MatrikonOPC OPC Exchange


OPC Security – Mountain or Molehill

Posted on August 24th, 2006 by Eric Murphy

With the recent airline scares, security is once on everyone’s mind.  Incidents such as the Heathrow plot renew focus on the possible vulnerabilities of critical infrastructure, such as those in the power, oil and gas, manufacturing and other industries.    One key area of concern deals with SCADA infrastructures and communication protocols, including OPC.

So the million dollar question is “How secure are our SCADA infrastructures and OPC installations?”.   The answer you get depends on who you ask.   Most company spokespeople will assure you their critical systems are secure, besides ‘control systems aren’t connected to the Internet, and are running, rare proprietary protocols’.    If you ask folks in the IT security world, the answer is more like “Danger, Will Robinson! Danger!”.   Since OPC is used extensively in the control industry, and allows open access to a myriad of proprietary protocols, it becomes a natural focus for security concerns.  

So is this all just fear mongering and scare tactics by the cyber-security industry?   Personally, I’ve been in many plants, in many industries, in many countries, and can believe a lot of what they say to be true.   On the other hand, I’ve also seen many sites that are doing things right.   With a proper security assessment, architecture and some thought to the right configuration settings, anyone can have a reasonably hardened OPC communications system.   However too many installations are content with a firewall, and default configuration settings.

Here’s my two cents.  I don’t think there is any reason for immediate panic.  Just because it’s possible, doesn’t make it probable.   Still, it’s better safe than sorry.   A few changes in policy, architecture and product choice would go along way to shoring up the defenses.

Let’s Exchange.  I’d like to hear some opinions or experiences.  I’m doing a presentation on this topic at the OPCUG, and it’s nice to have some new, interesting anecdotes.

2 Responses to “OPC Security – Mountain or Molehill”

  1. n.l. belardes Says:

    Wally Gastreich at ProSoft Technology put together a white paper on industrial wireless security issues. There hasn’t been any significant break-ins at the point of his paper’s release. But I haven’t stayed on top of the topic in the news to see if anything is happening out there…

    White paper blog article:

    http://prosoftblog.com/2005/12/12/12/

  2. Matthew Franz Says:

    With only anecdotal/hearsay threat statistics, both sides are correct!

    It would be really interesting to get some solid statistical data on OS/patch levels and malware infection rates on OPC client/server apps perhaps relative to non-OPC Windows hosts in the same organization.

    - mdf

Leave a Reply

For spam filtering purposes, please copy the number 3078 to the field below: