The electrical grid constitutes of legacy systems that were built with no security in mind. As we move towards the Industry 4.0 area though a high-degree of automation and connectivity provides: 1) fast and flexible configuration and updates as well as 2) easier maintenance and handling of misconfigurations and operational errors. Even though considerations are present about the security implications of the Industry 4.0 area in the electrical grid, electricity stakeholders deem their infrastructures as secure since they are isolated and allow no external connections. However, external connections are not the only security risk for electrical utilities. The Tactics, Techniques and Procedures (TTPs) that are employed by adversaries to perform cyber-attack towards the critical Electrical Power and Energy System (EPES) infrastructures are gradually becoming highly advanced and sophisticated. In this article we elaborate on these techniques and demonstrate them in a Power Plant of the Public Power Corporation (PPC). The demonstrated TTPs allow to exploit and execute remote commands in smart meters as well as Programmable Logic Controllers (PLCs) that are responsible for the power generator operation.
翻译:电网由早期未考虑安全因素构建的传统系统组成。然而,随着工业4.0时代的到来,高度自动化与互联互通带来了:1)快速灵活的配置与更新;2)更便捷的维护以及对配置错误和操作失误的处理。尽管工业4.0时代电网的安全影响已受到关注,但电力行业利益相关者仍认为其基础设施是安全的,因为这些系统处于隔离状态且不允许外部连接。然而,外部连接并非电力设施面临的唯一安全风险。攻击者针对关键电力与能源系统(EPES)基础设施实施网络攻击所采用的战术、技术与程序(TTPs)正逐渐变得高度先进和复杂。本文详细阐述了这些技术,并在希腊公共电力公司(PPC)的一座发电厂中进行了演示。所演示的TTPs能够利用并远程执行智能电表以及负责发电机运行的可编程逻辑控制器(PLCs)中的远程命令。