VWAY

Newsroom
Technical Resources


STPAExample of applying STPA-Sec analysis(Industrial Cyber-security ) - Chiller

STPA-Sec Analysis using Chiller

Industrial Control Systems (ICS) become increasingly software-intensive. For example, cyber-physical systems are electronic control systems that control physical processes and machines such as, motors and valves, in an industrial plant using Information and Communication Technologies (ICT). The advances in computing power and network transmission speeds, coupled with a decrease in hardware cost, has enabled new applications of ICT in industrial settings to improve efficiency of the underlying physical processes. The resulting displacement of traditional analog and mechanical devices with software-intensive control systems has inadvertently intertwined the architecture of physical processes with cyberspace; thus, exposing them to new risk possibilities. In this analysis, we demonstrate the use of Systems-Theoretic Process Analysis (hereinafter referred to as STPA) to identify cyber-vulnerabilities that have the potential to cause physical damage in industrial control systems using a chiller control system as an use-case. It is shown that the method provides a well-guided and structured analysis process to unveil new cyber vulnerabilities that span not only technical aspects but also the broader socio-organizational system. The method ties system-level losses to violation of constraints at both the component-level as well as the process level and provides recommendations to make the system more resilient by defining additional countermeasures to control vulnerabilities in the system.



System Information

The central focus of this analysis step targets cyber-safety STPA analysis (hereinafter refrred to as STPA-Sec) of Chiller Control. The following picture is the system information screen where the abstract for the analysis will be described in general.


VisualPro System Information screen for the project 'Cyber-safety STPA analysis of Chiller Control' — company VWAY, department National Institute of Industry (South Korea), cyber security method STRIDE, analysis period 2022-11-01 to 2022-11-30, with a photo of an industrial chiller

Picture 1. System information of STPA-Sec of Chiller Control



1. Identify Losses & Hazards

STPA analysis takes four steps, the first of which is ‘identify Losses & Hazards’. The screen presented below is for identifying Losses.


VisualPro Losses screen for the chiller analysis — L-1 loss of equipment (financial/operational), L-2 loss of cooling (environmental control), L-3 death, dismemberment or injury to plant personnel, with the related hazards H-1 to H-5

Picture 2. Identifying Losses of chiller’s STPA-Sec


STPA loss table for the chiller — L-1 loss of equipment (financial/operational) related to H-1 to H-3, L-2 loss of cooling related to H-1 to H-5, L-3 death, dismemberment or injury to plant personnel related to H-1 to H-4

Table 1. Losses table of chiller’s STPA-Sec


For a system of chiller’s STPA-Sec, 5 Hazards can be identified, each of which then creates a traceable relationship with Losses. The identified hazards are as follows :


VisualPro System-Level Hazards screen for the chiller — H-1 operating beyond normal operational limits, H-2 violating the correct sequence of operations, H-3 unable to provide accurate feedback about status, H-4 releasing asphyxiate gasses, H-5 not responding to local chilled water demand

Picture 3. Identifying Hazards of chiller’s STPA-Sec


STPA system-level hazard table for the chiller — H-1 operating beyond normal operational limits, H-2 violating correct sequence of operations, H-3 unable to provide accurate status feedback, H-4 releasing asphyxiate gasses, H-5 not responding to local (chilled water) demand, each mapped to losses L-1 to L-3

Table 2. Hazards table of chiller’s STPA-Sec


For a chiller’s cyber threats, 8 Constraints can be identified, each of which then creates a traceable relationship with Hazards. The identified Constraints are as follows :


VisualPro System-Level Constraints screen for the chiller — SC-1 must not operate beyond normal operational limits, SC-2 violations outside limits must be detected and prevented, SC-3 must not violate the correct sequence of operations, SC-4 must provide accurate status feedback at all times, SC-5 must prevent release of asphyxiate gasses, SC-6 workers must be alerted if gasses are released, SC-7 must be sized adequately for local demand, SC-8 damage to critical loads must be prevented if demand cannot be met

