Showing posts with label Firewall. Show all posts
Showing posts with label Firewall. Show all posts

Thursday, 15 August 2024

Industrial network security.

LAN Firewalls enable industrial operators to overcome networking challenges, ensuring both network security and uptime.

Because of their frequency, cyberattacks on critical infrastructure are no longer the sensational news they once were. However, these types of cyberattacks heavily impact communities and businesses closely tied to critical infrastructures, such as power substations, intelligent transportation, and water treatment.

To mitigate the impact of cyberattacks, governments worldwide are implementing laws and regulations to strengthen cybersecurity for critical infrastructure. For example, by October 2024, EU members are required to incorporate the NIS2 Directive into their national laws to strengthen cybersecurity for critical infrastructure. Therefore, industrial organizations need to adopt a comprehensive cybersecurity framework and implement robust solutions to meet these standards and regulations.

Defense-in-depth Strategies.
Typically, industrial cybersecurity standards and regulations recommend defense-in-depth strategies, which involve implementing multiple layers of protection to limit security risks for organizations. Industrial operators will concentrate on fortifying network boundaries and establishing security zones to minimize potential threats from external access.

However, addressing internal threats is just as critical because internal devices without protection can compromise an entire network. For instance, plugging in a portable storage device that carries malware can compromise a network and have it controlled by bad actors. Thus, protecting the network from internal and external threats is of utmost importance. Industrial firewalls effectively filter traffic to prevent potential threats from internal and external access. However, industrial operators usually have concerns about network performance when deploying industrial firewalls in LANs near critical assets.

here the focus on four concerns faced by various stakeholders— asset owners, chief information security officers (CISOs), system integrators, OT network administrators, and industrial network design experts—when implementing firewall solutions. Also highlighted is how next-gen industrial LAN firewalls overcome these challenges to strengthen network security and ensure uninterrupted network operation.

Four Worries When Implementing Firewall Solutions.
Although implementing firewall solutions increases the security level of industrial operations, these changes can affect current operations. Striking a balance between network security and performance is challenging. 

1: Adding New Devices Requires Changes to Existing Networks.
Deploying industrial firewall solutions into existing networks can lead to significant network topology changes. Redesigning the topology and reconfiguring IP subnets to integrate the new firewall solution into existing networks will demand substantial efforts and time from industrial engineers. This is particularly difficult for critical applications that cannot afford any network downtime. Therefore, industrial operators need a firewall solution that does not alter their present network configuration.
2: Adding New Devices Affects Network Performance and Services.
Seamless system operations rely on smooth network communications. The big worry when adding new devices to enhance cybersecurity is whether they meet current network performance standards, such as boot time, network latency, and operating environment needs. Furthermore, the addition of new devices raises the likelihood of network downtime caused by maintenance or device malfunctions. Therefore, a firewall solution must prioritize network performance and mitigate the risk of complete shutdown from a single point of failure.
3: Protecting Many Legacy Devices at Field Sites Is Challenging.
Standards such as IEC 62443 and frameworks like NIS2 require critical assets to protect against DoS attacks and maintain event logs during incidents. However, many critical assets in industrial applications are legacy devices that usually use older versions of operating systems and cannot be replaced right away to meet these network security requirements. To safeguard legacy devices from growing threats, a firewall solution is required that doesn’t require frequent system updates. Moreover, a significant number of legacy devices at field sites use diverse industrial communication protocols for different application needs. For improved communication security, a firewall solution needs to support these protocols and conduct detailed data analysis in industrial control networks.
4: Monitoring Networks and Cyberthreats Is Not So Simple.
To ensure the safety of networks, constant monitoring and management of network security is crucial. It requires a lot of time and effort for administrators to keep their eyes on the network status, making sure they receive real-time notifications when a network error or security event occurs. The absence of an effective monitoring mechanism for firewall solutions leads to delays in network error notifications and security event alerts, resulting in extended network downtimes and compromised operational performance.

