Risk Mitigation in Petroleum Cyber-Physical Systems
Risk Mitigation in Petroleum Cyber-Physical Systems
Copyright: ©2024 The authors. This article is published by IIETA and is licensed under the CC BY 4.0 license
([Link]
[Link] ABSTRACT
Received: 24 November 2023 The oil and gas (O&G) industry is the engine of the global economy. Oil and gas
Revised: 19 January 2024 production passes through axes related to exploration, research, extraction, transportation,
Accepted: 23 January 2024 and finally the final manufacturing of energy products. All these stages permeate some
Available online: 29 February 2024 risks that threaten both the human factor and the material factor. The oil industry merged
with the fourth technological industry 4.0, which included multiple technologies and
systems, the most important of which is the cyber-physical system (CPS), which some
Keywords: researchers have named petroleum cyber-physical systems if it is embodied within this
petroleum cyber-physical systems (CPSs), oil industry. CPSs are collaborative systems formed of autonomous and smart devices that
and gas (O&G), risk, vulnerability analysis, can handle data flows and activities while maintaining integrated physical objects. Several
mitigation, security approach risks confront the energy field, with the potential to interrupt critical supply lines, hurt the
environment, and trigger a financial catastrophe. In the field of O&G, there are very few
scientific studies that are exposed to risks in a complementary and comprehensive manner,
including only those that focus on cyber-attacks and their causes. There is a lack of
comprehension and in-depth studies of all types of threats in all their aspects that surround
cyber-physical systems within this field. Some risk classifications are based on internal
and external risks, while others are based on the influencing and causative aspects in a
general way. This study deals with the classification of risks: 1) classification of risk for
the global industry of O&G. 2) in terms of the fact that the cyber-physical system is the
most important component in the O&G industry and that these risks are either physical,
cyber, or related to permissibility and authorization in the O&G field. A security approach
is also presented that leads to mitigating the impact of risks in oil and gas zones.
99
literature, the focus is on cyber-physical attacks. There are proposes a multifaceted security approach for securing oil and
very few academic works that specifically address cyber gas zones, which includes three phases, and some challenges
security issues in the oil and gas industries. Nonetheless, some for implementing oil and gas standards are highlighted. The
publications address various cyber security dangers to this discussion and conclusion are presented in sections 5 and 6.
industry. Hacquebord and Pernet [6] survey risks to the oil and
gas industry and present a study of known hacker groups and
their cyber-attacks against the oil and gas industry. It issued a 2. RISK CLASSIFICATION
survey on (O&G) as cyber threats in the study of Dragos [7]
and cataloged cyber organizations and state actors that attack The petroleum and natural gas industries are complex
(O&G) facilities. Lobo [8] produced a comprehensive cyber environments that include onshore and offshore industries,
risk technical evaluation tailored for the upstream subsector of upstream and downstream pipelines, and more. These
the oil and gas industry, and they present an extensive analysis organizations are all part of the same industry, yet each has its
of threats, common assaults, and even catalog an enormous list own set of risks and potential hazards to avoid. This industry
of upstream cyber-security events. In the study of Radmand et remains vulnerable to a wide range of risks, including natural
al. [9], they propose a taxonomy of wireless sensor network disasters, geopolitical tensions, operational incidents, cyber-
cyber-security threats in the O&G industries, and they present attacks, unauthorized access, etc. Existing classifications are:
common wireless network security criteria and link them to 1) internal and external risks; and 2) classification in general:
probable attacks on wireless networks utilized in O&G ICS. It natural disasters, geopolitical tensions, and operational
focuses solely on wireless technologies. The US Department incidents. These ratings are in-depth, do not highlight all
of Energy issued Risk Management Guidance for Energy aspects and causes of risk, and do not cover all risks that may
Infrastructure, which applies to the O&G field [10]. In the occur. This is why every area of this industry should have
study of McLaughlin et al. [11], the SCADA system and its comprehensive coverage and analytical studies of concerns,
detailed architecture were described. The SCADA risks, and threats. Through this research, we offer a general
communication protocols, critical control system protection, classification of the risks that threaten this field, which can be
and security assessment are also presented. a principle for analytical studies on which each domain is
According to Sergiopoulos et al. [12], there has been no based separately, such as marine oil, land petroleum, or
systematic method for documenting, charting, and transport. We also propose a classification that is related to the
categorizing cyber security breaches in the oil and gas sector. petroleum physical cyber systems, which are the result of
Furthermore, the historical record highlights the vulnerability integrating the smart technological industry with the
of the oil and gas operational technology infrastructure to petroleum industry.
cyberattacks. Our proposed classification is:
In the petroleum field literature, there is a paucity of risk (1) Risk classification for the entire industry of O&G.
modeling and feasible mitigation strategies. Also, there is no (2) Classification in terms of the fact that the cyber-
classification of the full possible risk in the O&G sector. There physical system is the most important component in the O&G
are currently two categories of risk: 1) risks that are internal or industry and that these hazards are either physical, cyber, or
external, and 2) general classifications that include natural connected to permissibility and authorization for O&G firms.
disasters, geopolitical conflicts, and operational incidents.
These ratings do not address every potential risk and do not 2.1 Risk classification for the entire industry of O&G
emphasize every aspect or cause of risk. Also, there are simply
reports, instructions, and guidelines, with no systematic and The field of oil and gas is considered one of the largest vital
comprehensive compilation of all relevant hazards and risks. sectors, which is the backbone of major economies in the
This study contributes to: 1) risk classification for the entire world and is linked to the environment and the ocean because
industry of O&G. 2) classification in terms of the fact that the its extraction and production are hard work in a difficult
cyber-physical system is the most important component in the environment that may be mountainous, marine, or in rugged
O&G industry and that these hazards are either physical, cyber, areas. Operation in this field is based on human, material, and
or connected to permissibility and authorization for O&G equipment factors. Our classification of risk is based on those
companies. 3) proposes a security approach for securing oil aspects: environment, human, business, and security.
and gas zones. The goals of this study are:
(1) Recognize potential risks in the oil and gas industry 2.1.1 HSE (Health, Safety, and Environment) risks
and provide systematic classification. Health. The O&G sector uses and exposes workers to a
(2) How to bridge the gap between the risk’s awareness variety of large and dangerous products, equipment, and
and defense by proposing a security solution that led to the materials. The most typical workplace dangers that affect a
mitigation of impact and aid for protection against risks, which worker's health are:
is a multifaceted security approach that is divided into three (1) Highway car incidents cause 4 out of every 10
parts. workplace fatalities for employees.
The paper is organized as follows: Section 2 describes risk (2) According to the OSHA IMIS Database, 3 out of
classification and distinguishes two types of classification. every 5 fatal on-site incidents are caused by being struck by,
The first is for the entire (O&G) business, which is based on caught in, or caught between moving objects (such as moving
aspects such as HSE, human, business, and security. The or falling machinery, moving vehicles, high-pressure lines,
second classification is related to the cyber-physical system in etc.) [13].
the O&G area. Also, the significance of risk identification and (3) Explosions and Fires: This industry works with
classification, along with some empirical data and a case study, combustible gases and vapors like hydrogen sulfide and well
are presented in this section. Section 3 gives an overview of gases that can escape from trucks, production equipment, or
mitigating the impact of risk in petroleum CPS. Section 4 surface equipment (shale shakers).
100
(4) Chemical exposure occurs in restricted places such as petroleum pool, its abundance and reserves, its nature, its
petroleum storage and other tanks, mud pits, reserve pits, and burial depth, its initial formation pressure, its permeability, its
other dug locations where workers typically operate. Workers active porosity, its cave and fault conditions, and its
are exposed to both health hazards, such as asphyxiation, and underground rock hardness will all have an impact on how
harmful chemical products. well the petroleum operation goes.
Safety. Safety risks may be related to extraction activities,
equipment, or humans. As per the United States Department 2.1.2 Security risks
of Labor, oil and gas extraction activities are associated with Cyber. Expanded automation, expanded computer network
certain safety risks [13], such as human accidents, vehicle connectivity, and increased use of cloud computing services
accidents, explosions and fires, equipment hazards, and expose O&G companies to increasing cyber-security
electrical hazards. vulnerabilities.
Personnel operating on offshore (O&G) facilities, as well as In the study of Mahmoud et al. [19], cyber-attacks are
seafarers in general, are potentially exposed to the classified as denial of service (DoS) assaults, deception attacks,
unpredictability of wind and sea conditions, vessel motion, and replay attacks. In the O&G field, attacks are directed at the
noise, vibration, poor air quality, hazardous chemicals, intense operating domain [20]. The majority of attacks in this sector
physical labor, and cramped workspace [14, 15]. are denial of service (DoS) attacks, which endanger system
Environment. There are four stages of oil and gas availability by flooding the connecting device with requests to
exploration and production [16]: jam communication channels and prevent valid requests [21].
(1) A geological and geographical survey is required to In 2012, one of the world's largest oil firms was the victim of
determine the potential of an oil well for commercial viability. a massive cyberattack. Shamoon, a debilitating wiper infection,
(2) Exploration is a critical step for determining rig made tens of thousands of the company's computer servers
placement, exploratory drilling, plugging the well, destroying inoperable [22]. Another illustration of the Black Energy
production wells, and so on. malware, which evolved from a trojan to a new piece of
(3) One of the major stages is development and malware delivering the KillDisk payload, is a piece of
production, which involves platform commissioning, pipeline malware that has evolved through time. It targeted the power
installation, production drilling, pipeline maintenance, and so plant Prykarpattya Oblenergo as well as other Ukrainian
on. electricity distribution companies [23]. However, we cannot
(4) Decommissioning is the ultimate stage of oil and gas overlook the ransomware attacks that are increasingly
production. When the well is drained, this includes removing prevalent in multiple sectors. Techniques such as network
the platform and plugging the well. traffic or system call analysis can be used to detect this type of
All of these stages have a direct impact on the environment attack upon its appearance [24].
[16]. Examples include the impact of seismic surveys on Piracy. Piracy is regionally based [25], and it is influenced
aquatic species and the interruption of fisheries. Pollution by a number of factors such as unpredictable political
emissions are affected by rig placement during the exploration environments, ineffective governments, a lack of economic
stage. Development and production have an impact on development, poverty, and the capacity to reward in order to
operational discharges, accident spillage, and physical prosper [26]. By 2007, attacks on offshore infrastructure and
disturbances. emissions from operations, other impacts: piracy had become common in the Gulf of Guinea [27]. The
(1) In the Arctic region and in areas of the sea ice cover, offshore petroleum industry has also been impacted by pirate
there are untapped potentials for exploration, and there are activity off the east coast of Africa.
difficulties and obstacles in extracting hydrocarbons [17]. Terrorism. Oil-producing nations are more susceptible to
(2) The use of seismic surveys for exploration has terrorism because oil installations are prime targets for
sparked worries about their effects on marine life due to the terrorist attacks that aim to have a greater impact and disrupt
loud noise they generate. This noise can evict marine species the external interests of powerful nations. It makes use of data
from their habitat, alter their behavior, muddle safety related from the oil industry and terrorist attacks [28].
to equipment and human communication, induce stress, and,
at close ranges, even harm their hearing systems [17]. 2.1.3 Human risks
(3) Oil leak incidents occur during oil exploration and Employees. Quality, operational level, cultural level,
transportation in the offshore petroleum industry. The worry personnel age composition, and overall quality are important
with oil leaks is that they cause enormous contamination in the for the employee in the O&G organization. The lack of these
ocean, which causes a variety of economic and environmental characteristics is the main cause of the risks caused by human
issues [18]. errors. Many studies suggest that drilling events are caused by
According to the United States Department of Labor, oil and people and that human error has played a substantial role in the
gas extraction activities pose: prevalence and severity of the consequences [29].
specific environmental and safety risks [13], such as Managers and organizations. Petroleum operations will be
hazardous chemicals, hydrocarbon gases and vapors (HGVs) impacted by the management skills, charisma, and leadership
and low oxygen environments, temperature extremes, and of managers. These characteristics also relate to organizational
naturally occurring radioactive material (NORM). risk. Petroleum operations will be impacted by these elements,
(1) Climatic risk: The volume of petroleum operations such as illogical organizational structures, inadequate staffing,
will be influenced by meteorological circumstances. For and irrational responsibility distribution. Organizational risk
example, borehole operations are extremely dangerous when will have an impact on the operating period and can impact the
it rains or snows, while petroleum operations are extremely economic effectiveness of the company.
risky when it is extremely hot. Lack of training. Engineers and staff are frequently
(2) Geologic risk: The structure and complexity of the untrained or undertrained in cyber security [30].
101
2.1.4 Business risks this sense, the following are the most well-known cyber risks:
Financial risk. Oil and gas are products, and their prices are (1) Denial-of-service (DoS) attacks: Unavailability
significantly more volatile than those in other markets. In attacks in ICS components can render O&G systems
addition to the actual price of raw materials, the underlying inaccessible if vulnerabilities are successfully exploited [34].
expenses of harvesting and refining natural resources have a (2) Command Injection: Common network attacks on
considerable impact on their pricing. Furthermore, petroleum ICS include blocking or replaying command or reporting
operations have a long cycle, a broad geographical dispersion, messages (DoS) [35].
a huge number of personnel, and a large quantity of funds. (3) Data exfiltration: Data exfiltration is the unlawful
Economic and market risk. Taxation is a key tool for the disclosure of sensitive or confidential information. Data
government to manage oil and gas production, supply, and exfiltration can be committed by either an outsider or an
demand, which directly influence the level of profits of insider of a company [36].
petroleum enterprises. (4) Data tampering: An offensive operation may occur
Supply and demand shocks are a risk for oil and gas firms, within another offensive operation, and the intention is to
especially because energy facilities require large amounts of obscure the larger operation, mislead the data, and deceive the
capital and time to ramp up to full capacity. Concerns have defender [37]. It is called data tempering, and we consider it
been raised about any disruption in the global supply of oil and an indirect attack.
gas (O&G), which might have an impact on oil prices and, by
extension, the global economy [31]. 2.2.3 Authorization risks for petroleum CPS
This danger is tied to both human and material factors. Any
2.2 Risk related to petroleum CPS in the O&G industry human access to facilities and the use of any material not
allowed in the field of exploitation, production, or discipline.
2.2.1 Physical risks for petroleum CPS Even unauthorized access to data can be used to abuse the lack
Physical hazards are those that threaten facilities, equipment, of cryptography in protocols or communication channels.
and the human factor and cause physical damage to them, such Internal authorization and access (employees).
as destruction, burning, and vandalism. In the oil and gas (1) Employees' lack of threat awareness, coercion or
industry, we consider that any damage that may be caused to blackmail, or even the sale of company security information
facilities, storage equipment, storage levels, and transportation on the dark web for profit can raise network vulnerability and
equipment is physical damage [32]. In this context, we can constitute a critical risk. In 2017, for example, an employee in
mention the most important physical risks as follows: the Middle East used a USB drive to download and watch a
Tank attacks. The treated gas and water are held in settling movie on a critical infrastructure computer. The user was
tanks until they may be exported. The oil tank level spoopng unaware that this activity resulted in the distribution of
Attacks are outfitted with level control sensors that send data malware later called Copperfield by Nyotron, the company in
to avoid tank overfilling. The major purpose of this approach charge of detecting it. Data leakage, network scanning, and
is to deceive sensors into reporting that the tank level is lower remote control of an ICS workstation were all caused by
than it actually is [31]. Copperfield [38].
Wellhead production data exfiltration. By using malicious (2) A risk exists due to the lack of strong authentication
software such as trojans on hacked control station and authorization procedures for personnel and any software
workstations, an attacker could gain access to sensitive entities.
information such as wellhead production data. The use of (3) Many studies believe that drilling events are caused
Domain Generation Algorithms (DGA) in creating by humans and that human error has played a significant role
communications between bots and their Command and in incidence and consequence aggravation.
Control (C&C) servers is one example that led to obtaining External access (third parties or foreign and attackers).
sensitive information [32]. Third-party SCADA systems must be monitored for
Drone attacks. Physical attacks are also a problem; just dependability risks such as firmware changes,
recently, a drone attack on the world’s largest refinery crippled misconfigurations, open ports, communication failures,
5% of the world’s global oil supply [33]. equipment faults, and others.
The risks here revolve around the possibility of operating
2.2.2 Cyber risks for petroleum CPS these systems remotely, through strangers from the company,
Numerous threats were faced upstream, such as during the or through professional attackers. External remote services
exploration phase, when malware entered through network may serve as attack surfaces for adversaries seeking to get first
storage nodes to steal competitive seismic data for an offshore access to internal network resources from distant locations
field that was up for bid. As in the development phase, a pre- [39].
deployed rogue program begins dictating drilling parameters, Using the TRISIS framework, Xenotime created a
resulting in well deviation and other well integrity difficulties. disruption at an O&G plant in Saudi Arabia in 2017. This
Through the production and abandonment phases, a masked malware was designed to attack the Triconex safety controllers
worm in SCADA arbitrarily adjusts the speed of motor pumps, [7]. It employed backdoor malware to shut down the facility's
resulting in suboptimal production and well damage. industrial systems.
Cyber-attacks are occurring on the industrial control Table 1 summarizes the most significant and well-known
systems (ICS) of O&G firms, putting worker safety, reputation, risks associated with the CPS and system structure in the oil
and operations, as well as the environment, at risk. Whether and gas industry.
hackers use spyware to target field bidding data, malware to Many studies have cited events and accidents in the O&G
infect production control systems, or denial of service to block industry; we categorized this event using our proposed risk
the flow of information through control systems, they are classification in petroleum CPS. Table 2 shows some O&G
becoming increasingly sophisticated and, particularly industry events.
concerning, launching coordinated attacks on the industry. In
102
Table 1. Well-known risks associated with the CPS and system structure in the oil and gas industry
Components
Description Risks Impact
in O&G
- Cyber-attacks on O&G systems might - Hardware Layer: Tampering attacks and
- Third-party devices may present
be allocated to different ICS physical attacks [32, 39]
unforeseen vulnerabilities in both
architectural layers. - Supply chain attacks as hardware trojans in
upstream and downstream
- Devices and embedded components any stage of the supply chain [40-42].
infrastructures [40]
such as RTU, PLC, and relays are - Unpatched legacy/end-of-life equipment.
found in the hardware layer. - Firmware Layer: firmware injection [40, 43]
- Disruption of ICS operation
- The firmware layer is between the attacks
hardware and software layers. It - Software Layer: injection, malware attacks,
consists of the operating system that remote code execution [32, 39].
is used by midstream and downstream - Unpatched operating systems [44]-SQL - Disruption of ICS operation
controllers, systems, and field injection, malwares attacks [45], XSS and - Affect ICS process
equipment. CSRF Attacks [46]-Buffer overflows [45, - Compromised OT processes,
- The software layer of an ICS includes 46]. commands and data
ICS
all of the programs used to monitor - Improper access control or authentication
and control machines and peripheral processes in software used in ICSs [47-49]
systems, as well as other software - Network Layer: Dos attacks and jamming
platforms and human machine - ICS exposed to network attacks
attacks.
interfaces. [50]
- MODBUS lacks of secure channel [48].
- The network layer contains: firewalls, - Attackers can get access to field
- FINS protocol for PLC lacks encryption in
modems, routers, remote access devices and control-related
data exchanges [49]
points. [7] and wireless sensors use S- systems [51]
- Absence of network partitioning
MAC, LMAC or B-MAC protocols.
- Layer of Processing: The dynamic - Attackers operate machinery, alter
properties of the intended ICS model - Layer of Processing: ICS-centric attacks [52] production, losses in revenue,
must be followed by the ICS performance degradation [53, 54]
procedures [52].
- Field Bus Layer: Telnet intrusions [56]
intrusion from outside the local network,
- SCADA Components: Three Layers which may affect both routine and aberrant - Unavailability
(filed bus, Industrial Ethernet, login attempts and command/response
Business Management) [55]. exchanges, DoS attacks
- SCADA communication protocols - The FINS protocol not use
SCADA such as Modbus-TCP Distributed - Industrial Ethernet Layer: DoS attacks, encryption to exchange data.
Network Protocol (DNP3), IEC- integrity attacks, and phishing attacks [58]. Using wireshark to extract the
60870–5-104 and the Inter-Control - Attacks on the PLC: Cryptographic attacks, password of the read protection as
Center Protocol (lCCP, IEC60870–6) Replay attacks, Fragmentation attacks. it was being transferred to the
[57]. PLC
- Business Management Layer: onan attack,
- Unavailability
DoS attacks
- On closed loop systems, smart
- Sensor misconfigurations [59]
meters compete with one another
- The use of IoT devices spread across
- Failures caused by the interaction of smart - Denial of Services and integrity
all layers.
gadgets and legacy equipment incidents
IOT - O&G IoT systems enable real-time
- Absence of access control or encryption on
monitoring and control of activities
IoT device links - Affecting the overall
throughout the value chain.
- Using insecure open source code and infrastructure ecosystem [60]
implementations
- Field device communication
- Vulnerable to denial-of-service, man-in- - Unavailability
Protocols protocols (ZigBee, 6LoWPAN, and
the-middle, and spoofing attacks [39, 61] - Integrity incidents
so on) [32].
- Sensors: Spoofing attacks that result tank
- Explosion, loss of life,
- Access control hardware (smart cards, overfill and containment breach -
environmental damage
RFID, etc.), server hardware Temperature or pressure sensors: Data
- Bad product quality, revenue loss.
(RACKs, CPUs, etc.), sensors, tampering attacks
- Exposing sensitive information,
Hardware actuators, RTUs, PLCs, routers, - PLC, safety instrumented system, and
injecting false information into
valves, ATGs, slaves, et. actuators: DoS attacks
actuator states, causing DoS, shut
- WSN security issues in all layers - PLC, pumps, actuators: Command
down, restart, or even require
(from hardware to application layer). injection attacks - controlled simulated
reprogramming [60, 62]
attacks: can target all hardware in all layers
2.3 Significance of risk identification and classification of Shah et al. [63], Khadem et al. [64], and Zand [65], have
proved that risk identification and resource allocation are the
Many case studies in the literature that focus on risk analysis basis of the risk management process and the key to the
and assessment in the oil and gas sector, such as in the studies protection action plan.
103
Table 2. Events in oil and gas industry
According to Shah et al. [63], constructing new oil and gas study to highlight some of the most critical risk elements
pipelines (OGPs) without studying the potential risk factors associated with oil and gas projects, as well as
(RFs) that influence the safety of these pipes creates time and recommendations for risk reduction. The argument is based on
expense overruns in these projects. In the field of oil and gas, publicly available material and covers two independent
to prevent project failure, it is vital to appropriately manage projects in Iran and Qatar. Furthermore, they provided a
the related risks [64]. Reducing future delays and cost framework that suggests recognizing and evaluating risks as
overruns in oil and gas projects involves conducting risk early in the project life cycle as is feasible. The types of risk
analysis and developing risk management measures [65]. introduced in the study of Zand [65] are construction,
Creating safe and secure systems in the oil and gas industry operational, regulatory, and financial. They overlooked the
requires detecting and categorizing all types of risk. Risk human element, as well as the organization's overall safety and
classification facilitates the definition of roles and duties security.
within the oil and gas organization, as well as the identification In reality, human, material, and equipment aspects are the
of vulnerable regions and their causes. This simplifies risk foundation of operations in the oil and gas sector and power
minimization and protection. The aim of this study is to the global economy while being encircled by the natural
identify potential risks in the oil and gas sector and to offer a environment. All activities in the oil and gas sector should be
methodical classification based on findings from published carried out safely and securely. Based on those factors -
research as well as guidelines and reports. environment, human, business, and security - we categorize
The current risk classification in the literature fails to take risk. Table 3 shows the findings of published papers in each
into account all relevant industry aspects and elements, such risk class.
as in the study of Zand [65]. The authors conducted a case
104
Table 3. The findings of published papers in each risk class and gas industry. We use the Qatar Petroleum Organization's
Health, Safety, and Environmental Conservation and
Cyber Risk
HSE Human Business Protection Policy [70] as a case study.
Risk Risk Risk
[7, 13-
[13-18,
15, 29, [31, 63-
[6-24, 32-43, 45-47, 49-61] 31-33,
30, 38, 65]
66, 67]
39, 66]
105
3. RISK MITIGATION IN THE OIL AND GAS exploitation, processing, and transportation systems and
INDUSTRY operations.
We can summarize the most important measures, proposals,
History has shown that oil and gas OT infrastructure is and recommendations in the field of protecting gas and oil
susceptible to cyberattacks. Many surveys, such as the study facilities in the following group of points, which we have
[62], emphasize dangers and risk reduction in different ways arranged according to their importance from our point of view:
and with different goals. Alcaraz and Zeadally [71] discuss (1) Identify and classify safety and security concerns in
CPS vulnerabilities and prospective threats, as well as O&G firms.
mitigating remedies. They presented a testbed for finding (2) Identify the weaknesses and causes of vulnerability
vulnerabilities in SCADA protocols in the study of Sayegh et and responsibility.
al. [49]. (3) Setting the safety and security objectives.
An overview of ICS security and protocol-related (4) Develop a safety and security plan, combining safety
(Modbus/TCP, DNP3, IEC 61850) and sensor/actuator with security standards.
vulnerabilities is presented, along with recommended security (5) Industrial control system availability and integrity are
solutions to mitigate their risk [72]. assured with a strong and modern cyber strategy.
Most statistics indicate that operator error or illegal activity (6) Early detection of attacks and managing time for
is what causes accidents. Therefore, the petroleum industry response and defense.
should improve staff education and engage in a variety of (7) To prevent physical manipulation, employ hardware
inspection, advocacy, and communication activities. security safeguards.
Malware mitigation, intrusion, and anomaly detection are (8) Incorporate end-to-end encryption and embedded
suggested for security and privacy in the study of Chen et al. security in all processes.
[73]. To lower the danger of permitted access, facilities should (9) Implement authentication and access control
put strong authentication and authorization procedures in place mechanisms.
for all software entities and their workers. (10) Every facility must implement appropriate network
In the study of Marzooq and Rashid [74], they studied ways segmentation.
to raise safety awareness and showed how a person's (11) Assure employee training and raise their awareness.
consciousness and behaviors have a big impact on their safety,
actions, and capacity to deal with risks at work.
The O&G industry is strongly encouraged to adhere to 4. A PROPOSED SECURITY APPROACH FOR
standards. In order to make the methods understandable to SECURING OIL AND GAS ZONES
design engineers, they illustrate IEC61508 compliance in oil
and gas applications with an emphasis on steam turbines and 4.1 Secured oil and gas zone
provide a strategy for reliability analysis of intricate safety-
structured systems [75]. A secured zone is a collection of logical or physical assets
The National Institute of Standards and Technology (NIST) that all have the same security criteria within the oil and gas
explained by Stouffer et al. The study [47] how organizations organization. A zone has a distinct boundary with other zones.
should design and implement security programs and security A zone's security policy is often implemented by a
strategies for the Industrial Control System (ICS). It combination of measures located both at the zone's perimeter
highlighted how existing IT security knowledge, programs, and within the zone. Zones can be hierarchical in the sense that
and practices should be coordinated and integrated into new they can be made up of subzones (ANSI/ISA-99.00.01-2007,
programs. It was suggested that the unique needs and Security for Industrial Automation and Control Systems, Part
characteristics of ICS technologies and surroundings be taken 1: Terminology, Concepts, and Models, 29 October 2007).
into account. It is also suggested that organizations regularly
examine and update their ICS security plans and procedures to 4.2 Phases of the proposed security approach
reflect changes in technologies, operations, standards, and
regulations, as well as particular facility security demands. This subsection proposes a multifaceted approach, which is
There is a widespread belief among security experts that it divided into three parts. The first part identifies systems,
is impossible to defend the perimeter of their IT systems, and architectures, and risks in the oil and gas zone. The second
the focus is shifting from defense to detection and rapid phase involves integrating industrial Next-Generation
response. The energy sector is vulnerable to a variety of threats Firewalls (NGFW) for SCADA and ICS systems. The third
that can have serious consequences for operations, safety, and phase involves incorporating oil and gas industry standards
the environment. into the security life cycle of oil and gas zones. Figure 3
Some defense approaches and risk management strategies depicts the security approach, which focuses on the following
concentrated on basic gaps in the literature and frequently security goals:
discovered reports from real-world cyberattacks. In the (1) Securing the zone perimeter.
previous part, we classified existing risks in the oil and gas (2) Protect the oil and gas zone from common risks.
industry into physical, cyber, and authorization categories. To (3) Prevents unauthorized access and reduces access to
lower each category of risk, we recommend combining data and resources.
associated safety and health standards, as well as cyber and
environmental norms and regulations. The most important 4.2.1 Phase one: Identifying systems, architectures, and risks
standard is ISO 20815:2008, an international standard for in the oil and gas zone and gaining visibility over assets
production assurance and dependability management in the This phase includes recognizing and describing locations,
petroleum, petrochemical, and natural gas industries. It types, quality, and total assets, as well as having complete
includes production assurance principles in drilling, visibility over OT assets such as field devices, SCADA
106
systems, and network visibility. Also, a complete collection of systems in the oil and gas zone is the cover of the technology's
data and specifications for all PLC, RTU, DCS, and SCADA subzone (ICS, SCADA). Next-Generation Firewalls (NGFW)
devices, as well as operating systems and related are industrial threat security firewalls that provide visibility,
vulnerabilities, is presented in Table 1. control, and automatic real-time analytics detection. The
The segmentation of networks and using various firewall's objective is to reduce the risk of unwanted access (or
technologies are the most utilized strategies for vulnerability network traffic) and adhere to the philosophy of minimum
mitigation and control in the sphere of oil and gas [76]. We permission and continuous surveillance of all traffic.
separated the petroleum zone into systems (ICS, SCADA) to How is integrating industrial NGFWs into SCADA and ICS
boost its security, as mentioned in Figure 3. The objective Systems?
behind system identification is to partition the system into Large, complicated systems, such as aged industrial
discrete security subzones and add layers of protection to machinery and dispersed networks, can be found in
separate the system's most critical components. Figure 3 ICS/SCADA environments. In order to design an acceptable
presents ICS and SCADA components. solution, it is necessary to analyze the needs and complexity
Regarding risk identification as a key task in this phase, we of the ICS and SCADA environments before implementing
classified risk for petroleum CPS in Section 2 as physical, firewalls.
cyber, and authorization risks. The ICS and SCADA environments should only allow users
to access the designated areas. When moving to a different
4.2.2 Phase two: Using Industrial Next-Generation Firewalls network level, safeguarding the access by incorporating a
(NGFW) for SCADA and ICS systems firewall on each side prevents unauthorized access. Figure 4
A firewall is a network security device that monitors and shows ICS and SCADA, which are divided into network levels
restricts network traffic based on predefined security rules and are based on the ISA-99 standard.
(Wikipedia). The idea of using industrial NGFWs for secure
107
Figure 5. Risk in oil and gas zones and related standards: 1) Organization standards for authorization risks 2) cybersecurity
standards for cyber risks; and 3) HSE standards for physical risks
We employed an industrial NGFW with an integrated the petroleum industry as physical, cyber, and authorization.
transparent mode. Traffic is reviewed against ASA firewall Figure 5 (assembled by the authors) depicts the risks and
policies, such as access rules, in this mode, and any traffic related standards for the oil and gas perimeter.
identified for blocking by these policies is dropped. A subset We divided the oil and gas perimeter into three virtual axes:
of the traffic is then inspected per FirePOWER inspection perimeter access, physical perimeter, and cyber perimeter.
policies, and any traffic marked for blocking is deleted. This phase proposes the protection of those axes and the key
The implementation of the suggested NGFW integration is standards that may relate.
based on the following steps: Protection of perimeter access. There is a requirement for
(1) Divide ICS and SCADA into network layers based on technological measures that monitor entry into petroleum
the ISA-99 standard. zones. Physical access or logical access is possible, and the
(2) Select the transparent mode of NGFW. organization should address authorization protection.
(3) Logging and inspection of SCADA protocols and ICS All oil and gas companies have rules, laws, policies,
by Next Generation SCADA protocols include Distributed guidelines, and directives that help them achieve their security
Network Protocol Version 3 (DNP3), which can use TCP, goals and objectives. Securing logical access includes
UDP, or both. Another option is Modbus/TCP. c) The Open authentication procedures, ACLs inside network components,
Platform Communications Unified Architecture (OPC UA). intrusion detection and prevention systems (IDS and IPS)
(4) Alerts for malformed traffic. signatures, and situational awareness tools.
(5) Configuration tasks are completed via the For securing physical access, organizations may use the
management client. following common procedures to avoid unwanted physical
The applications of Next-Generation Firewalls (NGFW) access to perimeters and system impacts:
include: (1) Forbid unauthorized physical access to critical
(1) Encryption capabilities. locations.
(2) Whitelisting. (2) Forbid unauthorized physical modification,
(3) VPN. manipulation, theft, or other removal or damage of existing
(4) Intrusion detection. systems, infrastructure, or communications interfaces.
(5) Deep Packet Inspection. (3) Forbid unauthorized communication eavesdropping,
To maintain cyber security and the security lifecycle, the or other potentially detrimental impact, such as a USB
following actions should be completed: memory device, wireless access point, Bluetooth, or cellular
(1) Upgrading antivirus signatures. device.
(2) Applying security updates to Windows servers. (4) Manage access to the ICS and server rooms.
(3) Using intrusion detection systems (IDS) that can (5) Physical access requires multifactor authentication
detect malicious or suspicious network activity. (key card, card-and-personal identification number (PIN), or
biometric).
4.2.3 Phase three: Integrate oil and gas industry standards into (6) Employing cameras and motion detectors to monitor
the security life cycle of oil and gas zones entry.
Organizations in the oil and gas industry are increasingly (7) Notifying of any device manipulation, such as power
having to deal with many kinds of threats. We proposed in this removal, device resets, cabling modifications, or the addition
phase to integrate oil and gas standards into the security life or use of removable media devices.
cycle of oil and gas zones. We previously classified risks in Protection of Physical Perimeter. It is vital to address the
108
physical protection of the petroleum zone, its components, 4.3 Challenges
infrastructure, and humans as part of the overall security of the
zone's environment. Integrating several oil and gas standards into the security
Many zone facilities' security is strongly linked to safety, life cycle of zones presents substantial challenges. There is a
with the primary purpose of keeping people out of potentially link between applying safety and cybersecurity requirements
hazardous circumstances while allowing them to conduct their and Petroleum and Gas Authority legislation and controls.
jobs or carry out emergency measures. Physical security (1) Objectives and methods: Aligning standard
controls are any physical measures mandated by objectives and procedures is a challenging task. HSE standards
organizational rules and directives in accordance with the oil are focused on standardizing, preventing, and mitigating the
and gas industry's HSE standards. impacts of material and hardware failures or systematic errors
The key standards for the protection of the physical that can lead to hazardous occurrences and accidents that
perimeter are: endanger the environment and human health. The
(1) ISO 45001/2018: The worldwide standard ISO 45001 cybersecurity standard focuses on preventing or mitigating the
for occupational health and safety helps shield workers and effects of acts that may jeopardize the confidentiality, integrity,
guests from illnesses and accidents related to their jobs. or availability of information or systems. The organization
(2) API Standard 780 is employed by pipeline operators, standard focuses on preventing or minimizing unwanted
which makes it easier to conduct security risk assessments access to systems and data within the oil and gas perimeter
(SRAs), which are intended to identify and reduce hazards. using access rules, regulations, and laws.
Approved as a suitable anti-terrorism technology by the (2) Standards compliance and application should ensure
Department of Homeland Security (DHS). that cybersecurity measures do not impair functional safety
(3) HSE guidance on managing Industrial Automation performance or vice versa. Some security measures or
and Control Systems (IACS). techniques, such as encryption or authentication methods, may
Protection of the cyber perimeter. Communication boost security while also adding delay or complexity to the
breakdowns and cyberattacks are threats that SCADA and ICS reaction time or availability of the safety function.
systems must overcome to maintain their safety and (3) It is critical to undertake a holistic review throughout
dependability. In order to guarantee that SCADA systems in the lifecycle phases to guarantee that oil and gas standards are
the oil and gas sector are reliable and safe, Gosnadzor [68] integrated and consistent with one another. Close
offered an examination of the fundamental security and collaboration and coordination are required among the various
reliability design process. To ensure the design of safe stakeholders involved in the design, implementation, and
SCADA and ICS, as well as secure operation in oil and gas testing of industrial systems [77]. It also necessitates ongoing
zones, the IT and OT security lifecycles in the oil and gas monitoring and enhancement of both functional safety and
sector should be maintained and accorded with a set of security cybersecurity.
standards.
The key standards of cyber security are:
(1) The NIST Cybersecurity Framework is the 5. DISCUSSION
preeminent framework utilized by organizations across all
industries; natural gas and oil companies are increasingly The oil and gas sector faces a variety of hazards, with cyber
focusing enterprise-wide programs on the NIST CSF. It was being one of the most critical due to the industry's reliance on
used to strengthen critical infrastructure security. increasingly interconnected IT and OT systems. For
(2) (ISO) 27000: The most well-known standard in the Addressing these difficulties and improving oil and gas
family, it specifies the standards for information security cybersecurity are vital for protecting critical infrastructure and
management systems. systems, ensuring safety, and ensuring the industry's
(3) ISO 9001: Quality Management System. operational continuity. We attempted to close the gap in this
(4) The International Electrotechnical Commission's field by implementing a thorough risk classification for the
(IEC) 62443 is a leading set of standards for industrial control domain of oil and gas and highlighting existing mitigation and
systems (ICS) security. It is widely used in the oil and gas industry best practices.
sector and may be used for any kind of ICS. The security of assets and key infrastructure in the oil and
(5) SOC certification: system and organization controls. gas industry is challenging, and no clear and practical solution
(6) GDPR certification: General Data Protection can truly carry and guard against all risks in this field.
Regulation. In this study, we presented a multifaceted security approach
(7) NIS Directive (EU) 2016/1148. that is divided into three parts, the first of which is the
To carry out this phase: reconfiguration and assessment of infrastructure that may exist
(1) Safety procedures and processes need to be defined, in the oil and gas zone.
including safety procedures for various operations within the The second phase will focus on integrating new-generation
perimeter, such as drilling, transportation, and refining. industrial firewalls into SCADA and ICS systems in the oil
Develop an emergency response plan for various eventualities, and gas industry. This integration aids in the segmentation of
such as spills, fires, and accidents. Provide employees training the network of zones into levels so that each one can be
on safety measures and risk awareness. secured and separated from the others. Firewalls, strong
(2) Compliance: Implement local and international HSE perimeter defenses, intrusion detection and prevention
rules and perform regular audits and evaluations. systems (IDS), and secure network topologies can all help to
(3) Measurement: Create customized methods to monitor protect critical systems from unauthorized access.
HSE performance and conduct regular inspections, The final phase focused on meeting and strengthening
assessments, and audits. several oil and gas standards, which can significantly aid in
managing ever-changing threats.
109
The proposed security approach's purpose is to protect vital based architecture for oil and gas industry. 2017 19th
infrastructure, provide business continuity, avoid cyber threats, International Conference on Advanced Communication
manage various risks, and monitor and regulate activities in Technology (ICACT), PyeongChang, Korea (South), pp.
zone networks. 705-710.
[Link]
[6] Hacquebord, F., Pernet, C. (2019). Drilling deep: A look
6. CONCLUSION at cyberattacks on the oil and gas industry. Trend Micro
Research.
Industrial cyber security is critical for removing many of the [7] Dragos. (2019). Global Oil and Gas Cyber Threat
main risks associated with the oil and gas industry's new trends Perspective. [Link]
and difficulties. To mitigate risks, it is critical to raise content/uploads/Dragos-Oil-and-Gas-Threat-
awareness of all types of existing dangers. This paper provides [Link].
a risk classification for the entire industry of O&G and a [8] Lobo, F. (2018). Upstream oil & gas cyber risk:
classification of risk related to the petroleum cyber-physical Insurance technical review. Lloyd’s Market Assoc.:
system. Both risk classifications seek to aid in the London, UK.
establishment of a framework for assessing the complete risk [9] Radmand, P., Talevski, A., Petersen, S., Carlsen, S.
profile of the oil and gas industry, as well as cyber risk (2010). Taxonomy of wireless sensor network cyber
connected to CPS in particular. Such profiles could be used to security attacks in the oil and gas industries. 2010 24th
simplify the careful provision of cyber-related insurance IEEE International Conference on Advanced
coverage for oil and gas facilities. Information Networking and Applications, Perth, WA,
The paper also bridges the gap between the risk’s awareness Australia, pp. 949-957.
and defense by presenting long-term mitigations that aid in [Link]
protection against risks. The proposed security approach [10] DOE. (2011). Risk Management Guide. PM - Office of
ensures the security of the oil and gas perimeter. This approach Project Management Oversight and Assessments.
considers the interconnectivity of physical and digital Available at [Link]
components within the oil and gas zone, seeking to [11] McLaughlin, S., Konstantinou, C., Wang, X., Davi, L.,
comprehensively protect all parts within this perimeter. Sadeghi, A.R., Maniatakos, M., Karri, R. (2016). The
The proposed solution is a multifaceted security approach cybersecurity landscape in industrial control systems.
that includes the configuration and evaluation of potential Proceedings of the IEEE, 104(5): 1039-1057.
infrastructure in the oil and gas zone as an initial phase. In the [Link]
second phase, the oil and gas industry's SCADA and ICS [12] Stergiopoulos, G., Gritzalis, D.A., Limnaios, E. (2020).
systems are integrated with industrial new-generation Cyber-attacks on the oil & gas sector: A survey on
firewalls. that facilitate the division of the zone network into incident assessment and attack patterns. IEEE Access, 8:
distinct and secure levels and shield vital systems from 128440-128475.
unwanted access. The final phase concentrated on achieving [Link]
and reinforcing compliance with oil and gas standards, which [13] Oil and gas extraction - hazards. Occupational Safety and
can greatly help in handling constantly evolving risks. Health Administration. [Link]
For future work, we are planning on implementing the gas-extraction/hazards, accessed on Nov. 22, 2023.
strategy of zero-trust in the oil and gas industry. [14] Haward, B.M., Lewis, C.H., Griffin, M.J. (2009).
Motions and crew responses on an offshore oil
production and storage vessel. Applied Ergonomics,
REFERENCES 40(5): 904-914.
[Link]
[1] Alcaraz, C., Zeadally, S. (2013). Critical control system [15] Oldenburg, M., Hogan, B., Jensen, H.J. (2013).
protection in the 21st century. Computer, 46(10): 74-83. Systematic review of maritime field studies about stress
[Link] and strain in seafaring. International Archives of
[2] Stellios, I., Kotzanikolaou, P., Psarakis, M., Alcaraz, C., Occupational and Environmental Health, 86: 1-15.
Lopez, J. (2018). A survey of IoT-enabled cyberattacks: [Link]
Assessing attack paths to critical infrastructures and [16] Chandrasekaran, S. (2016). Health, Safety, and
services. IEEE Communications Surveys & Tutorials, Environmental Management in Offshore and Petroleum
20(4): 3453-3495. Engineering. John Wiley & Sons.
[Link] [17] Levantesi, S., Levantesi, S., Bongioanni, M., Bongioanni,
[3] Giraldo, J., Cárdenas, A., Quijano, N. (2016). Integrity M., Olivieri, F., Olivieri, F. (2020). Oil and gas
attacks on real-time pricing in smart grids: Impact and exploration poses severe risks to marine species, better
countermeasures. IEEE Transactions on Smart Grid, 8(5): management is needed. LifeGate.
2249-2257. [Link] [Link]
[4] Zhou, J., Li, L., Vajdi, A., Zhou, X., Wu, Z. (2021). risks-to-marine-life.
Temperature-constrained reliability optimization of [18] Rink, K., Chen, C., Bilke, L., Liao, Z., Rinke, K., Frassl,
industrial cyber-physical systems using machine learning M., Kolditz, O. (2018). Virtual geographic environments
and feedback control. IEEE Transactions on Automation for water pollution control. International Journal of
Science and Engineering, 20(1): 20-31. Digital Earth, 11(4): 397-407.
[Link] [Link]
[5] Khan, W.Z., Aalsalem, M.Y., Khan, M.K., Hossain, M.S., [19] Mahmoud, M.S., Hamdan, M.M., Baroudi, U.A. (2019).
Atiquzzaman, M. (2017). A reliable Internet of Things Modeling and control of cyber-physical systems subject
110
to cyber attacks: A survey of recent advances and Acquisition (SCADA) systems, Distributed Control
challenges. Neurocomputing, 338: 101-115. Systems (DCS), and other control system configurations
[Link] such as Programmable Logic Controllers (PLC). US
[20] Avanzini, G.B., Spessa, A. (2019). Cybersecurity Dept. of Commerce, National Institute of Standards and
verification approach for the oil & gas industry. In Technology.
Offshore Mediterranean Conference and Exhibition, [33] Kalin, S., Gamal, R.E., Zhdannikov, D. (2019). Attacks
Ravenna, Italy. on Saudi oil facilities knock out half the kingdom's
[21] Taylor, J.M., Sharif, H.R. (2017). Security challenges supply. Reuters.
and methods for protecting critical infrastructure cyber- [34] Ing. Punzenberger Copa-data GmbH dos vulnerabilities:
physical systems. In 2017 International Conference on CISA. Cybersecurity and Infrastructure Security Agency
Selected Topics in Mobile and Wireless Networking CISA. [Link]
(MoWNeT), Avignon, France, pp. 1-6. advisories/icsa-12-013-01.
