SlideShare a Scribd company logo
Digital Maintenance and Test
Equipment and Impact on Control
System Security
Mike Toecker, PE
Context Industrial Security
@mtoecker
Introduction
• Professional Computer Engineer (USA-
MO)
– Specialized in Computer Security for
Industrial Systems
• Currently, Owner/Engineer at Context
Industrial Security
– Former Burns and McDonnell
Engineering
– Former NextEra Energy
– Former Digital Bond
• 10 Years in Cyber Security for ICS
– Fossil/Hydro/Nuclear Power Plants,
Transmission, Control Centers, Mine,
Water Treatment, Distribution, Gas
Processing/Transport
First, a Message from the
Goat of Honesty and Truth
I’m unaware of any incidents,
public or private, where
malicious hacked M&TE has
been the cause of an industrial
cyber security incident.
This has been a message from
the Goat of Honesty, Integrity,
and Empirical Evidence.
Maintenance and Test
Equipment (M&TE)
M&TE is a class of industrial
equipment that aids maintenance and
engineering personnel in ensuring the
reliability, efficiency, and profitability
of electrical and mechanical systems
and equipment.
It can be considered part of the on-site
implementation of Reliability
Engineering principles.
BASICALLY…. M&TE IS EQUIPMENT
USED TO MAINTAIN AND TEST OTHER
EQUIPMENT
You’ve Seen M&TE,
Likely Didn’t Realize It
An automobile has lots of control
systems, some are just plain
mechanic, many are digital. The
digital ones are hackable. We know
this for sure, thanks to Miller and
Valasek.
What we don’t think about are the
digital tools used to evaluate
whether or not an automobile is
ready to return to the road.
If some of these look like Control
Systems, it’s cause they are.
Battery Test
Automatic
Alignment
Engine Diagnostic (OBD-II/EOBD)
Computerized Balancing
Emissions
Compliance
I NEED A NEW
ALTERNATOR?!?!
Maintenance and Test Tools were
developed to provide objective
guidance on replacement and repair of
expensive components.
For me, it was the difference between
driving home happy, and driving home
$500 poorer.
I went home $500 poorer, because a
computer told me to.
Industrial Facilities Differ Only in Scale
ICS Compared to M&TE
• Operations Focus
• Networked
• Monitor the Industrial
Process in Real-Time
• Generally Fixed Assets,
Installed in Facility
• Maintenance Focus
• Rarely Networked
• Evaluate Specific
Criteria Associated with
Process Equipment
• Mobile, Often
Handheld, Goes from
Site to Site
THE VULNERABILITY OF M&TE
Trend Towards Digital
Equipment
Digital Equipment is all the rage these
days. Generally, digital measurement
of analog signals is more error-proof
and reliable, with a far greater degree
of accuracy than the older analog
meters.
With digital, you also get the capability
to record your data, compare it to
other recordings, trend it, analyze it
with advanced math packages.
In short, it’s kinda a win.
The Usual Digital
Vulnerabilities
M&TE has taken the same path as ICS,
adoption of the commercial hardware
and software into the products used
on industrial equipment.
Examples:
1. Automated Analyzer using MS
Access and WinXP
2. Firmware updates without code
signing, passwords, or other
means of control
3. Calibrators running BusyBox Linux
4. HART Descriptors Updateable Via
Plain Jane HTTP
Bring Your Own Device;
Industrial Edition
Because of economics, accounting
practices, and work load, this kind of
maintenance and testing work is
routinely outsourced to external
companies.
To the right are snippets of language
from an RFP for Substation Testing
Services, which is reasonably typical.
There was no mention of cyber
security in this RFP.
Demonstrates Known Concern that Testing Agents
have a lot of power to recommend expensive
changes
So, how do you think they are upgrading this
firmware in the relay? (Hint: The answer is laptop)
Consequences of Malicious
Interference are Different
ICS M&TE
Consequences of hacking M&TE and
using it maliciously are going to be
different than hacking ICS.
Digital Calibration and
Interface
Handheld devices and laptops used for
interacting with digital transmitters are
pretty ubiquitous at many sites. These
have some very advanced capabilities,
often outside of the operator’s
purview and cyber security
monitoring.
The most interesting ones get firmware
updates and device descriptors from the
internet, downloaded directly into the
handheld.
This is an area I’m planning to explore
extensively over the next few years.
Motor Condition
Evaluation
There are few industrial facilities that
don’t have motors, these are tested via
automated systems that check the motor
for shorts, dirt, and poor insulation
quality.
Valve Testing
Maintenance of Valves is a big deal in a
lot of industrial facilities. Many valves
MUST close if required due to safety
reasons, so testing is performed to
ensure the valve is capable of closing.
Other valves are important to the
process, and are evaluated for
problems on a consistent basis .
Valves which fail tests are swiftly
replaced.
Facilities with these valves often used
portable test suites to initiate,
monitor, and determine pass/fail of a
valve. Common tests are partial stroke,
full stroke, and valve stability. The green valve has a smart positioner, which is
calibrated using either a HART or Fieldbus
connection, and can aid automated testing.
Relay Testing and
Validation
Utilities and other industrials with
large power requirements must test
protective relays to ensure they work
under all conditions.
Automated rigs sets are the usual way
these tests, often regulatory required,
are performed.
Binary and
Analog Test Leads
USB
IEC/61850
PoE/Ethernet
Bluetooth
Eddy Current Testing
This type of testing is used to find
deformities and weaknesses in tubing,
pipes, tanks and other large metal
components, preferably before leaks,
cracks, or breaks happen.
There are many variations of this,
many industries need ways to inspect
piping without opening/digging it up.
The Illustration above was via the
Non-Destructive Testing Resource
Center.
https://www.nde-
ed.org/EducationResources/educati
onresource.htm
Ground Tests, and other
Major Electrical Tests
0
10
20
30
40
50
60
0 50 100
Resistance vs %Distance
Resistance
We often need to know the electrical
characteristics of a system, such as
whether it has a good or bad ground,
in order to diagnose problems
effectively.
USB Interface to PC
Other M&TE
• Gas Analysis – Transformer
Health
• Ultrasonic Testing - Pipe
Thickness
• Vibration Analysis – Health
of Rotating Equipment
There’s a lot I didn’t cover, I tried to hit
the high points. However, there is a
lot more out there, and a lot of it is
industry specific.
SO, WHAT MIGHT AN M&TE HACK
LOOK LIKE?
Motor Test Hacking
Motors are a major component of any
industrial facility. They don’t last
forever though, and they are pretty
expensive components to replace.
Pricing taken from “W22 Severe Duty Motors – TEFC” on
weg.net and subject to change without notice
Some Motor Tests
• Kelvin Method Winding
• Meg-Ohm
• Polarization Index (PI)
• Step-Voltage
• Surge Test
Major problems in the motor often
result from:
• Ground Wall Insulation
• Turn to Turn Insulation
• Phase to Phase Insulation
Most motor failures on the electrical
side come from insulation going bad,
and getting a short somewhere in the
motor.
Surge Test Process
Charge up
Capacitor to a
Voltage Setpoint
Discharge Capacitor
into Single Phase
(sometimes Two)
Charge Dissipation
Produces a
Characteristic
Waveform
Record the
Waveform and
Associated Data
Compare the Current
Waveform to Previous
Waveform Using
ppEAR or Similar
Increase the
Voltage Setpoint
per Test Spec
The technical explanation is that the
impulse from the capacitor will
discharge into the winding, resulting in
a wave with a characteristic response.
That characteristic response is stored
and compared the previous.
START
STOP
Source: http://www.maintenancetechnology.com/2007/03/dc-step-voltage-and-
surge-testing-of-motors/
The fun
explanation is
that we are hitting
a punch-me clown
repeatedly, harder
each time, to see
if it does
something
different than last
time.
Failure Criteria #1
If the frequency of any resulting
waveform shifts to the left, the motor
is either bad or going bad.
The white line has shifted to the left,
or using other words has a different
zero crossing. This motor is bad, or is
going bad.
This is when the punch-me clown goes
down, loses grip with the floor,
bounces, and/or doesn’t come back up
the same way.
Source: http://www.maintenancetechnology.com/2007/03/dc-step-voltage-and-
surge-testing-of-motors/
Failure Criteria #2
If the changes between each of the
pulses result in a different waveform
(about 4-5% difference is normal),
then the motor is bad, or going bad.
This is measures with an equation
called Error Area Ratio. It’s basically a
percentage difference between two
voltage measures taken at the same
time in the test.
The dotted line in the EAR subgraph is
at 4-5%.
Source: http://www.existest.com/appnotes/Baker/Teoria%20Surge.pdf
That’s the EAR, you see it go off the chart, which signals a
response dramatically different from the previous.
Aside: Why Does This
Work?
Every Played F-Zero? The Cloud Carpet Track of
the Icarus Circuit illustrates this well.
If the racetrack is a motor winding, Point D is a
short circuit. But, you can’t USE Point D until
you gain get enough of a top speed to jump all
the way over. That top speed is where the
insulation in the motor allows a short.
Please Don’t Sue Me Nintendo, I love you.
PROCESS TO FAKE A SIGNAL
Discuss the process.
Consequences
Bad Motor Reports as Good
• Failure of the Motor is a
Given at Some Point
• No Maintenance Activity to
Open It Up For Inspection
• Impossible to Determine
How Much Life is Left
• Impact Depends on Motor
Function
Good Motor Reports as Bad
• Engineering will Evaluate the
Motor for Useful Life
• Motor will be removed, or
scheduled for removal
• Money spent to order, design,
install, and test new motor.
• **Possible the motor will be
sent to 3rd party for testing**
Attackers Want
To Minimize Discovery Risk
Bad Motor Reporting as Good Good Motor Reporting as Bad
It’s Tough to Test Molten Slag for Irregularities
PROTECTION AND MITIGATION
Step 1: Identify Your High
Consequence Equipment
Talk with the engineers and operations,
most of them either know what
equipment they have that, if it fails,
presents a High Consequence. If they
don’t know already, they usually have
the means to do so.
High Consequence, No Particular Order:
1. High Cost of Replacement
2. Personnel Safety Concerns
3. Negative Impacts to the Process
4. Regulatory Requirements
Step 2: Identify Tests Done on
High Consequence Equipment
Likely, this will require discussions with
engineers and maintenance personnel,
as operations may not have the
definite answers for this question like
they normally due.
Tests will depend on the equipment.
Figure out the methodology, accuracy,
what measures are taken to prove a
test, etc.
Step 3: Evaluate Susceptibility
to Malicious Cyber Influence
Looking at each test, and the
equipment used to perform it, identify
how susceptible it is to malicious
influence.
You’re looking for cyber vulnerable
equipment, equipment provided by
third parties, poor firmware update,
etc. This is basically a high level device
risk assessment.
Rate them on a scale:
10 – Highly Susceptible
…
1 – Not Susceptible
Step 4: Identify and Apply
Protective Measures
Physical
Protection
Lock Up When Not
in Use
Allow Use By Only
Qualified
Individuals
Place Tamper
Evident Seals
Create “Test
Checks” to provide
confirmation of
Tests
Cyber
Protection
Block Firmware
Update
Mechanisms
Check Firmware
Signatures w/
Vendor
Remove Network
Access that is Not
Required
Heavily Restrict
Portable Media
Usage
Vendor
Protection
Require Pre-Site
Evaluation of
Equipment
Require Use of
Special Hardened
Laptops
Consider Altering
Calibration
Requirements to
Include Cyber
As these aren’t traditional IT devices, the
usual protections may not be applicable.
Define a set of protective measures that
reduce risk from the identified
vulnerabilities, and then apply them in
order greatest to least susceptibility.
Remember, we’re already focusing on
the most high consequence equipment
already.
Some basic protections are to my left,
this is a min-max area as it’s very easy to
affect maintenance’s processes ($$$).
Are There Any Questions?

