Despite Stuxnet, Duqu, control system flaws still overlooked

20.10.2011

The report reignited fears about cyberattacks targeted at the control systems behind equipment at critical infrastructure such as power plants, water treatment facilities and chemical plants.

The problem, though, is that the concerns so far have focused on the front-end, mostly Windows-based Human Machine Interface (HMI) systems that are used to interact with control systems, Peterson said.

Many flaws that have been described as control systems flaws have really been at the front-end engineering workstation layer.

For example last month, Italian researcher Luigi Auriemma in Supervisory Control and Data Acquisition (SCADA) products from multiple vendors including Rockwell Automation, Cogent Datahub, Measuresoft and Progea.

Earlier this year, Auriemma had disclosed similar flaws in products from Siemens, Iconics, 7-Technologies and Datac. Most of the flaws were at the HMI layer.