Malware Shuts Down Industrial Safety System

Trisis Malware shut down the industrial safety system of a plant in the Middle East mid-November.

Also known as Triton, the Trisis malware was the first attack of its kind. It targeted Schneider Electronic’s Triconex safety instrumented system (SIS). Triconex helps protect employees and the public by catching safety issues that might otherwise go unnoticed.

According to an Analysis of Safety System Targeted Malware published by Dragos, an industrial cyber security company, the exact safety implications of the malware are unknown.

“There could be risk to the safety as set points could be changed for when the safety system would or would not take control of the process in an unsafe condition,” Dragos said.

Should a safety issue arise, Triton could prevent the safety system from enacting a designated procedure. In an industrial situation, an inhibited safety system debilitates.

Wired quotes Rob Lee, founder of Dragos, explaining the danger of the malware.

“Everything could still appear to be working, but you’re now operating without that safety net,” said Lee. It depends on what the industrial process is doing, but you could absolutely have dozens of deaths.”

Cyber security Companies Respond

The malware is an issue cyber security companies addressed considerably due to its significance.

“The attack of an SIS cannot be taken lightly but should not be met with hype and fear” because “the impact of hype can be far-reaching and crippling,” said Dragos.

Dragos called Trisis a “learning moment” in relation to its status as the first malware to attack safety systems. They explained that it is a specifically designed malware that is not capable of a high-scaled attack. Trisis did not expose a vulnerability in Triconex.

The malware works based on an “understanding [of] how Triconex SIS devices function,” Dragos said. It uses “ladder logic to create the desired impact on the target SIS.”

SIS systems, though used in a variety of industries, are based on specialized services and industry knowledge, according to Schneider Electric. This protects industrial SIS systems from scaled attacks.

Dragos supported Schneider Electric:

“This was a clear attack on the community. There can be no victim blaming or product shaming that is reasonable nor will it make the community better. The implication is that adversaries are targeting SIS and defenders must live in this reality presented adapting as appropriate to ensure safety and reliability of the operations our society depend upon.”

Homeland Security News Wire called Triton a “watershed attack.” It ended when “the SIS controllers initiated a safe shutdown when application code between redundant processing units failed a validation check.”

Operators then found the hostile code. Although this is the only known attack of malware on safety systems and did not cause real damage, its existence remains a threat.

Source of Attack

“I don’t expect this to show up in Europe and North America, but the adversary has created a blueprint to go after safety systems,” Lee said. “That tradecraft is what they’re testing out.”

The cybersecurity company FireEye asserts that responsibility for the attack is unknown, a nation state likely sponsored it.

“The targeting of critical infrastructure as well as the attacker’s persistence, lack of any clear monetary goal and the technical resources necessary to create the attack framework suggest a well-resourced nation state actor,” FireEye said.

Damage sustained industrially can have far-reaching effects beyond the scope of the plant. A chemical leak or burst pipe that a safety system fails to alert could result in environmental disaster.

Dragos offers tips for defense in their analysis that include putting safety systems on isolated networks and restricting access to safety controllers. Trisis is a sophisticated system, but cybersecurity companies are aware of it and forthcoming with information on how to counter it.

About Breanna Kane

A happy realist, I like finding new ways to tackle age-old processes through writing and debate. In my spare time, I’m perfecting the argument that proper neutrality is not passive.

Have a tip we should know? tips@rhd.news

Most Read

  1. News
    Pandora Papers Financial Leak Shows Us the Secrets of the World’s Rich and Powerful
    3 years ago
  2. Health
    US Supreme Court Rejects J & J TALC Cancer Case Appeal
    3 years ago
  3. Lifestyle
    9 Habits that Drain your Daily Focus and How to Avoid Them
    3 years ago
  4. BUSINESS
    Women’s Demand for Shapewear – the big Trends
    3 years ago
  5. BUSINESS
    Valentino Launches its Cosmetics Line
    3 years ago
  6. Health
    US Promises to Share 60 million Doses of AstraZeneca Vaccines
    3 years ago
  7. Health
    UK Offers Aid Amid Surging COVID-19 Cases in India
    3 years ago
  8. Sports
    Thousands of fans welcome Charlton funeral cortege at Old Trafford
    5 months ago
  9. News
    Brit left fighting for life after train derails in Argentinia
    5 months ago
  10. BUSINESS
    Dubai faces down airline rivals with $50 bln jet orders
    5 months ago
  11. Sunak
    UK’s Sunak brings back Cameron, sacks Braverman
    5 months ago
  12. Sports
    Man United’s Hojlund, Eriksen withdrawn from Denmark team duty
    5 months ago
  13. Health
    Autumn Sneezing Syndrome is on the rise… here’s what you can do
    5 months ago
  14. Canada
    Canada beat Italy to win Billie Jean King Cup for first time
    5 months ago

Follow @rushhourdaily: