再評估營運可視性 / 15 分鐘

ICS 事件裡:看不到、沒告警、沒有紀錄是三種問題

操作畫面失去可信狀態、告警沒有出現,以及事後缺少紀錄,可能同時發生,也可能彼此無關。本文說明三者的差異與應對方式。

在 ICS 環境裡,「操作員看不到」、「告警沒有出現」與「事後沒有可用紀錄」可能同時發生,也可能彼此無關。三者都會影響判斷,卻不是同一種故障:畫面失去可信狀態,不代表所有告警都被關閉;告警路徑被抑制,也不代表其他製程數值一定不可見;事後紀錄不足,更不能直接證明事件發生時 HMI 已經失效。

本文把內容分成三層。已知事件事實只重述來源機構記錄的時間、資產、動作與結果;來源建議只整理文件提出的防護做法;編輯推論才討論集中式日誌、資料鏡像與單向遙測釋出的有限用途。三者不能互相代替,也不會補上來源未確認的歸因、告警狀態、技術能力、影響範圍或事件結果。

核心結論

營運可視性是一條完整的觀察路徑,從來源狀態、感測器/控制器、告警邏輯、HMI、紀錄、傳輸一路到目的端分析。「看不到」關心操作員能否取得足以判斷目前製程的可信畫面;「告警被抑制」關心應出現的告警是否在途中被停用、攔截、改變或隱藏;「紀錄/遙測可用性」則關心預定用途需要的資料是否存在、被保留、可取得、可解析,而且帶有足以判讀的時間與來源。

集中分析可以把已取得的多個資料來源放在一起;資料鏡像可以在另一個安全域建立選定資料的副本;硬體強制單向釋出則可以固定特定跨域路徑的資訊流方向。它們各自改善觀察路徑的一部分,但都無法補回來源端不存在、未產生、已被抑制或已遭改變的證據。

三個概念與界線

下列是本文為架構評估採用的操作定義,不是把某一份來源改寫成普遍事件結論。

看不到|目前操作畫面無法取得或不可信

「看不到」是指操作員無法取得、更新或合理信賴完成目前判斷所需的製程狀態、控制狀態與相關脈絡。原因可能是 HMI 存取中斷、畫面或資料被操弄、採集停止、傳輸失效、資料過期或顯示端故障。這只描述觀察條件,不代表實體製程已停止、控制已遺失、攻擊歸因已成立,或所有遙測都不可用。

Operational consequence 是 operator 可能無法區分正常、降級與危險狀態,因而延後確認、切換到替代畫面或 manual operation,或在資料可信度未釐清前限制操作。具體後果取決於被遮蔽的變數、持續時間、safety design、現場指示與既有程序,不能由「loss of view」四個字推定實體損害。

告警被抑制|應出現的告警沒有成為可行動訊號

「告警被抑制」是指應觸發告警的來源狀態或事件已經存在,但在產生、傳遞、分類、顯示或通知途中被停用、阻擋、改變或隱藏,導致操作員沒有收到原本應可採取行動的訊號。原因可能是惡意操作、設定錯誤、維護狀態或其他故障;只看到「沒有告警」,不足以判定原因。

Alarm suppression 比 loss of view 窄。Operator 可能仍看到部分 process values,卻失去預期的優先提示;反過來,HMI 整體不可用時,即使 source alarm logic 仍在運作,operator 也可能無法看到結果。Operational consequence 是異常條件可能較晚被注意、確認或升級,但事件是否真的造成 safety 或 process impact,仍要回到 source condition、其他 indicators 與事件紀錄。

紀錄/遙測可用性|用途需要的證據是否可用

紀錄/遙測可用性不等於「系統有開日誌」。評估時至少要問:需要的來源是否產生紀錄?採集是否涵蓋該來源?資料是否被保留?傳輸與接收是否成功?目的端能否解析?時間、來源與狀態資訊是否足以支援監控、應變或調查?

Operational consequence 依用途而不同。即時 monitoring 的資料過期可能讓 current state 判斷失真;incident response 缺少 authentication、configuration 或 network evidence,可能無法確認 activity path 或建立可靠 timeline;retention 太短則可能在事件被發現前覆寫重要資料。Availability 仍不等於 evidence completeness、source integrity 或正確 interpretation。

三種問題會帶來什麼後果

問題 直接受影響的判斷 可能的營運後果 不能直接推定
看不到 目前製程/控制狀態是否可見且可信 操作員可能要改用現場指示、替代畫面或手動操作;確認與決策可能延後 製程已停止、控制已遺失、攻擊已確認
告警被抑制 應觸發告警的狀態是否形成可行動提示 異常可能較晚被注意、確認或升級;告警流程的可信度需要另行查核 所有畫面都失效、所有告警都被抑制、一定造成實體結果
紀錄/遙測不可用 監控或調查所需證據是否存在且可用 偵測、範圍判定、時間線、復原驗證或交接可能受限 當時 HMI 一定失效、沒有事件發生、已取得其餘全部證據

來源事實|已知事件與可用證據的限制

2024 年 5 月聯合 fact sheet 把觀察範圍限定在自 2022 年至 2024 年 4 月、北美與歐洲的部分小型 OT systems。文件記錄,2024 年初 CISA 與 FBI 回應數個美國 Water and Wastewater Systems victims;未授權使用者遠端操弄 HMIs,使 water pumps 與 blower equipment 超出正常 operating parameters,並在每一個所述案例中把 setpoints 調到上限、改變其他 settings、關閉 alarm mechanisms,及修改 administrative passwords 以鎖住 operators。查閱 2024 聯合 fact sheet 的事件範圍

同一來源依 victim incident reporting 將 activity 的 operation disruption 描述為有限,並記錄部分 victims 出現 minor tank overflow events;多數 victims 隨後改用 manual controls 並迅速恢復 operation。這些結果只屬於該 fact sheet 所述事件集合。來源沒有確認所有 alarms、所有 HMIs、每個 WWS facility 或其他 sector 都呈現相同狀態;本文也不把「alarm mechanisms 被關閉」擴張為來源已確認完整 loss of view。查閱來源記錄的 operational consequences

ICS-CERT 的 2009–2011 incident-response summary 記錄另一種 visibility limitation。在一個 critical manufacturing organization 的 enterprise network intrusion 中,ICS-CERT 認為 data exfiltration 可疑,但因 available logging 不足而無法確認;同一段明確說 control processes 與 operations 未受影響。這個結果不能被改寫成已確認 exfiltration,也不能套用到其他事件。查閱 ICS-CERT onsite response summary

該報告對 17 次 onsite responses 的 common findings 進一步指出,許多 organizations 沒有啟用足夠 logging capabilities,無法提供有價值的 log data 供分析;有些 forensic images 在事件後很久才建立,重要 timestamps 已被覆寫,因而無法建立 reliable timeline。這是 2009–2011 response activities 的彙整,不是所有 ICS incidents 的普遍比例或目前環境狀態。查閱 ICS-CERT 的 logging 與 timeline findings

來源建議|依事件條件選擇防護做法

2024 聯合 fact sheet 的 mitigations 對應它觀察到的 internet-exposed HMIs、remote access、default/weak passwords 與缺少 multifactor authentication。Authoring organizations 建議把 HMIs 與 PLCs 從 public-facing internet 斷開;若 remote access 確有需要,則以 firewall 或 VPN、strong password 與 multifactor authentication 控制 access,並限制 remote logins、盤點 systems、建立防護性 network monitoring 與備份設定。查閱 fact sheet 的 defender mitigations

AA21-287A 要求 Water and Wastewater Systems 對 remote access 啟用 logging 並定期 audit,採用 network segmentation,並讓 emergency response plan 納入 loss or manipulation of view、loss or manipulation of control 與 safety threats。文件也建議演練 degraded electronic communications 下的 alternate controls 與 manual operation。這是 2021 年聯合 advisory 對該 sector 的 planning and operational guidance,不是來源機構對 2024 fact sheet 事件結果的補述。查閱 AA21-287A 的 planning 與 logging guidance

NIST SP 1800-7B 的 electric-utility reference design 把 operations-side logs 先保存在 local log collector/aggregator,再複製到 enterprise,並由 SIEM 集中 review 與 correlation。文件同時要求監測 sensor liveness、expected updates、intermediate collectors、資料 integrity 與缺漏;它明確提醒,若資料不是直接送到 SIEM,intermediate system 也必須參與辨識 source failure。查閱 NIST 的 collection、replication 與 liveness guidance

同一份 NIST guide 說明一個重要限制:在其 one-way transfer 設計中,enterprise SIEM 不能沿該路徑 ping operations-side sensors;若 communication network failure,SIEM 也可能無法直接知道已失去 source connection,in-transit log data 可能被丟棄。Reference design 因此另行使用 local storage、heartbeats、integrity checks 與 gap detection。文件甚至指出,沒有保證每一筆 dropped information 都會被偵測。查閱 NIST 的 SIEM data verification 與 one-way limitation

編輯推論|三種資料做法各自改善一部分

從上述事件與來源建議,可以得到一項有限結論:集中式日誌、資料鏡像與硬體強制單向遙測釋出,都可能改善觀察路徑的一部分。使用任何一種做法,都要寫清楚資料來源、資料類別、更新方式、失效指標、保存期限、目的端用途與不涵蓋範圍。

集中式日誌可以把已收集的身份驗證、設定、網路、應用程式或製程事件放在同一處,支援跨來源檢視、關聯與保存。它只能集中實際產生並送達收集端的紀錄,無法處理來源端日誌故障、根本沒有產生的事件、已被抑制的事件、既有入侵對來源證據的影響,或採集規則漏掉的活動。集中位置本身也需要存取控制、完整性保護、健康監控與保存治理。

