DNA Analyzers can also be cyber vulnerable

July 16, 2012
I attended a High Tech Crime Task Force meeting where we were given a tour of the high tech crime lab. One of the locations on the tour was the DNA lab. There were several DNA analyzers which are available 24/7. Effectively, the DNA analyzer is a chemical analyzer. Consequently, I asked the tour host how maintenance was performed and if remote maintenance could be performed. I was told the system could be connected to the Internet, but wasn't. This brought up a number of questions I did not get a chance to ask:

I attended a High Tech Crime Task Force meeting where we were given a tour of the high tech crime lab. One of the locations on the tour was the DNA lab. There were several DNA analyzers which are available 24/7. Effectively, the DNA analyzer is a chemical analyzer. Consequently, I asked the tour host how maintenance was performed and if remote maintenance could be performed. I was told the system could be connected to the Internet, but wasn't. This brought up a number of questions I did not get a chance to ask:
- How do you know if the system has not been connected to the Internet
- Would you know if it were connected
- What security is employed by the system
- Are there control system cyber security policies in place
- How is firmware upgraded and by whom
- ...

It is interesting how may applications use control systems that may not be apparent:
Industrial facilities, mass transit, jail doors, traffic management, aircraft controls, amusement park rides, automotive controls, building controls, DNA analyzers,....

Joe Weiss

Sponsored Recommendations

IEC 62443 4-1 Cyber Certification – Why ML 3 is So Important

The IEC 62443 Security for Industrial Automation and Control Systems - Part 4-1: Secure Product Development Lifecycle Requirements help increase resilience for control systems...

Multi-Server SCADA Maintenance Made Easy

See how the intuitive VTScada Services Page ensures your multi-server SCADA application remains operational and resilient, even when performing regular server maintenance.

Your Industrial Historical Database Should be Designed for SCADA

VTScada's Chief Software Architect discusses how VTScada's purpose-built SCADA historian has created a paradigm shift in industry expectations for industrial redundancy and performance...

Linux and SCADA – What You May Not Have Considered

There’s a lot to keep in mind when considering the Linux® Operating System for critical SCADA systems. See how the Linux security model compares to Windows® and Mac OS®.