# Analyzing security in industrial automation systems

(security-principles)=
## Security principles

Based on the [preparation](security-preparation):

:::{wpd} Principle of least privilege
... requires that every component of a computer system, e.g., program, user, must be able to access only the information and resources that are necessary for its purpose.
:::
:::{wpd} Defense in depth
:id: Defense_in_depth_(computing)
A concept in which multiple layers of defense are placed through a system
:::
:::{wpd} Fail-safe
A design feature or practice that, in the event of a failure of the design feature, inherently responds in a way that will cause minimal or no harm to its environment.
:::
:::{wpd} KISS principle
A design principle that implies that *simplicity* should be a design goal.
:::
:::{wpd} Separation of duties
The concept of having more than one person required to complete a task.
:::

Open design
: A design which is publicly available so it can be built or understood.

Segmentation
: Division of a system into multiple isolated subsystems. Different subsystems can have different security requirements.

:::{wpd} Usability
Capacity of a system to provide a condition for its users to perform the tasks safely, effectively, and efficiently while enjoying the experience.
:::
E.g., users use post-its if the password requirements are hard to remember.

:::{wpd} Attack surface
The sum of a software environment's different points where an attacker can try to enter data to, extract data from, or control a device or critical software.
:::
We should minimize the attack surface.

Secure by default
: All the security features of a system are turned on when a product is delivered.

## Activity

::::{activity} Analyzing attack surface
Open the diagram on [Guide to Operational Technology (OT) Security - Section 2.3.4 Programmable Logic Controller-Based Topologies](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-82r3.pdf#%5B%7B%22num%22%3A185%2C%22gen%22%3A0%7D%2C%7B%22name%22%3A%22XYZ%22%7D%2C70%2C720%2C0%5D)

1. You see the following components on the diagram:

   1. `Engineering Workstation`
   1. `Data Historian`, i.e., [Operational historian](https://en.wikipedia.org/wiki/Operational_historian)
   1. [`PLC`](https://en.wikipedia.org/wiki/Programmable_logic_controller)
   1. `Photo Eye`, i.e., [Photoelectric sensor](https://en.wikipedia.org/wiki/Photoelectric_sensor) <!-- proximity sensors are based on electromagnetic signals, magnetism etc (https://kwoco-plc.com/proximity-vs-photoelectric/)-->
   1. `HMI`, i.e., human–machine interface; a kind of [user interface](https://en.wikipedia.org/wiki/User_interface)
   1. [`Servo Drive`](https://en.wikipedia.org/wiki/Servo_drive), [Variable-frequency drive](https://en.wikipedia.org/wiki/Variable-frequency_drive), i.e., motor controller electronics <!-- Difference: Servo drive has feedback-->
   
   We have in the laboratory the following components:
   
   1. Robot arm
   1. Gripper
   1. Sensors, e.g., photoelectric sensors, limit switch, camera for object identification
   1. Pendant
   1. Ethernet cable
   1. Your computer
   
   Match the laboratory components to the components in the diagram. In other words, which component on PLC control system implementation example represents which component in our laboratory?
1. Draw a similar diagram using the components in our laboratory. Also include the human user.
1. :::{wpd} Attack vector
   A specific path, method or scenario that can be exploited to break into an IT system. The term was derived from the [*disease vector*](https://en.wikipedia.org/wiki/Disease_vector) in biology.
   
   Examples: 
   
   - [phishing](https://en.wikipedia.org/wiki/Phishing) leading to unauthorized access to a computer
   - [malware](https://en.wikipedia.org/wiki/Malware) infection resulting in manipulation or stealing of a database
   - exploiting a security vulnerability in a PLC's administrative web interface causing denial of service or unwanted control actions like driving the motors above their limits. Specific example: [SQL injection](https://en.wikipedia.org/wiki/SQL_injection)
   :::

   Identify potential *attack vectors* on the diagram you have drawn.
1. Imagine that your attack vectors are successful. List at least three consequences. Example perspectives: IT, OT, business.
1. Pick at least three principles from the section {ref}`security-principles` to secure your system against the attack vectors you have chosen.
::::
<!-- TODO don't they need some examples of breaches? -->