資料鏡像可以在另一個安全域建立選定狀態、historian 資料、告警事件或日誌的副本,不必沿用原始雙向連線。鏡像顯示的是它實際收到並重建的資料;如果來源數值遭到操弄、告警沒有產生、採集已停止、格式被誤解或資料已過期,目的端結果也可能不完整或不可信。因此,畫面要顯示來源時間、接收時間、過期狀態、順序/缺口與重建錯誤,而不是只顯示最後一筆值。

硬體強制單向遙測釋出只能改變特定跨域路徑的可達性與資料流方向:資料只朝分析環境移動,目的端無法沿同一通道向來源端建立回程流量。但這不代表遙測必達或不會遺失,也不保證告警一定產生,或目的端一定知道來源收集器是否仍正常。NIST 參考設計對連線中斷察覺與傳輸途中掉資料的限制,正說明方向控制仍需要來源端緩衝、存活檢查、完整性與缺口處理。查閱 NIST 的限定條件

因此,三種做法都不能保證取得完整的鑑識紀錄,也不能發現所有活動、防止攻擊、保證告警完整或操作員可視性、清除既有入侵,或保護整個環境。來源沒有產生或已在來源端被抑制的證據,也無法事後補造。適用性結論只能落在已明確設計與驗證的遙測路徑、網路可達性或資料流條件。

評估清單

  1. 為每個 operational decision 列出必要 process values、control state、alarms、logs 與現場 indicators,不先假設單一 HMI 或 SIEM 足以涵蓋全部。
  2. 分開測試 HMI unavailable、stale data、alarm mechanism disabled、source logging stopped、collector full、transfer interrupted 與 destination ingestion failed。
  3. 為每筆資料保留 source identity、event time、collection time、receive time、schema/version,以及可辨識的 stale、gap 與 parse failure state。
  4. 確認 alarm-worthy condition、alarm event generation、alarm transmission、presentation 與 operator acknowledgement 各自有何 evidence。
  5. 對集中式 log 定義 events of interest、retention、access control、time synchronization、integrity、collector health 與 investigation export 程序。
  6. 對 data mirror 記錄它只包含哪些 data classes,以及 source-side missing、suppressed、manipulated 或 stale data 如何在 destination 顯示。
  7. 對 one-way release 分別驗證硬體方向、source buffering、destination reconstruction、liveness indication、loss tolerance 與 gap handling。
  8. 演練 loss/manipulation of view 與 degraded communications 下的 alternate display、manual operation、safety coordination、incident response 與 recovery。
  9. 將其他 ingress、remote access、removable media、identity abuse、insider activity、source-side compromise 與 physical failure 留在 residual risk。

閱讀限制

本文是產品中立的技術與事件研究,不是對任何現場完成的告警合理化、事件重建、失陷評估、安全分析或架構核准。事件事實與來源建議只適用於各文件記錄的時間、資產、產業與觀察範圍;編輯推論只界定特定遙測路徑、網路可達性與資料流。引用 CISA、FBI、NSA、EPA、其他合作機構、DHS 或 NIST,不表示它們為本文推論、任何產品、任何部署、任何架構或安全結論提供背書、驗證或認證。

Source record

Primary sources

  1. 01

    Defending OT Operations Against Ongoing Pro-Russia Hacktivist Activity

    Cybersecurity and Infrastructure Security Agency; Federal Bureau of Investigation; National Security Agency; Environmental Protection Agency; Department of Energy; United States Department of Agriculture; Food and Drug Administration; Multi-State Information Sharing and Analysis Center; Canadian Centre for Cyber Security; United Kingdom National Cyber Security Centre / Cybersecurity and Infrastructure Security Agency

    Published
    2024-05-01
    Accessed
    2026-07-19
    Location
    Overview; Overview of Threat Actor Activity; 2024 Year-to-Date Activity; Remote Access to HMIs; Mitigations
    Source class
    authoritative primary source
    Required
    required
  2. 02

    Ongoing Cyber Threats to U.S. Water and Wastewater Systems

    Federal Bureau of Investigation; Cybersecurity and Infrastructure Security Agency; Environmental Protection Agency; National Security Agency / Cybersecurity and Infrastructure Security Agency

    Published
    2021-10-14
    Accessed
    2026-07-19
    Location
    Observed cyber intrusions from 2019–2021; Remote Access Mitigations; Network Mitigations; Planning and Operational Mitigations
    Source class
    authoritative primary source
    Required
    required
  3. 03

    ICS-CERT Incident Response Summary Report 2009–2011

    Industrial Control Systems Cyber Emergency Response Team / United States Department of Homeland Security

    Published
    2012-06-28
    Accessed
    2026-07-19
    Location
    Section 2, Onsite Incident Response Summary; Section 3, Common Findings—Detection and Response, pages 7–14
    Source class
    authoritative primary source
    Required
    required
  4. 04

    NIST SP 1800-7B: Situational Awareness for Electric Utilities

    National Cybersecurity Center of Excellence / National Institute of Standards and Technology

    Published
    2019-08-01
    Accessed
    2026-07-19
    Location
    Volume B, Sections 4.2, 5.1.1.19, 5.2.5.2, and 5.2.5.3
    Source class
    authoritative primary source
    Required
    required