Picture 4. Identifying Constraints of a chiller’s cyber threats


STPA system-level constraint table for the chiller — SC-1 to SC-8 mapped to hazards H-1 to H-5: must not operate beyond normal limits, detect and prevent operation outside limits, must not violate the correct sequence of operations, must provide accurate status feedback at all times, must prevent release of asphyxiate gasses, must alert proximate workers if gasses are released, must be sized adequately for local demand, and must prevent damage to critical loads if demand cannot be met

Table 3. Constraints table of chiller’s cyber threats



2. Control Structure Modeling

The second step out of the four is to build a model of the system called a control structure. A control structure captures functional relationships and interactions by modeling the system as a set of feedback control loops. The control structure usually begins at a very abstract level and then is through iteration refined to capture more detail about the system. This step is essential regardless of whether it concerns safety, security, privacy, or other any other properties. A high-level control structure of the system under analysis is illustrated below. There are several control loops captured in the control structure, such as the control loop between ‘Operator’ and ‘DSC’, between ‘Chiller PLC Controller’ and ‘VFD Control Unit’ and between ‘Cooling Capacty’ and ‘Chilled Water Temperature Sensor’.. etc. The control structure at this abstraction level includes many CAs.


STPA control structure for the chiller control system — operator with mental model, DSC, chiller PLC controller, VFD control unit, chilled water temperature sensor and cooling capacity, with control actions (set chiller sequence and temperature setpoint, manual start/stop through the chiller HMI, permissives and pressure/temperature setpoints, increase/decrease speed signal, compressor motor speed control via frequency and voltage) and feedback (differential pressure and temperature, chilled water supply/return line, operating status, chilled water temperature, evaporator physical status), plus other inputs such as motor state, compressor pressure differential, oil temperature and inlet guide vane position

Picture 5. STPA Control Structure Diagram for Chiller System



3. Identify UCA

The third step out of the four identifies Unsafe Control Action (UCA). Accorting to STPA methodology, UCA is created into four types (Not providing causes hazard / Providing causes hazard / Too early, too late, out of order / Stopped too soon, applied too long). The associated UCAs for a Control Actions will be given in the below picture as an example.


VisualPro UCA screen for the chiller increase/decrease speed signal, with the analysis type set to Security — UCA-1 not increasing compressor speed when refrigerant temperature is below setpoint, UCA-2 and UCA-4 to UCA-6 providing the command unsafely, UCA-3 providing it too early

Picture 6. Identifying UCAs of Chiller System


STPA unsafe control action table for the chiller increase/decrease speed signal — UCA-1 not increasing speed when refrigerant temperature is below setpoint, UCA-2 increasing speed when permissives are unavailable, UCA-4 increasing speed in the reverse direction, UCA-5 increasing to a different value than requested, UCA-6 the signal executed incorrectly with successive ramp-ups and ramp-downs at an unsafe rate via the VFD (the Stuxnet case), UCA-3 increasing before permissives are available, UCA-7 continuing to increase when permissives become unavailable

Table 4. UCA table of Chiller System’s cyber threats



4. Identify Loss Scenario

Once you have identified an UCA, you should create a scenario that causes it. STPA refers to this as a Loss Scenario and can be written by referring to a Guide Word that causes a Loss Scenario provided by the Handbook. Below are some of the possible Loss Scenario in UCA2 : Chiller controller increases compressor speed when permissives for this action are unavailable. You can additionally find lock symbols in the red column on the picture below, meaning each UCA’s relevance to cyber-safety, while the UCA under a shield symbol indicates its attachment to overall safety.

(The shield UCA is provided only for example – it’s NOT part of the logic)


VisualPro Loss Scenario screen for the chiller with the control loop diagram, listing loss scenarios LS-1 to LS-5 for UCA-2 with their STPA Handbook guide words and STRIDE categories (T tampering, D denial of service, S spoofing)

Picture 7. Identifying Loss Scenarios of Chiller System’s cyber threats


STPA-Sec loss scenario table for UCA-2 — five scenarios in which the chiller controller incorrectly believes it has the permissive to increase compressor motor speed because the information it bases the decision on is corrupted: malicious feedback injection from sensors, malicious command injection that overloads and spoofs the controller node, malicious feedback injection from connections, malicious feedback drop at connections, and communication drop or delay at the sensor


