1.7 Cybersecurity of Power Facilities: Past, Present, and Future
77
existence in Iran unlicensed SCADA systems is proved by the photographs provided
by one of the mondial new agencies showing a message about expired license on one
of the displays running at nuclear power station in Bushehr.
Moreover, as it was stated in the Report unregulated login to external networks may
occur at normal routine replacement of some separate components of the equipment
for new ones where modules GPS and\or GPS or WiFi, without mentioning the cases
when such login is effected explicitly and intentionally by the subcontractor himself
for his convenience at work and then just nobody bother to dismount or unhook it.
The ways of intrusions, unobvious though at first glance, can actually solve the
issue of transporting the viruses to critical parts of control systems which for safety
consideration are not logged in the external networks. In this context, the security
protocol should estimate the possibility of remote impact on the side of malicious
software even at “closed” systems.
Some experts, however, believe that the approach to solving the problem of cybersecurity or critical facilities of nuclear energy industry at branch level by means of
companies’ self-regulation as it is set out in the report Chatham House may bring
no expected gain. Reflex reaction to the detected damage produced by malicious
software may be not making the fact of attack public and transfer it to specialized
commission for research and investigation, but reducing to minimum image damage
due to concealment of such fact and rapid renewal of routine operation of the company
for mitigation of financial risks.
Besides, relatively small- size companies have no funds for special-purpose
systems to ensure cybersecurity and have to be content with minimum standard
packages with low cost for deployment and maintenance. However, even large-scale
companies that can afford investing significant sums into assuring cybersecurity are
haunted by lack of culture for such security due to conservative approaches exercised by non- dedicated personnel and general bureaucracy (when the task may be
distributed among a few responsible officers finally one of the links is lost).
The incident depicted in the Report as an example of emergencies at the facilities of
critical infrastructure which took place in 1995 at Ignalinskaya Nuclear Power Station
(Republic of Lithuania) is rendered as a kind of unauthorized check of readiness of
power station systems to similar situations performed by the stations’ employee.
However, commonly adopted version of this attack popular in Russian technical
literature, assuming that the incident was an operation conducted by local criminal
gang as a revenge for the member of their gang sentenced to death in 1994 with
assistance of the “agent” among the personnel maintaining the station control system
managed to tamper with the program for nuclear fuel recharging process control.
[5]. The threat was uncovered in due time manner and eliminated by the power
station’ s staff, but in the essence it was a “pure” case of cyberterrorism because
it implemented through informational system and by means of informational tools
[6]. One more incident not covered by the Report Chatham House took place in
1998 when Indian Center of Nuclear Researches named Khomi Baba [7] (India)
was subjected to similar attack when terrorists threatened to destroy reactor control
system. In other cases depicted in the Report at intrusion of malware into corporate
network of KoreaHydroandNuclearPowerCo. All the damage was reduced to the
Précédent

- 99/839

Suivant