ics security from the plant floor up - a controls engineers approach to securing plant floor...

38
1 ICS Security from the Plant Floor Up A Controls Engineers Approach to Securing Plant Floor Networks Jeffrey Smith

Upload: digital-bond

Post on 09-Jun-2015

318 views

Category:

Technology


0 download

DESCRIPTION

The presentation covers assessment, implementation methodology, and current level of success for addressing four key objectives which are protecting the controls fieldbus (networks) from untrusted networks (domain), secure and safe remote support capability from both inside and outside of the company, control supplier access to manufacturing equipment when onsite, and protect manufacturing systems from Malware and intrusion. This system isn’t theoretical, it’s in broad use and full critical production. If the time and connectivity is available a quick remote access demonstration can be given. The presentation will wrap up with a series of thoughts and ideas that occur to me regarding security in general as I listen to other organizations and groups talking about various security needs and activities.

TRANSCRIPT

Page 1: ICS Security from the Plant Floor Up - A Controls Engineers Approach to Securing Plant Floor Network, Jeffrey Smith of AAM

1

ICS Security from the Plant Floor Up

A Controls Engineers Approach to Securing Plant Floor Networks

Jeffrey Smith

Page 2: ICS Security from the Plant Floor Up - A Controls Engineers Approach to Securing Plant Floor Network, Jeffrey Smith of AAM

2

Less than a minute of blather about

Jeffrey Smith

Page 3: ICS Security from the Plant Floor Up - A Controls Engineers Approach to Securing Plant Floor Network, Jeffrey Smith of AAM

3

Nothing. Zero. Nada. Zip.

How much do I want to spend?

Page 4: ICS Security from the Plant Floor Up - A Controls Engineers Approach to Securing Plant Floor Network, Jeffrey Smith of AAM

4

ICS Security

1. Assess our current posture

2. Define key objectives for which to develop a solution to improve that posture.

Page 5: ICS Security from the Plant Floor Up - A Controls Engineers Approach to Securing Plant Floor Network, Jeffrey Smith of AAM

5

Key Objective #1

Protect the manufacturing controls networks (EtherNet/IP fieldbus) from the

enterprise networks (untrusted networks)

and they from us.

Page 6: ICS Security from the Plant Floor Up - A Controls Engineers Approach to Securing Plant Floor Network, Jeffrey Smith of AAM

6

Key Objective #1

Isolate the Controls Fieldbus from the Enterprise network through two different Firewalls, one managed by IT, one by Controls.

EtherNet/IP Fieldbus

IT Firewall

Zenwall-5Controls FirewallIndustrial Protocol DPI

IT SPACE

CONTROLS

Page 7: ICS Security from the Plant Floor Up - A Controls Engineers Approach to Securing Plant Floor Network, Jeffrey Smith of AAM

Key Objective #2

Secure and Safe Remote Support Capability from inside and outside the company

7

Page 8: ICS Security from the Plant Floor Up - A Controls Engineers Approach to Securing Plant Floor Network, Jeffrey Smith of AAM

8

Key Objective #3

Control and track supplier access to Manufacturing Control Systems when onsite in one of our facilities

Page 9: ICS Security from the Plant Floor Up - A Controls Engineers Approach to Securing Plant Floor Network, Jeffrey Smith of AAM

9

Supplier Support Login

Page 10: ICS Security from the Plant Floor Up - A Controls Engineers Approach to Securing Plant Floor Network, Jeffrey Smith of AAM

10

Key Objective #4

Protect manufacturing systems from malware attack by removing PC(s) from or isolating them on the controls network.

Whitelist where applicable.

Page 11: ICS Security from the Plant Floor Up - A Controls Engineers Approach to Securing Plant Floor Network, Jeffrey Smith of AAM

11

Say NO to PCs on your Fieldbus

Friends don’t let friends put PC(s) on Controls Networks

Computer

Page 12: ICS Security from the Plant Floor Up - A Controls Engineers Approach to Securing Plant Floor Network, Jeffrey Smith of AAM

12

Move the PCs to the EnterpriseENTERPRISE NETWORK

Page 13: ICS Security from the Plant Floor Up - A Controls Engineers Approach to Securing Plant Floor Network, Jeffrey Smith of AAM

13

Line Topology

Page 14: ICS Security from the Plant Floor Up - A Controls Engineers Approach to Securing Plant Floor Network, Jeffrey Smith of AAM

14

Station Topology

PanelView PlusCompactLogix L3x ERM

Kinetix 6500 Servos

EtherNet/IP – Device Level Ring (DLR)

PowerFLEX 755 VFD

OP90

E-TAP

Torque Tool

HMS Gateway

OptionalE-TAP173x AENT

Numatics G3

EtherNet/IP Ring Link

OP100 OP80

UPLINK #2TO MACH 102

STATION DEVICE LEVEL RING (DLR) TOPOLOGY

EtherNet/IP Ring Link

Page 15: ICS Security from the Plant Floor Up - A Controls Engineers Approach to Securing Plant Floor Network, Jeffrey Smith of AAM

15

PC at the Edge…If you must.

Page 16: ICS Security from the Plant Floor Up - A Controls Engineers Approach to Securing Plant Floor Network, Jeffrey Smith of AAM

16

Page 17: ICS Security from the Plant Floor Up - A Controls Engineers Approach to Securing Plant Floor Network, Jeffrey Smith of AAM

17

“Deep thoughts” by Jeff Smith

Page 18: ICS Security from the Plant Floor Up - A Controls Engineers Approach to Securing Plant Floor Network, Jeffrey Smith of AAM

18

10 Ton Security Model

DMZ!

ACL!

DPI

Page 19: ICS Security from the Plant Floor Up - A Controls Engineers Approach to Securing Plant Floor Network, Jeffrey Smith of AAM

19

Assessment is Critical

We don’t build rockets…you might.

