IT/CYSE 200T

Cybersecurity, Technology, and Society

In IT/CYSE 200T I explored how technology is related to cybersecurity from an interdisciplinary orientation. Attention is given to the way that technologically-driven cybersecurity issues are connected to cultural, political, legal, ethical, and business domains.

A few topics of discussion

SCADA Systems

In this write up, I explore the need for securing SCADA systems, as they are critical infrastructure that all of us depend on. In modern SCADA systems, we rely on many analogue and air gapped systems that can be vulnerable to attack if not remediated.

Introduction

SCADA systems are an integral part of our lives, they control all of the essential infrastructure, including water treatment, airports, energy pipelines and countless other industrial processes. SCADA stands for Supervisory Control and Data Acquisition. It describes a process of taking industrial apparatus’ and translating their physical state into digitized states which allows them to have their events logged, and their actions controlled remotely. This has given us an unprecedented surge in performance, accountability, and service continuity. Though this unprecedented rise of automation and convenience has exploded, it poses a significant security risk if left unguarded.

SCADA functionality

SCADA systems work through a straightforward system. The Apparatus that controls the actual process is at the head. This is usually a human interfaced device with an operator that oversees the process. The next step is a supervisory system that observes and collects data about the process. After this, the Remote Terminal Units translate the data collected by the supervisory unit and translates it into digital data that can be sent over conventional networks. Finally Programmable logic controllers act as the intermediary between a conventional network and the rest of the SCADA system.

To elaborate on the PLC and RTU, The RTU sits between the HMI and the PLC, the RTU is what allows the PLC to control the apparatus, by translating the analog/physical status of the apparatus into digital values. This allows the PLC to send those digital values like any other packet on a network, to be logged and stored in a server, while also allowing the apparatus’ to be automated, or controlled remotely. SCADA networks tend to be air gapped networks, meaning they are isolated from the internet, and cannot be remotely accessed from any part of the internet, you must physically be on the network with the SCADA system to access it. This is the most secure aspect of SCADA networks, as this prevents the remote access of anyone to manipulate these systems.

SCADA threats and remediations.

To start with the things that SCADA systems do well: As mentioned before, SCADA systems are air gapped and are immune from most threats that affect other digital devices with internet connectivity. In theory, an air gapped network, and stringent security controls should allow for a low-risk vector. However, certain threats still exist and are very real. Later, In the persuall article it mentions the lack of non-repudiation when sending packets to SCADA devices anyone can tap a wire and intercept packets, and modify them, or simply send packets to the devices and control them. For example, a vulnerability that effects Mitsubishi electric SCADA systems, it details a arbitrary code execution that allows a local attacker to execute any code. Yet again proving the need for local authentication.

A simple fix would be to mandate a way to prove any computer on the network is who they say they are. A MAC address whitelist would be ideal and would prevent anyone from accessing the network with a wire splice. To take it a step further, you would implement a certificate authority that certifies that computers making modifications are who they say they are.

Conclusion

SCADA systems have provided a great explosion in productivity and continuity in so many of our essential systems we rely on as a society every day. Though SCADA systems are mostly secure, from most threats, they are still not immune to all threats. They must be secured, and accounted for to make sure no hostile actor can interfere with our infrastructure.

Bibliography

Cybersecurity and Infrastructure Security Agency. (2026, April 7). Mitsubishi Electric Iconics Digital Solutions and Mitsubishi Electric Products (Update C) (ICSA-24-338-04).

CIA triad

In this write up, I explore the guidelines of the Information security concept known as the CIA triad. The CIA triad is a tool used to identify what service a product is providing, if it is providing, security, uptime, or en during your data has not been tampered with.

 

The CIA triad is a concept used by IT security professionals, in order to assess and analyze the functionality of Information Systems. The CIA triad stands for Confidentiality, Integrity, and Availability. Authentication and Authorization are part of the CIA triad as well, however they relate more to the Confidentiality part of the triad.

There is no singular product that can provide all three, however all three must be in tandem for a functional enterprise IT, big or small. The importance cannot be understated as all three are required at all times.

At a high level overview, Confidentiality, means protecting data, data transmissions, and applications from those who should not see it. This includes access control, and restrictions on viewing and access to the data. This also includes transmissions of data, for instance packets being sent in and out of the network. Encryption offers confidentiality of data, and is a necessity in this day and age. As Chai said in their article “Data should be encrypted using 2FA” which bleeds into authentication, which will be addressed in a second (Chai 2022).

However this begs the question of those who need to access the data? What do those who need the data, documents, or applications to complete their day to day tasks do? If you are granted access to the data, you must be Authorized to use it. Authorisation means that you are granted access to a network, application, or document. After you are authorized to use a resource, you must Authenticate your identity in order to access the resources. Authentication comes in many forms, most commonly a password, or another token. A good authentication method is to have a multifactor approach, where the person accessing resources must have two factors to prove themselves, whether it is Something-you-have, such as a security token or one-time-passcode, or a Something-you are type of authentication, like a biometric such as your fingerprint or retina scan.

The two should not be confused as they are seemingly similar, but much different from each other. Think of Authorization as being on the VIP list into a club, and Authentication as your drivers license as proof that you are who you say you are.

Integrity is ensuring that data is not tampered or manipulated with. This is mostly used in data transmissions, but has application in data and documents. Integrity comes in many forms, including but not limited to, Hashing, Checksums, Read-access, restricting edit access, and access logs. All of these are forms of protecting data from unwanted manipulation.

Availability is the act of having your services available. More specifically the act of being available in the event of a malfunction, failure, or disaster. An important part of availability is “ensuring data recovery and business continuity” in the event of a disaster or loss of service (Chai 2022). One of the most minor acts of availability is having RAID set up on hard drives in the case of failure. RAID ensures that if one hard drive fails, another is there with the data available on the other.

A more severe case of availability is a power or ISP failure, if your power goes out in the event of a disaster, you should have generators or UPS’s available to power devices down safely. If your ISP were to have an outage, it is prudent to have a secondary internet line available in order to run data over.

A more extreme case of availability is a natural disaster, you should have a secondary site ready. These can be cold sites, which are basic aspects of your system such as the site or some racks ready to transfer the equipment over. A hot site is essentially a 1:1 copy of your system, up to date with hardware and backups of your system.

The CIA triad is the backbone of information systems, and following the guidelines set in it is important and should not be ignored. Implementing all of these controls, and products is non-negotiable, and redundancy is key in all three pillars of the triad.

Works Cited

Chai, Wesley. “What is the CIA Triad? Definition, Explanation, Examples.” Tech Target, 22 Sept. 2022.

Malicious code

In this short discussion, I explore how DNA was used to create a SQL injection attack on a database of the human genome, and how I believe that this is an easily preventable attack.

In my opinion, the “vulnerability” that was discovered by security researchers was complex, in its execution, however it fails to satisfy the requirements of being a threat (as of writing this), as it is for a public, freely available asset such as the human genome. It is not a new attack, as it is a sort of injection attack that leads to a buffer overflow, that can lead to arbitrary code execution. The attack is sophisticated as the origin is not of classical computing, and makes it intriguing. In order to mitigate the risk of privilege escalation and arbitrary code execution, researchers reccomen d that and uploaded DNA is uploaded to containers or VM’s that keep and damage contained to it. Another step that can be taken is to have the input manually validated after the isolated upload, and only accept uploads from trusted people, or have the DNA linked to a known organism. The researchers arbitrarily wrote code, and then translated it to ASCII to map the peptides, and then uploaded it to their program. Input validation, much like counters to SQL injections, would solve this problem. We must input validate as bad actors could attempt to erase all of the progress made on genome research, weather for financial, religious, or ethical reasons. Not accepting input from everyone makes the most logical sense as not everyone has DNA to upload. Trusting every human to upload is reckless, and despite the ethical implications of granting access to only a few qualified researches, is the best course of action in the long run.