More than you might think.
In terms of the vulnerability of your physical supply chain, attacks on both a French canal and Iran’s nuclear program contain lessons, and they have largely to do with the way physical assets are monitored in an automated way.
Saurabh Amin, an assistant professor of civil and environmental engineering at MIT, described at MIT’s Center for Transportation & Logistics Crossroads symposium in March how he was able to breach the monitoring system of a set of rural canals in France meant to provide irrigation water to farmers.
Amin said he not only hacked into the canal’s monitoring system, opening the gates to release water, he also fed false data into the system so the person monitoring the canals had no idea whether the disruption was due to an attack or a random fluctuation in water level (which is okay).
The breach was meant to test the capability of the monitoring system, and whether other large physical networks were similarly at risk. That’s where Iran’s nuclear program comes in.
You might recall the name Stuxnet. If not, cast your mind back to mid-2010. That’s when a virus eventually dubbed Stuxnet was discovered to be invading specific systems called programmable logic controllers.
PLCs are ubiquitous in modern society, regulating our day-to-day lives in quiet, hardly discernable, but crucially important ways. Such as regulating the gates on a set of rural locks. Or urban power grids. Or the centrifuges designed to create nuclear material.
Stuxnet, it has been theorized, was developed by a nation state specifically to disrupt Iran’s nuclear program by targeting centrifuge production. But it was quickly understood that the worm could theoretically target any PLC or supervision control and data acquisition (SCADA) system since it attacked via Windows and then sought out a relatively common industrial management platform.
Breaching a monitoring system provides a bloodless means to attack a system. Especially if the attack is supported by false data being introduced into the system to make those monitoring it believe everything is absolutely normal.
We’ve all seen the caper movies where a video of normal elevator security cameras is patched over the real security cameras—this is the high-tech, menacing version of that.
Think of this concept as a counterpoint to last month’s column, where we talked about the integrity of data-sharing among supply chain partners. This is about relying too heavily on the abstract idea of remote monitoring of critical physical systems.
I’m certainly not suggesting we move backward in time and progress and abandon such systems. What I am suggesting is that shippers, carriers, and managers of physical assets (re: computers, trucks, distribution centers, container terminals, etc.) not merely rely on a monitoring system. That’s a recipe for complacency.
I’ll try to do Amin’s message justice here, but he essentially argued that IT has introduced vulnerabilities into transportation and logistics networks. He also argued that private entities cannot merely rely on public agencies to protect and monitor critical infrastructure upon which transportation networks rely.
“Private entities have a difficult time making the business case to invest in security,” Amin conceded.
Indeed, there has to be an incentive to properly monitor things. Which reminds me of a colleague I knew early in my career as a newspaper reporter. This colleague’s job was to edit all the copy that came his way for a relatively small newspaper. After a few weeks on the job, he began to realize a simple fact: no one noticed if he edited every word that came across his computer, or not a single word.
As he put it: “I edit everything, I get paid the same amount as if I edit nothing.”
When the motivation to monitor is so low, the result will be vulnerability. My former colleague had no way of knowing if an insidious reporter planted false information or a series of expletives in a story. He merely relied on those reporters to properly do their job.
Using monitoring systems in such a way is based on the same theory. No one will attempt to breach my transportation or distribution network because everyone is honorable and no one has bad intentions.
Of course that’s not true. There are small-scale threats—like cargo theft at a distribution center—and large-scale ones—an attack on a large piece of public infrastructure.
Amin said public and private entities alike should think together about the threats that are most important to control.
“It’s more critical to control the high-intensity, low-frequency incidents than the low-intensity, high-frequency ones,” he said. “What might result from a very bad event is a situation where everybody is worse off.”
This suggests that a company that invests in security benefits the whole, not just that individual company.
“There needs to be a quantification of that ‘externality,’” Amin said. “Most companies think of infrastructure security as someone else’s problem.”
Amin’s research finds that thinking to be incorrect and outdated. Indeed, the protection of physical infrastructure, both public and private, should be considered part of an entire framework that is exposed to vulnerabilities.
Relying solely on monitoring technology exposes parts of that framework, as canals and centrifuges show. Just think of your network of assets, and how you monitor those assets. Then remember that the protection of those physical assets benefits not just your company, but all.
This column was published in the May 2015 issue of American Shipper.
Brokerage Compliance Symposium
The day before F3. Every compliance issue you face - fraud exposure, carrier liability, FMCSA rules, cargo theft, insurance gaps - navigated by attorneys and operators defining best practices in a changing industry.
F3 Awards Dinner
The night before F3. FreightTech100 companies honored. FreightTech 25 and Shipper of Choice winners revealed live. Cocktail reception into dinner and live music - 300 industry leaders in one purpose-built room.
F3: Future of Freight Festival
Industry-defining keynotes, rapid-fire technology demos, and industry leaders networking in experiences across Chattanooga - plus the inaugural F3 Awards Dinner featuring the FreightTech and Shipper of Choice reveals.
The day before F3. Every compliance issue you face - fraud exposure, carrier liability, FMCSA rules, cargo theft, insurance gaps - navigated by attorneys and operators defining best practices in a changing industry.
The Signal at Chattanooga Choo Choo • Chattanooga, TN Register NowThe night before F3. FreightTech100 companies honored. FreightTech 25 and Shipper of Choice winners revealed live. Cocktail reception into dinner and live music - 300 industry leaders in one purpose-built room.
The Signal at Chattanooga Choo Choo • Chattanooga, TN Register NowIndustry-defining keynotes, rapid-fire technology demos, and industry leaders networking in experiences across Chattanooga - plus the inaugural F3 Awards Dinner featuring the FreightTech and Shipper of Choice reveals.
The Signal at Chattanooga Choo Choo • Chattanooga, TN Register Now