Tragedy of the Commons

“The Tragedy of the Commons is a type of social trap, often economic, that involves a conflict over finite resources between individual interests and the common good.”
In a perfect world, we all understand that certain situations should not exist which put our critical infrastructure at risk — we all like to be able to have electricity, water, and other common utilities which we normally take for granted.
But we do not live in a perfect world, of course.
First, let’s look at the issue of “convergence”, or rather, “premature convergence” which seems to be a better definition:
“…premature convergence means that a population for an optimization problem converged too early, resulting in being suboptimal.”
This is similar to — what I believe to be — the situation wherein some unknown portion of the SCADA controls & operations community has strategically moved itself into: using the same platforms, operating systems, and software, which are now susceptible to the vulnerabilities that we all know too well. Buffer overflows, remote exploitation, denial of service vulnerabilities, and so forth and so on.
Now, this wouldn’t be a problem if these system were, in no uncertain terms, not connected to the Internet in any way, shape, or form.
But that is increasingly not the case.
Due to operational “optimization” (meaning: it is cheaper to use publicly available connectivity to manage these systems), the SCADA threat landscape now begins to look a lot like the network security landscape that we all know and respect — one of constant vigilance and constant defensive threat posture.
Within the past couple of days, there have been a couple of SCADA systems management platform vulnerabilities announced which could result in some rather serious exploitation. The SANS ISC reported yesterday a situation in which one software suite which “…provides unauthorized access, allows partial confidentiality, integrity, and availability violation, allows unauthorized disclosure of information, allows disruption of service.”
This seems rather serious. And I have been informed that there is at least one more similar vulnerability which has not been publicly disclosed yet.
As utility companies make operational decisions based on economic business savings (using the Internet, or an Internet VPN, to manage their client-control base to save money), the unintended consequences can be severe. When they occur. If they occur.
Throw the dice.
Let’s keep our fingers crossed that the SCADA community quickly comes to grips with the nature of network security.
Source: TrendsLab Malmware Blog
Tags: risk, SCADA, Security, tragedy of commons
June 21st, 2008 at 3:18 am
Money Magazine New Construction Associated Press…
I didn’t agree with you first, but last paragraph makes sense for me…
June 21st, 2008 at 6:18 am
I read similar article also named PS Technologies, and it was completely different. Personally, I agree with you more, because this article makes a little bit more sense for me
October 4th, 2008 at 7:19 pm
Thank you, I just wanted to give a greeting and tell you I like your website very much….Unsecured Personal Loans Business Web Hosting
October 6th, 2008 at 2:12 pm
I was searching for Blogs about make money on internet and found this site. I am interested in your content and appreciate sites like this.
October 12th, 2008 at 8:47 am
I finally decided to give you a little feedback ! well you got it! i love your site !!! no , really, its good
October 14th, 2008 at 7:21 am
Monday In searching for sites related to AdSense but more specifically to %KEYWORD, I found your site which has great content.
October 20th, 2008 at 4:44 pm
Hey!, been surfing the net for bussiness loans and found your blog regarding Tragedy of the Commons. You really know your stuff! I