Page 20: ICS Security from the Plant Floor Up - A Controls Engineers Approach to Securing Plant Floor Network, Jeffrey Smith of AAM

20

Ethernet based Fieldbus

Is still young, it has long way to grow and it’s a long way from mature when

compared to it’s IT counterpart.

Page 21: ICS Security from the Plant Floor Up - A Controls Engineers Approach to Securing Plant Floor Network, Jeffrey Smith of AAM

21

Can we move to Ethernet?

•Many companies, small to large, are just looking at making a move to an Ethernet based fieldbus.

•What’s the value proposition of Ethernet if we are pushing a huge security posture on them at the same time?

Page 22: ICS Security from the Plant Floor Up - A Controls Engineers Approach to Securing Plant Floor Network, Jeffrey Smith of AAM

22

Controls Engineers

•Many don’t have experience with Ethernet based controls networks.

•Companies are tight with training dollars, more are forcing their support staff to learn via OJT even though technology growth is raging.

Page 23: ICS Security from the Plant Floor Up - A Controls Engineers Approach to Securing Plant Floor Network, Jeffrey Smith of AAM

23

Migrating the “Ethernetly” Challenged

Are you helping? What does your “Convert Legacy Fieldbus X to an

Ethernet fieldbus” Engineering Plan look like?

Page 24: ICS Security from the Plant Floor Up - A Controls Engineers Approach to Securing Plant Floor Network, Jeffrey Smith of AAM

24

Shore up the foundation

Perhaps for those who have taken a “swag” at Ethernet based fieldbus, the

correct approach to TLC is to help them “fix” their strategy for Control System Ethernet and then help them

secure it.

TLC = Total Landed Cost

Page 25: ICS Security from the Plant Floor Up - A Controls Engineers Approach to Securing Plant Floor Network, Jeffrey Smith of AAM

25

Air Gapped?

Is there *REALLY* such a thing?

Page 26: ICS Security from the Plant Floor Up - A Controls Engineers Approach to Securing Plant Floor Network, Jeffrey Smith of AAM

26

Pssst! We can do Controls Stuff…

When talking about security, let’s capitalize on our seemingly forgotten skillset of hardwired safety/security.

Might not be a singular product purchased from a shelf, but it is value

controls can bring to the table.

It’s our cockpit door.

Page 27: ICS Security from the Plant Floor Up - A Controls Engineers Approach to Securing Plant Floor Network, Jeffrey Smith of AAM

27

If we had a little money left…

“Replace all unmanaged switches with managed switches.”

Page 28: ICS Security from the Plant Floor Up - A Controls Engineers Approach to Securing Plant Floor Network, Jeffrey Smith of AAM

28

How to get started?

Do something, a little today, and more tomorrow.

Eat the elephant one bite at a time.

Page 29: ICS Security from the Plant Floor Up - A Controls Engineers Approach to Securing Plant Floor Network, Jeffrey Smith of AAM

29

Not enough people talking about Detection and Fast Recovery.

If we agree we will never stop every attack, shouldn’t we spend time on detection and

recovery?

Detection and Recovery

Page 30: ICS Security from the Plant Floor Up - A Controls Engineers Approach to Securing Plant Floor Network, Jeffrey Smith of AAM

30

This year, the first production vehicle will be released that uses Ethernet instead of CAN as it’s primary vehicle communications network.

Nervous? I am.

Ethernet in Automobiles

Page 31: ICS Security from the Plant Floor Up - A Controls Engineers Approach to Securing Plant Floor Network, Jeffrey Smith of AAM

31

Forensic Diagnostics

Diagnostics

Page 32: ICS Security from the Plant Floor Up - A Controls Engineers Approach to Securing Plant Floor Network, Jeffrey Smith of AAM

32

What do I look for?

ICS Security Appliance

Page 33: ICS Security from the Plant Floor Up - A Controls Engineers Approach to Securing Plant Floor Network, Jeffrey Smith of AAM

33

Controls Security Appliance

•Fast, Low Latency Deep Packet Inspection of Industrial Protocols

•Ability to easily configure and manage firewall rules without needing a degree in “firewall”

•Horsepower to spare, with the ability to lay in changes without interrupting performance.

Page 34: ICS Security from the Plant Floor Up - A Controls Engineers Approach to Securing Plant Floor Network, Jeffrey Smith of AAM

34

ICS Security Appliances

•Can’t require an IT person at 2:00am when the line is down.

•Best way to introduce yourself and your new wiz-bang security “stuff” to the plant manager is to take the line down OR prevent the 2:00am support staff from bringing it back up.

Page 35: ICS Security from the Plant Floor Up - A Controls Engineers Approach to Securing Plant Floor Network, Jeffrey Smith of AAM

35

ICS Security Appliances

You won’t forget him and he won’t forget you or your security #%^!&%#*%.

And you thought CapEx funding of security initiatives was challenging before.…

Page 36: ICS Security from the Plant Floor Up - A Controls Engineers Approach to Securing Plant Floor Network, Jeffrey Smith of AAM

36

ICS Security Appliances

•Must have easily replicatable configurations

•Must be scalable from small to large

•Must have reasonable pricing models to accompany their scalability

Page 37: ICS Security from the Plant Floor Up - A Controls Engineers Approach to Securing Plant Floor Network, Jeffrey Smith of AAM

37

Security = Risk Mitigation

I’m often asked “How much security is enough?”

“Whatever you need to mitigate the risk you can’t live with.”

Page 38: ICS Security from the Plant Floor Up - A Controls Engineers Approach to Securing Plant Floor Network, Jeffrey Smith of AAM

38

I can make up answers to any…

Questions?