[Link] [35] Krishna Moorthy, U., Anding, D., Ng, C. L., Songli, S.,
[22] Finkle, J., Finn, T., Wagstaff, J. (2016). Shamoon virus Sahak, S., Baharudin, M.H. (2020). Alternative method
returns in Saudi computer attacks after four-year hiatus. to supply pneumatic air to an unmanned platform, in the
Reuters. [Link] article/us-cyber- event of the platform’s instrument gas system is on
saudi-shamoon-targets-idUSKBN13Q4AX/. downtime. In SPE Annual Technical Conference and
[23] Wilhoit, K. (2016). Killdisk and BlackEnergy Are Not Exhibition, p. D031S021R002.
Just Energy Sector Threats. Online: [Link]
[Link] [36] Ullah, F., Edwards, M., Ramdhany, R., Chitchyan, R.,
intelligence/killdisk-and-blackenergy-are-not-just- Babar, M.A., Rashid, A. (2018). Data exfiltration: A
energy-sector-threats. review of external attack vectors and countermeasures.
[24] Dib, A., Ghazi, S., Mehdi, M.M.S. (2023). Ransomware Journal of Network and Computer Applications, 101: 18-
attack detection based on pertinent system calls using 54. [Link]
machine learning techniques. International Journal of [37] Zhang, F., Kodituwakku, H.A.D.E., Hines, J.W., Coble,
Computer Networks & Communications (IJCNC), 15(4): J. (2019). Multilayer data-driven cyber-attack detection
123-145. [Link] system for industrial control systems based on network,
[25] Kamal-Deen, A. (2015). The anatomy of Gulf of Guinea system, and process data. IEEE Transactions on
piracy. Naval War College Review, 68(1): 93-118. Industrial Informatics, 15(7): 4362-4369.
[26] Murphy, M.N. (2007). Small boats, weak states and dirty [Link]
money: Contemporary piracy and maritime terrorism's [38] Iaa1- Operation Copperfield, Nyotron,
threat to international security. Doctoral dissertation, [Link]
Reading University. cyberattack-spotted-targeting-mideast-critical-
[27] Nincic, D. (2009). Maritime piracy: Implications for infrastructure-organizations. 2019.
maritime energy security. Journal of Energy Security, [39] Strom, B.E., Applebaum, A., Miller, D.P., Nickels, K.C.,
3(1). Pennington, A.G., Thomas, C.B. (2018). Mitre att&ck:
[28] Lee, C.Y. (2018). Oil and terrorism: Uncovering the Design and philosophy. Technical Report, The MITRE
mechanisms. Journal of Conflict Resolution, 62(5): 903- Corporation.
928. [Link] [40] Zerdazi, I., Fezari, M., Bayart, M. (2019). Evolution and
[29] Amir-Heidari, P., Maknoon, R., Taheri, B., Bazyari, M. vulnerability in SCADA systems.
(2016). Identification of strategies to reduce accidents [Link]
and losses in drilling industry by comprehensive HSE volution_and_Vulnerability_in_SCADA_Systems.
risk assessment—A case study in Iranian drilling [41] Tsoutsos, N.G., Konstantinou, C., Maniatakos, M.
industry. Journal of Loss Prevention in the Process (2014). Advanced techniques for designing stealthy
Industries, 44: 405-413. hardware trojans. In Proceedings of the 51st Annual
[Link] Design Automation Conference, pp. 1-4.
[30] Gol Mohammadi, N., Paulus, S., Bishr, M., Metzger, A., [Link]
Könnecke, H., Hartenstein, S., Weyer, T., Pohl, K. [42] Jin, Y., Maniatakos, M., Makris, Y. (2012). Exposing
(2014). Trustworthiness attributes and metrics for vulnerabilities of untrusted computing platforms. 2012
engineering trusted internet-based software systems. In: IEEE 30th International Conference on Computer Design
Helfert, M., Desprez, F., Ferguson, D., Leymann, F. (eds) (ICCD), Montreal, QC, Canada, pp. 131-134.
Cloud Computing and Services Science. CLOSER 2013. [Link]
Communications in Computer and Information Science, [43] Gao, W., Morris, T., Reaves, B., Richey, D. (2010). On
vol 453. Springer, Cham. [Link] SCADA control system command and response injection
319-11561-0_2 and intrusion detection. 2010 eCrime Researchers
[31] Mohammed, A.S., Reinecke, P., Burnap, P., Rana, O., Summit, Dallas, TX, pp. 1-9.
Anthi, E. (2022). Cybersecurity challenges in the [Link]
offshore oil and gas industry: An Industrial Cyber- [44] Kovacs, B. (2023). Hackers can exploit Siemens control
Physical Systems (ICPS) perspective. ACM system flaws in attacks on power plants. SecurityWeek.
Transactions on Cyber-Physical Systems (TCPS), 6(3): [Link]
1-27. [Link] siemens-control-system-flaws-attacks-power-plants/.
[32] Stouffer, K., Pillitteri, V., Lightman, S., Abrams, M., [45] Deresford. (2010). The sauce of utter pwnage.
Hahn, A. (2015). Guide to Industrial Control Systems [Link]
(ICS) security: Supervisory Control and Data [46] Stouffer, K., Falco, J., Scarfone, K. (2011). Guide to
111
industrial control systems (ICS) security. NIST Special [Link]
Publication, 800(82): 16-16. [62] Stergiopoulos, G., Gritzalis, D.A., Limnaios, E. (2020).
[47] iSIGHT Intelligence, F. (2016). Overload: Critical Cyber-attacks on the oil & gas sector: A survey on
lessons from 15 years of ICS vulnerabilities. incident assessment and attack patterns. IEEE Access, 8:
[48] Ádámkó, É., Jakabóczki, G., Tamás, S.P. (2018). 128440-128475.
Proposal of a secure modbus RTU communication with [Link]
Adi Shamir's secret sharing method. International [63] Shah, R., Kraidi, L., Matipa, W., Borthwick, F. (2022).
Journal of Electronics and Telecommunications, 64(2): Investigation of the risk factors causing safety and delay
107-114. [Link] issues in oil and gas pipeline construction projects. In:
[49] Sayegh, N., Chehab, A., Elhajj, I.H., Kayssi, A. (2013). Batako, A., Burduk, A., Karyono, K., Chen, X.,
Internal security attacks on SCADA systems. In 2013 Wyczółkowski, R. (eds) Advances in Manufacturing
Third International Conference on Communications and Processes, Intelligent Methods and Systems in
Information Technology (ICCIT), Beirut, Lebanon, pp. Production Engineering. GCMM 2021. Lecture Notes in
22-27. Networks and Systems, vol 335. Springer, Cham.
[Link] [Link]
[50] Valasek, C., Miller, C. (2014). Adventures in automotive [64] Khadem, M.M.R.K., Piya, S., Shamsuzzoha, A. (2018).
networks and control units. Technical White Paper, Quantitative risk management in gas injection project: A
IOActive. case study from Oman oil and gas industry. Journal of
[51] Nelson, T., Chaffin, M. (2011). Common cybersecurity Industrial Engineering International, 14: 637-654.
vulnerabilities in industrial control systems. Control [Link]
Systems Security Program. [65] Zand, E.D. (2009). Risk analysis in oil and gas projects:
[52] Slowik, J. (2019). Evolution of ICS attacks and the A case study in the Middle East. Doctoral dissertation,
prospects for future disruptive events. Threat Intelligence Massachusetts Institute of Technology.
Centre Dragos Inc. [66] Lavasani, S.M., Ramzali, N., Sabzalipour, F., Akyuz, E.
[53] Khorrami, F., Krishnamurthy, P., Karri, R. (2016). (2015). Utilisation of Fuzzy Fault Tree Analysis (FFTA)
Cybersecurity for control systems: A process-aware for quantified risk analysis of leakage in abandoned oil
perspective. IEEE Design & Test, 33(5): 75-83. and natural-gas wells. Ocean Engineering, 108: 729-737.
