Many control-system owners don't block DNS traffic on network segments they believe are isolated, researcher finds Many organizations that run industrial control systems strive to isolate them from the Internet, but sometimes forget to disallow Domain Name System (DNS) traffic, which provides a stealthy way for malware to exfiltrate data. Sometimes referred to as supervisory control and data acquisition (SCADA) systems, industrial control systems (ICS) are notoriously insecure. Not only is their firmware full of flaws, but the communication protocols many of them use lack authentication or encryption. Since most ICS systems are typically meant to last over a decade once deployed, they’re not easily replaceable without considerable costs. As such, ICS operators tend to focus on securing the perimeter around control systems instead of patching the devices themselves, which is not always possible. This is done by isolating ICS environments from corporate networks and the larger Internet, an action sometimes referred to as airgapping. According to Reid Wightman from ICS security consultancy firm Digital Bond, control systems owners often believe that their critical environments are airgapped when they’re actually not. One thing that his team often discovers while performing security assessments for customers is that they have blocked Internet communications, but forgot about DNS. Wightman didn’t have specific numbers to share, but this oversight is common enough that he decided to dedicate half of his presentation Thursday at the S4xEurope conference to it. DNS is used to translate human-readable host names into numerical Internet Protocol (IP) addresses that computers need to talk to each other. It is a core component of the Internet, but it’s also used inside local networks for computers to find each other more easily. The problem is that DNS requests can be used to send data in and out of a network by crafting DNS queries and responses to and from domain names owned by attackers. This technique, known as DNS tunneling, has been known for years and has been used by malware in the past. The most recent example is from a cyberespionage group called Wekby, which for the past several years has been targeting organizations from the healthcare, telecommunications, aerospace, defense and high-tech industries. In May, researchers from security firm Palo Alto Networks reported that the group’s latest malware tool is using DNS tunneling to communicate with its command-and-control server. Wightman hasn’t seen any ICS-specific malware using DNS tunneling to escape network isolation, but the technique is certainly viable. Malware can be introduced into isolated ICS environments by insiders or contractors on infected USB drives, like in the case of the Stuxnet cybersabotage worm that infected Iran’s nuclear plant at Natanz. The best way to mitigate this problem would be to ban DNS entirely for the ICS environment, but in cases where local DNS is needed, the DNS server should be configured to reject DNS queries to external domains, Wightman said. “For example, control zone DNS forwards requests for corpdomain.com to corporate DNS, and rejects queries for any other domain.” Related content news Nvidia teases quantum accelerated supercomputers Nvidia debuts systems powered by Grace Hopper superchips, adds AI and quantum to the HPC mix. By Lynn Greiner May 13, 2024 4 mins CPUs and Processors Supercomputers Data Center news Cisco adds AI features to AppDynamics On-Premises A new virtual appliance for Cisco's AppDynamics observability platform will give enterprise customers more deployment options as well as AI-driven capabilities for anomaly detection and root cause analysis, application security, and SAP monitori By Michael Cooney May 10, 2024 4 mins Network Management Software Network Monitoring news CHIPS Act to fund $285 million for semiconductor digital twins Plans call for building an institute to develop digital twins for semiconductor manufacturing and share resources among chip developers. By Andy Patrizio May 10, 2024 3 mins CPUs and Processors Data Center news Microsoft’s AI ambitions fuel $3.3 billion bet on Wisconsin data center The Mount Pleasant site was initially earmarked for a manufacturing plant operated by electronics giant Foxconn. By Sascha Brodsky May 10, 2024 6 mins Data Center PODCASTS VIDEOS RESOURCES EVENTS NEWSLETTERS Newsletter Promo Module Test Description for newsletter promo module. Please enter a valid email address Subscribe