More Related Content

What's hot

Why you should conduct electrical preventive maintenance
Why you should conduct electrical preventive maintenanceWhy you should conduct electrical preventive maintenance
Why you should conduct electrical preventive maintenance
Heather Jarmusz
 
IRJET - Automated Monitoring Test Rig for Circuit Breaker Operation
IRJET -  	  Automated Monitoring Test Rig for Circuit Breaker OperationIRJET -  	  Automated Monitoring Test Rig for Circuit Breaker Operation
IRJET - Automated Monitoring Test Rig for Circuit Breaker Operation
IRJET Journal
 
AlLERT Life Cycle Sustainment.
AlLERT Life Cycle Sustainment.AlLERT Life Cycle Sustainment.
AlLERT Life Cycle Sustainment.
Mike Kellner
 
Jason Lowe I_C HMI Devloper
Jason Lowe I_C HMI DevloperJason Lowe I_C HMI Devloper
Jason Lowe I_C HMI Devloper
Jerome Lowe
 
Electrical Distribution Maintenance Services Guide
Electrical Distribution Maintenance Services GuideElectrical Distribution Maintenance Services Guide
Electrical Distribution Maintenance Services Guide
Thorne & Derrick International
 
Introduction to Functional Safety and SIL Certification
Introduction to Functional Safety and SIL CertificationIntroduction to Functional Safety and SIL Certification
Introduction to Functional Safety and SIL Certification
ISA Boston Section
 
Hire me!
Hire me!Hire me!
Hire me!
Vijay Persaud
 
Case study of dcs upgrade how to reduce stress during execution
Case study of dcs upgrade how to reduce stress during executionCase study of dcs upgrade how to reduce stress during execution
Case study of dcs upgrade how to reduce stress during execution
John Kingsley
 
drewresume72014
drewresume72014drewresume72014
drewresume72014
Drew Princiotta
 
Functional Safety (SIL) in the Subsea and Drilling Industry
Functional Safety (SIL) in the Subsea and Drilling IndustryFunctional Safety (SIL) in the Subsea and Drilling Industry
Functional Safety (SIL) in the Subsea and Drilling Industry
Lloyd's Register Energy
 
Roman Nemish. Global IoT Technologies, Most Common Use Cases and Success Stra...
Roman Nemish. Global IoT Technologies, Most Common Use Cases and Success Stra...Roman Nemish. Global IoT Technologies, Most Common Use Cases and Success Stra...
Roman Nemish. Global IoT Technologies, Most Common Use Cases and Success Stra...
IT Arena
 
Electrical Engineering Design And Consulting
Electrical Engineering Design And ConsultingElectrical Engineering Design And Consulting
Electrical Engineering Design And Consulting
Current Solutions PC
 
What is the IPC-JSTD-001 Certification Program
What is the IPC-JSTD-001 Certification ProgramWhat is the IPC-JSTD-001 Certification Program
What is the IPC-JSTD-001 Certification Program
Bob Wettermann
 
Controlling interests editors
Controlling interests editorsControlling interests editors
Controlling interests editors
eldhoev
 
THRIS WEB PAGE 1999
THRIS WEB PAGE 1999THRIS WEB PAGE 1999
THRIS WEB PAGE 1999
Piero Belforte
 
Digital Procurement in the Nuclear Industry: Tips on Embracing New Technologies
Digital Procurement in the Nuclear Industry: Tips on Embracing New TechnologiesDigital Procurement in the Nuclear Industry: Tips on Embracing New Technologies
Digital Procurement in the Nuclear Industry: Tips on Embracing New Technologies
ATC
 
Camera Encoded Phased Array for Semi-Automated Inspection of Complex Composit...
Camera Encoded Phased Array for Semi-Automated Inspection of Complex Composit...Camera Encoded Phased Array for Semi-Automated Inspection of Complex Composit...
Camera Encoded Phased Array for Semi-Automated Inspection of Complex Composit...
Innerspec Technologies
 
PRINT
PRINTPRINT
Power System Engineering Training
Power System Engineering TrainingPower System Engineering Training
Power System Engineering Training
Tonex
 
J-STD-001, IPC A-610 F to G Differences Webinar
J-STD-001, IPC A-610 F to G Differences WebinarJ-STD-001, IPC A-610 F to G Differences Webinar
J-STD-001, IPC A-610 F to G Differences Webinar
Bob Wettermann
 

What's hot (20)

Why you should conduct electrical preventive maintenance
Why you should conduct electrical preventive maintenanceWhy you should conduct electrical preventive maintenance
Why you should conduct electrical preventive maintenance
 
IRJET - Automated Monitoring Test Rig for Circuit Breaker Operation
IRJET -  	  Automated Monitoring Test Rig for Circuit Breaker OperationIRJET -  	  Automated Monitoring Test Rig for Circuit Breaker Operation
IRJET - Automated Monitoring Test Rig for Circuit Breaker Operation
 
AlLERT Life Cycle Sustainment.
AlLERT Life Cycle Sustainment.AlLERT Life Cycle Sustainment.
AlLERT Life Cycle Sustainment.
 
Jason Lowe I_C HMI Devloper
Jason Lowe I_C HMI DevloperJason Lowe I_C HMI Devloper
Jason Lowe I_C HMI Devloper
 
Electrical Distribution Maintenance Services Guide
Electrical Distribution Maintenance Services GuideElectrical Distribution Maintenance Services Guide
Electrical Distribution Maintenance Services Guide
 
Introduction to Functional Safety and SIL Certification
Introduction to Functional Safety and SIL CertificationIntroduction to Functional Safety and SIL Certification
Introduction to Functional Safety and SIL Certification
 
Hire me!
Hire me!Hire me!
Hire me!
 
Case study of dcs upgrade how to reduce stress during execution
Case study of dcs upgrade how to reduce stress during executionCase study of dcs upgrade how to reduce stress during execution
Case study of dcs upgrade how to reduce stress during execution
 
drewresume72014
drewresume72014drewresume72014
drewresume72014
 
Functional Safety (SIL) in the Subsea and Drilling Industry
Functional Safety (SIL) in the Subsea and Drilling IndustryFunctional Safety (SIL) in the Subsea and Drilling Industry
Functional Safety (SIL) in the Subsea and Drilling Industry
 
Roman Nemish. Global IoT Technologies, Most Common Use Cases and Success Stra...
Roman Nemish. Global IoT Technologies, Most Common Use Cases and Success Stra...Roman Nemish. Global IoT Technologies, Most Common Use Cases and Success Stra...
Roman Nemish. Global IoT Technologies, Most Common Use Cases and Success Stra...
 
Electrical Engineering Design And Consulting
Electrical Engineering Design And ConsultingElectrical Engineering Design And Consulting
Electrical Engineering Design And Consulting
 
What is the IPC-JSTD-001 Certification Program
What is the IPC-JSTD-001 Certification ProgramWhat is the IPC-JSTD-001 Certification Program
What is the IPC-JSTD-001 Certification Program
 
Controlling interests editors
Controlling interests editorsControlling interests editors
Controlling interests editors
 
THRIS WEB PAGE 1999
THRIS WEB PAGE 1999THRIS WEB PAGE 1999
THRIS WEB PAGE 1999
 
Digital Procurement in the Nuclear Industry: Tips on Embracing New Technologies
Digital Procurement in the Nuclear Industry: Tips on Embracing New TechnologiesDigital Procurement in the Nuclear Industry: Tips on Embracing New Technologies
Digital Procurement in the Nuclear Industry: Tips on Embracing New Technologies
 
Camera Encoded Phased Array for Semi-Automated Inspection of Complex Composit...
Camera Encoded Phased Array for Semi-Automated Inspection of Complex Composit...Camera Encoded Phased Array for Semi-Automated Inspection of Complex Composit...
Camera Encoded Phased Array for Semi-Automated Inspection of Complex Composit...
 
PRINT
PRINTPRINT
PRINT
 
Power System Engineering Training
Power System Engineering TrainingPower System Engineering Training
Power System Engineering Training
 
J-STD-001, IPC A-610 F to G Differences Webinar
J-STD-001, IPC A-610 F to G Differences WebinarJ-STD-001, IPC A-610 F to G Differences Webinar
J-STD-001, IPC A-610 F to G Differences Webinar
 

Similar to Maintenance and Test Equipment Cyber Security

New Tools for a Next Generation of Metering - TESCO Solutions
New Tools for a Next Generation of Metering - TESCO SolutionsNew Tools for a Next Generation of Metering - TESCO Solutions
New Tools for a Next Generation of Metering - TESCO Solutions
TESCO - The Eastern Specialty Company
 
TESCO Site Verification in a Pre and Post AMI World
TESCO Site Verification in a Pre and Post AMI WorldTESCO Site Verification in a Pre and Post AMI World
TESCO Site Verification in a Pre and Post AMI World
TESCO - The Eastern Specialty Company
 
Health Monitoring of Industrial and Electrical Equipment
Health Monitoring of Industrial and Electrical EquipmentHealth Monitoring of Industrial and Electrical Equipment
Health Monitoring of Industrial and Electrical Equipment
MAJAHARUL IMAM
 
Estimating Reliability of Power Factor Correction Circuits: A Comparative Study
Estimating Reliability of Power Factor Correction Circuits: A Comparative StudyEstimating Reliability of Power Factor Correction Circuits: A Comparative Study
Estimating Reliability of Power Factor Correction Circuits: A Comparative Study
IJERA Editor
 
Condition Monitoring of DC Motor using Artificial Intelligence Technique
Condition Monitoring of DC Motor using Artificial Intelligence TechniqueCondition Monitoring of DC Motor using Artificial Intelligence Technique
Condition Monitoring of DC Motor using Artificial Intelligence Technique
ijsrd.com
 
Field Test Kits and Hot Socket Repair Kits
Field Test Kits and Hot Socket Repair KitsField Test Kits and Hot Socket Repair Kits
Field Test Kits and Hot Socket Repair Kits
TESCO - The Eastern Specialty Company
 
Intrusive vs. Non-Intrusive Electric Actuators: Which option is right for you...
Intrusive vs. Non-Intrusive Electric Actuators: Which option is right for you...Intrusive vs. Non-Intrusive Electric Actuators: Which option is right for you...
Intrusive vs. Non-Intrusive Electric Actuators: Which option is right for you...
Mead O'Brien, Inc.
 
safety_critical_applications_and_customer_concerns
safety_critical_applications_and_customer_concernssafety_critical_applications_and_customer_concerns
safety_critical_applications_and_customer_concerns
Rufino Olay III
 
Mr DD update resume
Mr DD update resumeMr DD update resume
Mr DD update resume
David Duffin
 
BIST (Built-in-Self-Test) Features for Electronic Valve Actuators
BIST (Built-in-Self-Test) Features for Electronic Valve ActuatorsBIST (Built-in-Self-Test) Features for Electronic Valve Actuators
BIST (Built-in-Self-Test) Features for Electronic Valve Actuators
Mead O'Brien, Inc.
 
A-ConMonIntro.ppt
A-ConMonIntro.pptA-ConMonIntro.ppt
A-ConMonIntro.ppt
veeruyadav9
 
EE Reports Submetering 102 Guide
EE Reports Submetering 102 GuideEE Reports Submetering 102 Guide
EE Reports Submetering 102 Guide
EEReports.com
 
Circuit Break Connect Monitoring to 5G Mobile Application
Circuit Break Connect Monitoring to 5G Mobile ApplicationCircuit Break Connect Monitoring to 5G Mobile Application
Circuit Break Connect Monitoring to 5G Mobile Application
AIRCC Publishing Corporation
 
CIRCUIT BREAK CONNECT MONITORING TO 5G MOBILE APPLICATION
CIRCUIT BREAK CONNECT MONITORING TO 5G MOBILE APPLICATIONCIRCUIT BREAK CONNECT MONITORING TO 5G MOBILE APPLICATION
CIRCUIT BREAK CONNECT MONITORING TO 5G MOBILE APPLICATION
ijcsit
 
Field Testing
Field TestingField Testing
Meter Operations During and After AMI Deployment
Meter Operations During and After AMI DeploymentMeter Operations During and After AMI Deployment
Meter Operations During and After AMI Deployment
TESCO - The Eastern Specialty Company
 
Meter Operations in a Post AMI World
Meter Operations in a Post AMI WorldMeter Operations in a Post AMI World
Meter Operations in a Post AMI World
TESCO - The Eastern Specialty Company
 
Relay testing procedure
Relay testing procedure Relay testing procedure
Relay testing procedure
sambit mohapatra
 
High voltagebooklet ug_en_v01
High voltagebooklet ug_en_v01High voltagebooklet ug_en_v01
High voltagebooklet ug_en_v01
Luis Antonio González Mederos
 
Testing strategies for electronic components
Testing strategies for electronic componentsTesting strategies for electronic components
Testing strategies for electronic components
DepEd-Bataan
 

Similar to Maintenance and Test Equipment Cyber Security (20)

New Tools for a Next Generation of Metering - TESCO Solutions
New Tools for a Next Generation of Metering - TESCO SolutionsNew Tools for a Next Generation of Metering - TESCO Solutions
New Tools for a Next Generation of Metering - TESCO Solutions
 
TESCO Site Verification in a Pre and Post AMI World
TESCO Site Verification in a Pre and Post AMI WorldTESCO Site Verification in a Pre and Post AMI World
TESCO Site Verification in a Pre and Post AMI World
 
Health Monitoring of Industrial and Electrical Equipment
Health Monitoring of Industrial and Electrical EquipmentHealth Monitoring of Industrial and Electrical Equipment
Health Monitoring of Industrial and Electrical Equipment
 
Estimating Reliability of Power Factor Correction Circuits: A Comparative Study
Estimating Reliability of Power Factor Correction Circuits: A Comparative StudyEstimating Reliability of Power Factor Correction Circuits: A Comparative Study
Estimating Reliability of Power Factor Correction Circuits: A Comparative Study
 
Condition Monitoring of DC Motor using Artificial Intelligence Technique
Condition Monitoring of DC Motor using Artificial Intelligence TechniqueCondition Monitoring of DC Motor using Artificial Intelligence Technique
Condition Monitoring of DC Motor using Artificial Intelligence Technique
 
Field Test Kits and Hot Socket Repair Kits
Field Test Kits and Hot Socket Repair KitsField Test Kits and Hot Socket Repair Kits
Field Test Kits and Hot Socket Repair Kits
 
Intrusive vs. Non-Intrusive Electric Actuators: Which option is right for you...
Intrusive vs. Non-Intrusive Electric Actuators: Which option is right for you...Intrusive vs. Non-Intrusive Electric Actuators: Which option is right for you...
Intrusive vs. Non-Intrusive Electric Actuators: Which option is right for you...
 
safety_critical_applications_and_customer_concerns
safety_critical_applications_and_customer_concernssafety_critical_applications_and_customer_concerns
safety_critical_applications_and_customer_concerns
 
Mr DD update resume
Mr DD update resumeMr DD update resume
Mr DD update resume
 
BIST (Built-in-Self-Test) Features for Electronic Valve Actuators
BIST (Built-in-Self-Test) Features for Electronic Valve ActuatorsBIST (Built-in-Self-Test) Features for Electronic Valve Actuators
BIST (Built-in-Self-Test) Features for Electronic Valve Actuators
 
A-ConMonIntro.ppt
A-ConMonIntro.pptA-ConMonIntro.ppt
A-ConMonIntro.ppt
 
EE Reports Submetering 102 Guide
EE Reports Submetering 102 GuideEE Reports Submetering 102 Guide
EE Reports Submetering 102 Guide
 
Circuit Break Connect Monitoring to 5G Mobile Application
Circuit Break Connect Monitoring to 5G Mobile ApplicationCircuit Break Connect Monitoring to 5G Mobile Application
Circuit Break Connect Monitoring to 5G Mobile Application
 
CIRCUIT BREAK CONNECT MONITORING TO 5G MOBILE APPLICATION
CIRCUIT BREAK CONNECT MONITORING TO 5G MOBILE APPLICATIONCIRCUIT BREAK CONNECT MONITORING TO 5G MOBILE APPLICATION
CIRCUIT BREAK CONNECT MONITORING TO 5G MOBILE APPLICATION
 
Field Testing
Field TestingField Testing
Field Testing
 
Meter Operations During and After AMI Deployment
Meter Operations During and After AMI DeploymentMeter Operations During and After AMI Deployment
Meter Operations During and After AMI Deployment
 
Meter Operations in a Post AMI World
Meter Operations in a Post AMI WorldMeter Operations in a Post AMI World
Meter Operations in a Post AMI World
 
Relay testing procedure
Relay testing procedure Relay testing procedure
Relay testing procedure
 
High voltagebooklet ug_en_v01
High voltagebooklet ug_en_v01High voltagebooklet ug_en_v01
High voltagebooklet ug_en_v01
 
Testing strategies for electronic components
Testing strategies for electronic componentsTesting strategies for electronic components
Testing strategies for electronic components
 

Recently uploaded

June Patch Tuesday
June Patch TuesdayJune Patch Tuesday
June Patch Tuesday
Ivanti
 
Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...
Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...
Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...
Pitangent Analytics & Technology Solutions Pvt. Ltd
 
“How Axelera AI Uses Digital Compute-in-memory to Deliver Fast and Energy-eff...
“How Axelera AI Uses Digital Compute-in-memory to Deliver Fast and Energy-eff...“How Axelera AI Uses Digital Compute-in-memory to Deliver Fast and Energy-eff...
“How Axelera AI Uses Digital Compute-in-memory to Deliver Fast and Energy-eff...
Edge AI and Vision Alliance
 
Digital Banking in the Cloud: How Citizens Bank Unlocked Their Mainframe
Digital Banking in the Cloud: How Citizens Bank Unlocked Their MainframeDigital Banking in the Cloud: How Citizens Bank Unlocked Their Mainframe
Digital Banking in the Cloud: How Citizens Bank Unlocked Their Mainframe
Precisely
 
Introduction of Cybersecurity with OSS at Code Europe 2024
Introduction of Cybersecurity with OSS  at Code Europe 2024Introduction of Cybersecurity with OSS  at Code Europe 2024
Introduction of Cybersecurity with OSS at Code Europe 2024
Hiroshi SHIBATA
 
Your One-Stop Shop for Python Success: Top 10 US Python Development Providers
Your One-Stop Shop for Python Success: Top 10 US Python Development ProvidersYour One-Stop Shop for Python Success: Top 10 US Python Development Providers
Your One-Stop Shop for Python Success: Top 10 US Python Development Providers
akankshawande
 
Programming Foundation Models with DSPy - Meetup Slides
Programming Foundation Models with DSPy - Meetup SlidesProgramming Foundation Models with DSPy - Meetup Slides
Programming Foundation Models with DSPy - Meetup Slides
Zilliz
 
Connector Corner: Seamlessly power UiPath Apps, GenAI with prebuilt connectors
Connector Corner: Seamlessly power UiPath Apps, GenAI with prebuilt connectorsConnector Corner: Seamlessly power UiPath Apps, GenAI with prebuilt connectors
Connector Corner: Seamlessly power UiPath Apps, GenAI with prebuilt connectors
DianaGray10
 
Freshworks Rethinks NoSQL for Rapid Scaling & Cost-Efficiency
Freshworks Rethinks NoSQL for Rapid Scaling & Cost-EfficiencyFreshworks Rethinks NoSQL for Rapid Scaling & Cost-Efficiency
Freshworks Rethinks NoSQL for Rapid Scaling & Cost-Efficiency
ScyllaDB
 
JavaLand 2024: Application Development Green Masterplan
JavaLand 2024: Application Development Green MasterplanJavaLand 2024: Application Development Green Masterplan
JavaLand 2024: Application Development Green Masterplan
Miro Wengner
 
Skybuffer SAM4U tool for SAP license adoption
Skybuffer SAM4U tool for SAP license adoptionSkybuffer SAM4U tool for SAP license adoption
Skybuffer SAM4U tool for SAP license adoption
Tatiana Kojar
 
Fueling AI with Great Data with Airbyte Webinar
Fueling AI with Great Data with Airbyte WebinarFueling AI with Great Data with Airbyte Webinar
Fueling AI with Great Data with Airbyte Webinar
Zilliz
 
5th LF Energy Power Grid Model Meet-up Slides
5th LF Energy Power Grid Model Meet-up Slides5th LF Energy Power Grid Model Meet-up Slides
5th LF Energy Power Grid Model Meet-up Slides
DanBrown980551
 
Deep Dive: AI-Powered Marketing to Get More Leads and Customers with HyperGro...
Deep Dive: AI-Powered Marketing to Get More Leads and Customers with HyperGro...Deep Dive: AI-Powered Marketing to Get More Leads and Customers with HyperGro...
Deep Dive: AI-Powered Marketing to Get More Leads and Customers with HyperGro...
saastr
 
Columbus Data & Analytics Wednesdays - June 2024
Columbus Data & Analytics Wednesdays - June 2024Columbus Data & Analytics Wednesdays - June 2024
Columbus Data & Analytics Wednesdays - June 2024
Jason Packer
 
Driving Business Innovation: Latest Generative AI Advancements & Success Story
Driving Business Innovation: Latest Generative AI Advancements & Success StoryDriving Business Innovation: Latest Generative AI Advancements & Success Story
Driving Business Innovation: Latest Generative AI Advancements & Success Story
Safe Software
 
Astute Business Solutions | Oracle Cloud Partner |
Astute Business Solutions | Oracle Cloud Partner |Astute Business Solutions | Oracle Cloud Partner |
Astute Business Solutions | Oracle Cloud Partner |
AstuteBusiness
 
Apps Break Data
Apps Break DataApps Break Data
Apps Break Data
Ivo Velitchkov
 
[OReilly Superstream] Occupy the Space: A grassroots guide to engineering (an...
[OReilly Superstream] Occupy the Space: A grassroots guide to engineering (an...[OReilly Superstream] Occupy the Space: A grassroots guide to engineering (an...
[OReilly Superstream] Occupy the Space: A grassroots guide to engineering (an...
Jason Yip
 

Recently uploaded (20)

June Patch Tuesday
June Patch TuesdayJune Patch Tuesday
June Patch Tuesday
 
Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...
Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...
Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...
 
“How Axelera AI Uses Digital Compute-in-memory to Deliver Fast and Energy-eff...
“How Axelera AI Uses Digital Compute-in-memory to Deliver Fast and Energy-eff...“How Axelera AI Uses Digital Compute-in-memory to Deliver Fast and Energy-eff...
“How Axelera AI Uses Digital Compute-in-memory to Deliver Fast and Energy-eff...
 
Digital Banking in the Cloud: How Citizens Bank Unlocked Their Mainframe
Digital Banking in the Cloud: How Citizens Bank Unlocked Their MainframeDigital Banking in the Cloud: How Citizens Bank Unlocked Their Mainframe
Digital Banking in the Cloud: How Citizens Bank Unlocked Their Mainframe
 
Introduction of Cybersecurity with OSS at Code Europe 2024
Introduction of Cybersecurity with OSS  at Code Europe 2024Introduction of Cybersecurity with OSS  at Code Europe 2024
Introduction of Cybersecurity with OSS at Code Europe 2024
 
Your One-Stop Shop for Python Success: Top 10 US Python Development Providers
Your One-Stop Shop for Python Success: Top 10 US Python Development ProvidersYour One-Stop Shop for Python Success: Top 10 US Python Development Providers
Your One-Stop Shop for Python Success: Top 10 US Python Development Providers
 
Programming Foundation Models with DSPy - Meetup Slides
Programming Foundation Models with DSPy - Meetup SlidesProgramming Foundation Models with DSPy - Meetup Slides
Programming Foundation Models with DSPy - Meetup Slides
 
Connector Corner: Seamlessly power UiPath Apps, GenAI with prebuilt connectors
Connector Corner: Seamlessly power UiPath Apps, GenAI with prebuilt connectorsConnector Corner: Seamlessly power UiPath Apps, GenAI with prebuilt connectors
Connector Corner: Seamlessly power UiPath Apps, GenAI with prebuilt connectors
 
Freshworks Rethinks NoSQL for Rapid Scaling & Cost-Efficiency
Freshworks Rethinks NoSQL for Rapid Scaling & Cost-EfficiencyFreshworks Rethinks NoSQL for Rapid Scaling & Cost-Efficiency
Freshworks Rethinks NoSQL for Rapid Scaling & Cost-Efficiency
 
JavaLand 2024: Application Development Green Masterplan
JavaLand 2024: Application Development Green MasterplanJavaLand 2024: Application Development Green Masterplan
JavaLand 2024: Application Development Green Masterplan
 
Skybuffer SAM4U tool for SAP license adoption
Skybuffer SAM4U tool for SAP license adoptionSkybuffer SAM4U tool for SAP license adoption
Skybuffer SAM4U tool for SAP license adoption
 
Fueling AI with Great Data with Airbyte Webinar
Fueling AI with Great Data with Airbyte WebinarFueling AI with Great Data with Airbyte Webinar
Fueling AI with Great Data with Airbyte Webinar
 
Artificial Intelligence and Electronic Warfare
Artificial Intelligence and Electronic WarfareArtificial Intelligence and Electronic Warfare
Artificial Intelligence and Electronic Warfare
 
5th LF Energy Power Grid Model Meet-up Slides
5th LF Energy Power Grid Model Meet-up Slides5th LF Energy Power Grid Model Meet-up Slides
5th LF Energy Power Grid Model Meet-up Slides
 
Deep Dive: AI-Powered Marketing to Get More Leads and Customers with HyperGro...
Deep Dive: AI-Powered Marketing to Get More Leads and Customers with HyperGro...Deep Dive: AI-Powered Marketing to Get More Leads and Customers with HyperGro...
Deep Dive: AI-Powered Marketing to Get More Leads and Customers with HyperGro...
 
Columbus Data & Analytics Wednesdays - June 2024
Columbus Data & Analytics Wednesdays - June 2024Columbus Data & Analytics Wednesdays - June 2024
Columbus Data & Analytics Wednesdays - June 2024
 
Driving Business Innovation: Latest Generative AI Advancements & Success Story
Driving Business Innovation: Latest Generative AI Advancements & Success StoryDriving Business Innovation: Latest Generative AI Advancements & Success Story
Driving Business Innovation: Latest Generative AI Advancements & Success Story
 
Astute Business Solutions | Oracle Cloud Partner |
Astute Business Solutions | Oracle Cloud Partner |Astute Business Solutions | Oracle Cloud Partner |
Astute Business Solutions | Oracle Cloud Partner |
 
Apps Break Data
Apps Break DataApps Break Data
Apps Break Data
 
[OReilly Superstream] Occupy the Space: A grassroots guide to engineering (an...
[OReilly Superstream] Occupy the Space: A grassroots guide to engineering (an...[OReilly Superstream] Occupy the Space: A grassroots guide to engineering (an...
[OReilly Superstream] Occupy the Space: A grassroots guide to engineering (an...
 

Maintenance and Test Equipment Cyber Security

  • 1. Digital Maintenance and Test Equipment and Impact on Control System Security Mike Toecker, PE Context Industrial Security @mtoecker
  • 2. Introduction • Professional Computer Engineer (USA- MO) – Specialized in Computer Security for Industrial Systems • Currently, Owner/Engineer at Context Industrial Security – Former Burns and McDonnell Engineering – Former NextEra Energy – Former Digital Bond • 10 Years in Cyber Security for ICS – Fossil/Hydro/Nuclear Power Plants, Transmission, Control Centers, Mine, Water Treatment, Distribution, Gas Processing/Transport
  • 3. First, a Message from the Goat of Honesty and Truth I’m unaware of any incidents, public or private, where malicious hacked M&TE has been the cause of an industrial cyber security incident. This has been a message from the Goat of Honesty, Integrity, and Empirical Evidence.
  • 4. Maintenance and Test Equipment (M&TE) M&TE is a class of industrial equipment that aids maintenance and engineering personnel in ensuring the reliability, efficiency, and profitability of electrical and mechanical systems and equipment. It can be considered part of the on-site implementation of Reliability Engineering principles. BASICALLY…. M&TE IS EQUIPMENT USED TO MAINTAIN AND TEST OTHER EQUIPMENT
  • 5. You’ve Seen M&TE, Likely Didn’t Realize It An automobile has lots of control systems, some are just plain mechanic, many are digital. The digital ones are hackable. We know this for sure, thanks to Miller and Valasek. What we don’t think about are the digital tools used to evaluate whether or not an automobile is ready to return to the road. If some of these look like Control Systems, it’s cause they are. Battery Test Automatic Alignment Engine Diagnostic (OBD-II/EOBD) Computerized Balancing Emissions Compliance
  • 6. I NEED A NEW ALTERNATOR?!?! Maintenance and Test Tools were developed to provide objective guidance on replacement and repair of expensive components. For me, it was the difference between driving home happy, and driving home $500 poorer. I went home $500 poorer, because a computer told me to.
  • 8. ICS Compared to M&TE • Operations Focus • Networked • Monitor the Industrial Process in Real-Time • Generally Fixed Assets, Installed in Facility • Maintenance Focus • Rarely Networked • Evaluate Specific Criteria Associated with Process Equipment • Mobile, Often Handheld, Goes from Site to Site
  • 10. Trend Towards Digital Equipment Digital Equipment is all the rage these days. Generally, digital measurement of analog signals is more error-proof and reliable, with a far greater degree of accuracy than the older analog meters. With digital, you also get the capability to record your data, compare it to other recordings, trend it, analyze it with advanced math packages. In short, it’s kinda a win.
  • 11. The Usual Digital Vulnerabilities M&TE has taken the same path as ICS, adoption of the commercial hardware and software into the products used on industrial equipment. Examples: 1. Automated Analyzer using MS Access and WinXP 2. Firmware updates without code signing, passwords, or other means of control 3. Calibrators running BusyBox Linux 4. HART Descriptors Updateable Via Plain Jane HTTP
  • 12. Bring Your Own Device; Industrial Edition Because of economics, accounting practices, and work load, this kind of maintenance and testing work is routinely outsourced to external companies. To the right are snippets of language from an RFP for Substation Testing Services, which is reasonably typical. There was no mention of cyber security in this RFP. Demonstrates Known Concern that Testing Agents have a lot of power to recommend expensive changes So, how do you think they are upgrading this firmware in the relay? (Hint: The answer is laptop)
  • 13. Consequences of Malicious Interference are Different ICS M&TE Consequences of hacking M&TE and using it maliciously are going to be different than hacking ICS.
  • 14. Digital Calibration and Interface Handheld devices and laptops used for interacting with digital transmitters are pretty ubiquitous at many sites. These have some very advanced capabilities, often outside of the operator’s purview and cyber security monitoring. The most interesting ones get firmware updates and device descriptors from the internet, downloaded directly into the handheld. This is an area I’m planning to explore extensively over the next few years.
  • 15. Motor Condition Evaluation There are few industrial facilities that don’t have motors, these are tested via automated systems that check the motor for shorts, dirt, and poor insulation quality.
  • 16. Valve Testing Maintenance of Valves is a big deal in a lot of industrial facilities. Many valves MUST close if required due to safety reasons, so testing is performed to ensure the valve is capable of closing. Other valves are important to the process, and are evaluated for problems on a consistent basis . Valves which fail tests are swiftly replaced. Facilities with these valves often used portable test suites to initiate, monitor, and determine pass/fail of a valve. Common tests are partial stroke, full stroke, and valve stability. The green valve has a smart positioner, which is calibrated using either a HART or Fieldbus connection, and can aid automated testing.
  • 17. Relay Testing and Validation Utilities and other industrials with large power requirements must test protective relays to ensure they work under all conditions. Automated rigs sets are the usual way these tests, often regulatory required, are performed. Binary and Analog Test Leads USB IEC/61850 PoE/Ethernet Bluetooth
  • 18. Eddy Current Testing This type of testing is used to find deformities and weaknesses in tubing, pipes, tanks and other large metal components, preferably before leaks, cracks, or breaks happen. There are many variations of this, many industries need ways to inspect piping without opening/digging it up. The Illustration above was via the Non-Destructive Testing Resource Center. https://www.nde- ed.org/EducationResources/educati onresource.htm
  • 19. Ground Tests, and other Major Electrical Tests 0 10 20 30 40 50 60 0 50 100 Resistance vs %Distance Resistance We often need to know the electrical characteristics of a system, such as whether it has a good or bad ground, in order to diagnose problems effectively. USB Interface to PC
  • 20. Other M&TE • Gas Analysis – Transformer Health • Ultrasonic Testing - Pipe Thickness • Vibration Analysis – Health of Rotating Equipment There’s a lot I didn’t cover, I tried to hit the high points. However, there is a lot more out there, and a lot of it is industry specific.
  • 21. SO, WHAT MIGHT AN M&TE HACK LOOK LIKE?
  • 22. Motor Test Hacking Motors are a major component of any industrial facility. They don’t last forever though, and they are pretty expensive components to replace. Pricing taken from “W22 Severe Duty Motors – TEFC” on weg.net and subject to change without notice
  • 23. Some Motor Tests • Kelvin Method Winding • Meg-Ohm • Polarization Index (PI) • Step-Voltage • Surge Test Major problems in the motor often result from: • Ground Wall Insulation • Turn to Turn Insulation • Phase to Phase Insulation Most motor failures on the electrical side come from insulation going bad, and getting a short somewhere in the motor.
  • 24. Surge Test Process Charge up Capacitor to a Voltage Setpoint Discharge Capacitor into Single Phase (sometimes Two) Charge Dissipation Produces a Characteristic Waveform Record the Waveform and Associated Data Compare the Current Waveform to Previous Waveform Using ppEAR or Similar Increase the Voltage Setpoint per Test Spec The technical explanation is that the impulse from the capacitor will discharge into the winding, resulting in a wave with a characteristic response. That characteristic response is stored and compared the previous. START STOP Source: http://www.maintenancetechnology.com/2007/03/dc-step-voltage-and- surge-testing-of-motors/ The fun explanation is that we are hitting a punch-me clown repeatedly, harder each time, to see if it does something different than last time.
  • 25. Failure Criteria #1 If the frequency of any resulting waveform shifts to the left, the motor is either bad or going bad. The white line has shifted to the left, or using other words has a different zero crossing. This motor is bad, or is going bad. This is when the punch-me clown goes down, loses grip with the floor, bounces, and/or doesn’t come back up the same way. Source: http://www.maintenancetechnology.com/2007/03/dc-step-voltage-and- surge-testing-of-motors/
  • 26. Failure Criteria #2 If the changes between each of the pulses result in a different waveform (about 4-5% difference is normal), then the motor is bad, or going bad. This is measures with an equation called Error Area Ratio. It’s basically a percentage difference between two voltage measures taken at the same time in the test. The dotted line in the EAR subgraph is at 4-5%. Source: http://www.existest.com/appnotes/Baker/Teoria%20Surge.pdf That’s the EAR, you see it go off the chart, which signals a response dramatically different from the previous.
  • 27. Aside: Why Does This Work? Every Played F-Zero? The Cloud Carpet Track of the Icarus Circuit illustrates this well. If the racetrack is a motor winding, Point D is a short circuit. But, you can’t USE Point D until you gain get enough of a top speed to jump all the way over. That top speed is where the insulation in the motor allows a short. Please Don’t Sue Me Nintendo, I love you.
  • 28. PROCESS TO FAKE A SIGNAL Discuss the process.
  • 29. Consequences Bad Motor Reports as Good • Failure of the Motor is a Given at Some Point • No Maintenance Activity to Open It Up For Inspection • Impossible to Determine How Much Life is Left • Impact Depends on Motor Function Good Motor Reports as Bad • Engineering will Evaluate the Motor for Useful Life • Motor will be removed, or scheduled for removal • Money spent to order, design, install, and test new motor. • **Possible the motor will be sent to 3rd party for testing**
  • 30. Attackers Want To Minimize Discovery Risk Bad Motor Reporting as Good Good Motor Reporting as Bad It’s Tough to Test Molten Slag for Irregularities
  • 32. Step 1: Identify Your High Consequence Equipment Talk with the engineers and operations, most of them either know what equipment they have that, if it fails, presents a High Consequence. If they don’t know already, they usually have the means to do so. High Consequence, No Particular Order: 1. High Cost of Replacement 2. Personnel Safety Concerns 3. Negative Impacts to the Process 4. Regulatory Requirements
  • 33. Step 2: Identify Tests Done on High Consequence Equipment Likely, this will require discussions with engineers and maintenance personnel, as operations may not have the definite answers for this question like they normally due. Tests will depend on the equipment. Figure out the methodology, accuracy, what measures are taken to prove a test, etc.
  • 34. Step 3: Evaluate Susceptibility to Malicious Cyber Influence Looking at each test, and the equipment used to perform it, identify how susceptible it is to malicious influence. You’re looking for cyber vulnerable equipment, equipment provided by third parties, poor firmware update, etc. This is basically a high level device risk assessment. Rate them on a scale: 10 – Highly Susceptible … 1 – Not Susceptible
  • 35. Step 4: Identify and Apply Protective Measures Physical Protection Lock Up When Not in Use Allow Use By Only Qualified Individuals Place Tamper Evident Seals Create “Test Checks” to provide confirmation of Tests Cyber Protection Block Firmware Update Mechanisms Check Firmware Signatures w/ Vendor Remove Network Access that is Not Required Heavily Restrict Portable Media Usage Vendor Protection Require Pre-Site Evaluation of Equipment Require Use of Special Hardened Laptops Consider Altering Calibration Requirements to Include Cyber As these aren’t traditional IT devices, the usual protections may not be applicable. Define a set of protective measures that reduce risk from the identified vulnerabilities, and then apply them in order greatest to least susceptibility. Remember, we’re already focusing on the most high consequence equipment already. Some basic protections are to my left, this is a min-max area as it’s very easy to affect maintenance’s processes ($$$).
  • 36. Are There Any Questions?