[Link] [Link]
[54] Rajput, P.H.N., Rajput, P., Sazos, M., Maniatakos, M. [67] Fetisov, V., Gonopolsky, A.M., Davardoost, H.,
(2019). Process-aware cyberattacks for thermal Ghanbari, A.R., Mohammadi, A.H. (2023). Regulation
desalination plants. In Proceedings of the 2019 ACM and impact of VOC and CO2 emissions on low‐carbon
Asia Conference on Computer and Communications energy systems resilient to climate change: A case study
Security, pp. 441-452. on an environmental issue in the oil and gas industry.
[Link] Energy Science & Engineering, 11(4): 1516-1535.
[55] Wang, C., Fang, L., Dai, Y. (2010). A simulation [Link]
environment for SCADA security analysis and [68] Gosnadzor (2023). Official site of the Gosnadzor.
assessment. In 2010 International Conference on Available online at [Link] accessed
Measuring Technology and Mechatronics Automation, on February 10, 2023.
Changsha, China, pp. 342-347. [69] E2-69- Barometer, A.R. (2023). Identifying the major
[Link] business risks for 2023. [Link] agcs. allianz.
[56] Oman, P., Phillips, M. (2008). Intrusion detection and com/content/dam/onemarketing/agcs/agcs/reports/Allia
event monitoring in SCADA networks. In: Goetz, E., [Link].
Shenoi, S. (eds) Critical Infrastructure Protection. ICCIP [70] Balogun, T.G., Andaila, A.M. (2012). Development and
2007. IFIP International Federation for Information implementation of a health safety and environmental
Processing, vol 253. Springer, Boston, MA. management system in the Qatar petroleum drilling
[Link] department. In SPE International Production and
[57] Pidikiti, D.S., Kalluri, R., Kumar, R.K.S., Operations Conference & Exhibition, Doha, Qatar.
Bindhumadhava, B.S. (2013). SCADA communication [Link]
protocols: vulnerabilities, attacks and possible [71] Kholidy, H. A. (2021). Autonomous mitigation of cyber
mitigations. CSIT, 1: 135-141. risks in the Cyber–Physical Systems. Future Generation
[Link] Computer Systems, 115(10): 171-187.
[58] Giani, A., Karsai, G., Roosta, T., Shah, A., Sinopoli, B., [Link]
Wiley, J. (2008). A testbed for secure and robust SCADA [72] Krotofil, M., Gollmann, D. (2013). Industrial control
systems. ACM SIGBED Review, 5(2): 1-4. systems security: What is happening? 2013 11th IEEE
[Link] International Conference on Industrial Informatics
[59] Ciepiela, P. (2016). Digitization and Cyber Disruption in (INDIN), Bochum, Germany, pp. 670-675.
Oil and Gas. [Link]
[60] Johansson, E., Sommestad, T., Ekstedt, M. (2008). [73] Chen, X., Zhou, Y., Zhou, H., Wan, C., Zhu, Q., Li, W.,
Security issues for SCADA systems within power Hu, S. (2016). Analysis of production data manipulation
distribution. [Link] attacks in petroleum cyber-physical systems. 2016
[Link]/smash/get/diva2:495747/[Link]. IEEE/ACM International Conference on Computer-
[61] Force, J.T., Initiative, T. (2013). Security and privacy Aided Design (ICCAD), Austin, TX, pp. 1-7.
controls for federal information systems and [Link]
organizations. NIST Special Publication, 800(53): 8-13. [74] Marzooq, A.A., Rashid, H.A. (2023). The impact of
112
safety priorities on the economic management of projects: [76] Oudina, Z., Derdour, M, Dib, A., Aouidate, A.A. (2023).
A review. International Journal of Safety & Security Model based system engineering for trust SCADA and
Engineering, 13(1): 21-29. ICS systems in oil & gas industry. 2023 5th International
[Link] Conference on Pattern Analysis and Intelligent Systems
[75] Catelani, M., Ciani, L., Luongo, V. (2013). Safety (PAIS), Sétif, Algeria, pp. 1-8.
analysis in oil & gas industry in compliance with [Link]
standards IEC61508 and IEC61511: Methods and [77] Oudina, Z., Derdour, M. (2023). Toward modeling trust
applications. In 2013 IEEE International Instrumentation cyber-physical systems: A model-based system
and Measurement Technology Conference (I2MTC), engineering method. International Journal of Advanced
Minneapolis, MN, USA, pp. 686-690. Computer Science and Applications, 14(7): 441-452.
[Link]
113
The current cybersecurity vulnerabilities in industrial control systems expose the oil and gas sector to significant risks, including unauthorized access and operational disruptions, which can lead to severe impacts on safety, business continuity, and production. The sector's interconnected IT and OT systems make it particularly susceptible to cyber attacks, emphasizing the need for robust security measures that don't compromise functional safety .
Unauthorized access can lead to data breaches, operational disruptions, and compromising of critical infrastructure in cyber-physical systems. To mitigate this issue, strategic measures such as access rules, enhanced authentication methods, and strong perimeter defenses like firewalls and IDS are suggested to protect essential systems from unauthorized intrusions .
Integration of smart technological industry components into the oil and gas sector enhances risk management by improving real-time monitoring, enhancing data analytics, and providing better situational awareness. However, it also introduces new cyber-physical system risks that need to be managed through comprehensive risk classification and mitigation strategies, focusing on both cyber and physical security aspects .
The risk classification aims to systematically identify, document, and categorize various risks that threaten the oil and gas industry's operational infrastructure, such as natural disasters, cyber threats, and operational incidents. It distinguishes between internal and external risks and emphasizes the importance of the cyber-physical system as a vital component, categorizing hazards as physical, cyber, or related to permissibility and authorization . This classification aids in organizing and analyzing risks and helps to tailor mitigation strategies accordingly .
Workers in the oil and gas industry face several health and safety risks, including vehicle incidents, accidents involving machinery, explosions, fires, and chemical exposure. The sector addresses these challenges by implementing Health, Safety, and Environment (HSE) protocols, conducting regular training and safety drills, and adhering to safety standards to minimize workplace hazards and ensure the well-being of workers .
The case study highlights the importance of a comprehensive risk classification framework that identifies potential threats specific to the oil and gas industry. It categorizes risks into cyber, physical, and authorization threats, emphasizing the significance of recognizing these elements for effective management and mitigation of potential operational disruptions and cyber attacks .
Strategic challenges include ensuring cybersecurity measures do not impede functional safety, requiring coordination among stakeholders, and continuously reviewing standards for integration and consistency. These challenges can be addressed by conducting holistic lifecycle reviews, enhancing collaboration, and ongoing monitoring and adaptation of standards to align with technological advancements and threat landscapes .
The multifaceted security approach enhances cybersecurity by securing critical infrastructure, preventing cyber threats, and ensuring operational continuity in oil and gas zones. Its main components include reconfiguring existing infrastructure, integrating industrial firewalls for network segmentation and protection, and complying with industry standards to effectively manage evolving threats .
The oil and gas industry faces significant challenges in securing SCADA systems due to their reliance on interconnected IT and OT systems, which are vulnerable to cyber threats. The proposed approach to mitigate these risks is a multifaceted security strategy that includes reconfiguring and assessing infrastructure, integrating new-generation industrial firewalls into SCADA and ICS systems for network segmentation, and strengthening compliance with oil and gas standards to manage evolving threats .
The taxonomy categorizes various cybersecurity threats specific to wireless sensor networks in the oil and gas industries, focusing on their vulnerability to unauthorized access and data interception. Suggested measures to counter these threats include implementing robust encryption, regular security assessments, and adopting cybersecurity standards that ensure data integrity and confidentiality .