not say in which country the IP addresses were located. The memo noted that “some of the possible causes lead to consideration of an overseas cyberattack". The TSA then notified railway companies and transportation agencies in the US and Canada, operating on the assumption that this was a targeted attack rather than a glitch, and possibly part of a wider threat.
On Monday though, a Department of Homeland Security spokesman told US Media that, following further analysis, it "did not appear to be a targeted attack" but more of a "random incident" which just happened to affect the railway company. The spokesman did not add further detail to the disclosure.
The overall incident is reminiscent of the November 2011 claim that hackers had destroyed water pumps which was immediately followed by denials and confusion over the validity of the report – reports of Russian IP addresses being used were actually explainable and did not involve hacking. Unfortunately though, many industrial control systems used in national infrastructure are vulnerable and attackers need nothing more than freely available software such as Metasploit to find those vulnerabilities.
Hackers may have disrupted railway computers and schedules
Hackers attacked computers that controlled railway signals on a Pacific Northwest rail company's systems and disrupted the schedules of the trains on that line over two days in December. That is, according to a report on US online magazine NextGov which cites a US Transportation Security Administration (TSA) memo on the subject. The memo says that on 1 December 2011 an unnamed railway was "slowed for a short while" and trains delayed for about 15 minutes as a result of the attack. On 2 December, a "second event occurred" which did not affect schedules.
TSA investigators said they had identified three IP addresses as the source of the attacks on the unnamed railway but did not say in which country the IP addresses were located. The memo noted that “some of the possible causes lead to consideration of an overseas cyberattack". The TSA then notified railway companies and transportation agencies in the US and Canada, operating on the assumption that this was a targeted attack rather than a glitch, and possibly part of a wider threat.
On Monday though, a Department of Homeland Security spokesman told US Media that, following further analysis, it "did not appear to be a targeted attack" but more of a "random incident" which just happened to affect the railway company. The spokesman did not add further detail to the disclosure.
The overall incident is reminiscent of the November 2011 claim that hackers had destroyed water pumps which was immediately followed by denials and confusion over the validity of the report – reports of Russian IP addresses being used were actually explainable and did not involve hacking. Unfortunately though, many industrial control systems used in national infrastructure are vulnerable and attackers need nothing more than freely available software such as Metasploit to find those vulnerabilities.