HomeNewsIndia NewsSCADA and ICS to be the main targets of cyber attackers

SCADA and ICS to be the main targets of cyber attackers

Fortinet, a global leader in broad, integrated, and automated cybersecurity solutions, announced the findings of its 2019 Operational Technology Security Trends Report, analyzing data gathered from millions of Fortinet devices to discern the state of cybersecurity for supervisory control and data acquisition (SCADA) and other industrial control systems (ICS). The analysis found many attacks on OT systems that seems to target older devices running unpatched software, indicating that OT networks are increasingly being targeted by IT-based legacy attacks that are no longer effective against IT networks. The report also highlights a rise in purpose-built OT attacks designed to target SCADA and ICS systems.

The majority of these attacks tend to target the weakest parts of OT networks often taking advantage of the complexities caused by a lack of protocol standardization and a sort of implicit trust that seems to permeate many OT environments. This trend is not limited to specific sectors as threat actors targeting OT environments did not discriminate according to industry or geography, as every vertical and region saw a significant rise in attacks.

Malicious actors are able to extract maximum value from each new threat they develop by exploiting unprotected OT systems and vulnerabilities that persist in both older and newer networks and technologies. IT integration and convergence due to digital transformation efforts will continue to pressure this situation further. The best way to counter this new reality is by adopting and implementing a comprehensive strategic approach that simplifies the solution and involves IT and OT experts throughout an entire organisation,” said Michael Joseph, Director System Engineering, India & SAARC at Fortinet.

Key findings from the Fortinet 2019 Operational Technology Security Trends Report:

  • Exploits increased in volume and prevalence in 2018 for almost every ICS/SCADA vendor. In addition to the recycled IT attacks being thrown at unpatched or non-updated OT devices, 85% of unique threats detected targeted machines running OPC Classic, BACnet, and Modbus.
  • Cybercriminals targeted devices by exploiting the wide variety of OT protocols in place – many of which are specific to functions, industries and geographies. Due to the prevalence of legacy protocols and the slow replacement cycle for OT systems to deploy new architecture cybercriminals have actively attempted to capitalize by targeting the weak links in each protocol. These structural problems are exacerbated by the lack of standard protections and poor security hygiene practiced with many OT systems.
  • Custom OT attacks are also on the rise: Malware targeting ICS and SCADA systems have been developed and deployed for a decade or longer. Attacks specifically designed for OT systems seems to be on the rise, with safety systems increasingly a target. A handful of OT-based attacks over the past decade have managed to make headlines, including Stuxnet, Havex, BlackEnergy, and Industroyer. Most recently, Triton/Trisis targeted safety instrumented system (SIS) controllers which is the first true cyber-physical attack on OT systems.
  • Ransomware continues to attack OT systems: As of late 2018, ransomware attacks on IT systems have declined and many threat actors appear to have “moved on” to other types of attacks like cryptojacking. However, cybercriminals tend to recycle existing malware to attack OT systems. This may suggest that ransomware will be a bigger threat for OT systems than for IT ones in the near term.
  • Attacks on heating, ventilation and air conditioning (HVAC) systems and electrical grids are more likely to occur when these systems are operating at peak usage—most often during the Northern Hemisphere’s summer months. The age of an OT system is also a factor, with adversaries tending to target older technology more frequently than newer.

As OT systems become more connected, the trend of increased attacks seems likely to continue. This new exposure requires organizations to adhere to more rigorous security operations and life-cycle management best practices to protect their organizations from major threats to the core of their business. As a result, OT and IT teams need to come together to respond comprehensively to increasing threats.

For more information, visit: www.fortinet.com

ELE Times Research Desk
ELE Times Research Deskhttps://www.eletimes.ai
ELE Times provides a comprehensive global coverage of Electronics, Technology and the Market. In addition to providing in depth articles, ELE Times attracts the industry’s largest, qualified and highly engaged audiences, who appreciate our timely, relevant content and popular formats. ELE Times helps you build awareness, drive traffic, communicate your offerings to right audience, generate leads and sell your products better.

Related News

Must Read

Keysight Addresses Cross-Domain Physics Issues That Leave Electronic Designs Vulnerable to Late-Stage Failure

Keysight Technologies (NYSE: KEYS) today announced Keysight Multiphysics, a...

India Develops Indigenous Expendable Turbojet Engine for Future Missile System

In a breakthrough that will power the nation's aspirations...

STMicroelectronics Reports 26% Rise in Revenue, Bets Big on AI Data-centre Markets

According to STMicroelectronics, net revenues for the second quarter...

Rohde & Schwarz Presents New Software for Three-Phase Power Analysis on MXO Series Oscilloscopes

Rohde & Schwarz has introduced the new R&S MXO-K333 software...

DCP 800: Bosch expands its diesel testing technology range with a new pump test bench

Bosch is expanding its portfolio for diesel components with...

A New Wave of Chip Making, Phase 2 on the India Semiconductor Mission

The second phase of the India Semiconductor Mission has...

Tata Electronics to Manufacture India’s First Large-Scale Chip Factory

Tata Electronics, a group company under the $103 billion...

STM32U3B5/C5 With 2 MB of Flash and HSP, The 1st ULP STM32 to Run AI Without Batteries

The STM32U3B5/C5 are the first STM32U3 devices featuring 2 MB of...

India-UK Trade Agreement Opens New Opportunities for Electric Vehicle Industry in India

The effective implementation of India-UK Comprehensive Economic and Trade...