OTSecurity

Making OT Security Stronger Than IT


OT security is “hard” – engineering change control (ECC) makes patching slow and expensive, many OT devices and systems have no real support for zero trust (ZT), and most OT systems have large subsystems that operate without encrypted or authenticated communications. But imagine – imagine we could “wave a magic wand” and solve all of this, instantly. With one gesture, we patch everything, encrypt everything and ZT everything. Would we be “done?”

No. IT networks have near-universal security updates, ZT and encryption. If with a “magic wand” we could make our OT networks exactly as strong as our IT networks, then for most OT networks this would be a material improvement over the present-day, but would not be enough. From first principles, most OT networks must be materially better protected than most IT networks. The severity of worst credible consequences of cyber compromise drives the strength of security program that any network or system needs.

How Can We Make OT Stronger?

One way to make OT stronger than IT is to make OT security programs reflect OT rather than IT priorities. In most IT systems, information is the asset we protect and preventing espionage is the priority – encrypt the information and otherwise control the ability of adversaries to read the information. In most OT systems, on the other hand, physical operations are the asset, preventing sabotage is the priority, and information is the threat – the only way an OT system can change from a normal to a compromised state is if attack information enters the system, somehow. In OT it is therefore vital to control the movement of information, because all information flows can contain attacks.

How do we do that? Some examples:

  • The humble “deny by default” rule – do not allow connections through the IT/OT firewall to email servers, Google, nor the Internet at large. We cannot afford to pull attack information into OT,
  • More powerful unidirectional gateways at the IT/OT interface are hardware components that enable real-time server synchronization outbound from OT to IT, and allows no attack information at all to flow back into OT from IT, nor from the Internet, and
  • Strict procedural, software and sometimes hardware controls over the use of removable media, such as DVD’s and USB thumb drives.

In most OT networks there are less than a dozen kinds of ways that information can enter the network. Lock them down. Lock them hard.

Cyber-Informed Engineering

More generally, the emerging Cyber-Informed Engineering (CIE) discipline, among other things, points out how to use “unhackable” engineering tools to both eliminate physical risk and to deterministically control the movement of attack information. What is “unhackable?” These are tools that behave deterministically, often without any CPU built in, or a monitor-only CPU, unable to alter the behavior of the device. These engineering-grade mitigations range from electromechanical overpressure relief valves to digital hardware such as FPGA’s and ASICs.

CIE is still under development. The most recent innovation is a database of some 62,000 records. Each record describes an “unhackable” mitigation that can be applied in a particular industry. And again, of all the engineering-grade mitigations in the database, deterministic network engineering tools such as unidirectional gateways and hardware-enforced network traffic filtering are by far the most universally applicable.

Anomaly Detection

Another way to make OT networks stronger than IT is with anomaly-based monitoring and intrusion detection systems. Most industrial networks change much less frequently than do IT networks, and are used very predictably, day after day. This means that we can tune our OT-aware anomaly-based IDS systems to be more aggressive about alerting on even small changes from “normal,” without introducing unmanageable numbers of false alarms.

That said, we must be careful not to confuse the pillars of the NIST Cybersecurity Framework (NIST CSF). For example, if a new bridge is designed with hydraulic dampers to counteract harmonic frequencies, it is not enough for the design engineer to “hope” that if a cyber attack targets the control system for the dampers, “hope” that we can detect the attack before the dampers are crippled and the bridge tears itself apart. “Hope” is not what we expect of design engineers – we expect bridges that carry a specified load, in a specified operating environment, for a specified number of decades, with a large margin for error – deterministically.
We do need the CSF detect, respond and recover pillars, and it is good that we can design our OT detection tools to be stronger than IT, but we must not confuse detection with protection.

Looking Forward

In short, how can we make OT security stronger than IT? With sabotage-focused deterministic network engineering, Cyber-Informed Engineering, and OT-aware anomaly detection. And yes, use IT tools as well – they “raise the floor” by bringing OT systems closer to the strength of IT systems, but cannot go beyond IT.
For more examples of how and why to make OT systems stronger than IT, please join our webinar on July 29, or access the recording afterwards at the same URL.

 



Source link