Editor's Notes

  1. The best initial example I can give is that of a car. Your car has a control system, in fact there are many of them in a modern automobile. These systems are networked, they are digital, and they are hackable, we know this. You are the operator of these control systems, and you drive it around at insane speeds, making both good and poor decisions about how you treat the physical components of that automobile. Then, you take it in for service, either scheduled or unscheduled. And mechanics swarm over your car, testing various systems to ensure they are within specifications. A general process that they follow is this: Check out recall notices and advisories to plan their work Pull Error Codes from your ODB-II (or, as we are in Europe, the EOBD port) Check out their knowledge base for any error codes they encounter Check your tires, tire pressure, alignment, balance, etc Check your engine, RPMs, Timing, combustion, etc Check the transmission, fluid level, wear and t Check your battery and alternator, voltage and current checks, insulation checks, battery capacity and discharge Check your steering, the power steering belt, fluid, pump and look for leaks
  2. https://www.nde-ed.org/EducationResources/CommunityCollege/EddyCurrents/Applications/tubeinspection.htm
  3. Most motor failures on the electrical side come from insulation going bad, and getting a short somewhere in the motor. The short may not appear until a certain voltage threshold hits, where it will spark and cause more insulation to be damaged, making it easier the next time. Repeat as necessary.
  4. This is a characteristic of the impedance being changed because there is a short in the winding that begins during one of the steps).
  5. This is a characteristic of the impedance being changed because there is a short in the winding that begins during one of the steps).
  6. This is a characteristic of the impedance being changed because there is a short in the winding that begins during one of the steps).