STPA-Sec loss scenario table for UCA-3 (increasing compressor speed before permissives are available) — LS-6 malicious feedback manipulation from sensors makes the controller assume an incorrect state, LS-7 malicious command manipulation makes the controller take the opposite action


STPA-Sec loss scenario table for UCA-7 (continuing to increase compressor speed when permissives become unavailable) — LS-8 equipment addition or plant configuration changes make previously applied security measures obsolete, for example a VFD firmware update that inadvertently removes them


STPA-Sec loss scenario table for UCA-4 (compressor runs in the reverse direction) — LS-9 malicious command manipulation sends a reverse rotation signal to the VFD, LS-10 the VFD control algorithm is maliciously manipulated, LS-11 VFD feedback is treated as redundant so reverse rotation is never detected


STPA-Sec loss scenario table for UCA-5 (compressor speed set to a value other than requested) — LS-12 an independent control path to the VFD allows its parameters to be tampered with, LS-13 command manipulation at the VFD sets output voltage/frequency incorrectly, LS-14 VFD feedback is treated as redundant so the controller cannot tell whether the speed was set correctly


STPA-Sec loss scenario table for UCA-6 (the speed signal executed incorrectly — the Stuxnet case) — LS-15 malicious command manipulation sets the compressor to the attached load's critical speed or throttles it between extreme values, LS-16 sensor feedback is scattered and normal operating values are injected so operators do not know the true conditions


STPA-Sec loss scenario table for UCA-1 (not increasing compressor speed when refrigerant temperature is below setpoint) — LS-17 malicious command drop or delay with the VFD spoofed and unavailable, LS-18 the VFD incapacitated by malicious logic that blows its capacitors, LS-19 VFD feedback treated as redundant so the controller cannot tell whether the command was received

Table 5. Loss Scenario table of Chiller System’s cyber threats


Once you have identified a Loss Scenario, you then can create a Countermeasure to prevent every related Loss Scenario there is by creating a connection between them.


VisualPro Countermeasures screen for the chiller analysis — each loss scenario LS-5 to LS-14 mapped to countermeasures CM-1 to CM-16, with the detail of CM-1: the VFD drive selected for use at CUP must not allow reverse rotation via digital command from the PLC

Picture 8. Identifying Countermeasures of Chiller System’s cyber threats


STPA-Sec countermeasure table for the chiller — component level constraints CM-1 to CM-10 (VFD must not allow reverse rotation by digital command or wiring, VFD protected from being energized outside the chiller PLC, protection preserved across firmware updates, independent redundant motor speed display, independent shutdown method, no writeable feature over network protocol without authentication, feedback to the PLC confirming command receipt, manual bypass, thermal protection relays on all motors) and management level constraints CM-11 to CM-15 (re-analyse the cyber-safety architecture after any equipment change, full cybersecurity assessment for like-for-like replacements, the same rigorous analysis for contractor equipment, no remote firmware updates by contractors, a comprehensive cybersecurity policy with training for plant personnel), each mapped to the loss scenarios it addresses

Table 6. Countermeasure table of Chiller System’s cyber threats



Conclusion

In this STPA analysis, we have analyzed a single representative control loop (the compressor motor speed control) of an archetypal industrial control system (i.e. the centrifugal chiller) at a small-sized power plant in the context of cyber-security using a vulnerability analysis method based on Systems Thinking. Starting with system-level losses and hazards, we traced the functional control structure of the plant and abstracted out the compressor capacity control loop for a detailed analysis of a single control action under various system states. We then generated loss scenarios under which the unsafe control actions would result in system-level losses. Finally, we proposed new ‘countermeasures’ at various layers of the functional control structure (starting at the process layer and going all the way back up to the enterprise and regulatory level) to prevent the system from entering unsafe system states.



Shaharyar Khan, Stuart Madnick, and Allen Moulton, “Cyber-safety Analysis of an Industrial Control System for Chillers using STPA-Sec", UK, 2018

A hand holding a glowing padlock hologram — closing image of the industrial cybersecurity STPA-Sec example