Maximize Industrial Network Security and Uptime.
With Moxa EDF-G1002-BP Series LAN firewalls, industrial operators can overcome networking challenges, ensuring both network security and uptime. Operating in transparent firewall mode, the Moxa LAN firewall prioritizes safeguarding critical assets and facilitating secure east-west communication within the LAN.

Simplified Installation.
The nature of the LAN firewalls allows the deployment of firewalls without reconfiguring IP subnets. Such designs are perfect for those critical applications that cannot afford to change their existing network topology. To simplify network installations, these 2-port LAN firewalls allow bump-in-the-wire installations so that engineers can simply connect these LAN firewalls in front of critical assets without reconfiguring IP subnets. This way, the LAN firewalls ensure minimal disruption to existing configurations and enhance network security.

The Moxa EDF-G1002-BP Series
is an industrial-grade LAN firewall
Optimized Network Uptime.
It only takes 30 seconds of boot time to enable Moxa LAN firewalls. This quick boot time ensures that during a power outage and subsequent restoration the anomaly detection mechanism between the control center and terminal PLC equipment does not trigger mistakenly. Also, Moxa LAN firewalls have a LAN Bypass function that prevents hardware or software anomalies from causing the firewall to interrupt operational services. Both mechanisms aim to achieve uninterrupted operations.

Legacy Device Protection.
Making it easy to protect legacy devices is the core mission of Moxa LAN firewalls. They are designed for industry use, incorporating an intrusion prevention system (IPS) and deep packet inspection (DPI) technology to strengthen network security. Industrial-grade IPS designs ensure the security of legacy devices, including PLC and HMI. Moxa IPS functions safeguard legacy devices from current threats using virtual patches and pattern-based protection, allowing additional time to update systems. Moxa DPI technology provides greater control over the security of industrial communications. To maintain data integrity, rules can be defined that limit Modbus equipment to read-only access, for instance. Legacy devices can be safeguarded using different protocols and benefit from DPI technology’s support for multiple industrial protocols and advanced traffic filtering capabilities.

Simplified Network Management.
Using Moxa LAN firewalls to secure network and legacy devices will simplify network monitoring and security management, along with Moxa MXview One network management software and MXsecurity network security management software. MXview One software provides a holistic view of network security status and notifies users when a network error occurs. With MXsecurity software, users can effectively manage firewalls and monitor security events. Implementing firewall policies on a centralized platform minimizes manual errors in individual configurations. Furthermore, Moxa software notifies users of security events for quick responses and risk mitigation.

 


@Moxa_Europe @Cybersec_EU @DigitalEU @OConnellPR #PAuto #Cybersecurity #LAN

Monday, 12 June 2023

Understanding concepts for network security.

In today's interconnected world, network security is of utmost importance. It is crucial to understand key concepts like IP firewall settings, port forwarding, network address translation (NAT), and gateway address settings to safeguard systems and data. In this article, we will delve into these topics and explore how they contribute to network security as well as tips for proper IP router operation.

An IP firewall acts as a barrier between your network and external networks, monitoring and filtering incoming and outgoing traffic. By defining rules and policies, it allows or denies access to specific IP addresses or ports. Firewall settings can be customized to suit individual security requirements and provide access to desired LAN-side devices, prevent unauthorized access, and minimize potential threats.

Port forwarding is a technique that enables remote devices to traverse the firewall and access specific services or applications hosted on a private network. By configuring port forwarding settings on a router or firewall, incoming requests to a specific port are directed to a particular device within the network. This feature is commonly used for accessing webpages and applications to configure and program remote jobsite devices. It is essential to ensure that port forwarding is implemented securely, as misconfigurations can expose vulnerable services to unauthorized access.

Network address translation (NAT) is a technology that allows changing or translating IP addresses between different subnets. Usually, a WAN-side or public IP is translated to a private network to allow access to all services of LAN-side device. This provides an added layer of security by hiding internal IP addresses from external networks, making it difficult for potential attackers to target individual devices directly. The WAN-side device can communicate to a LAN device behind the firewall without any special configuration as it uses the WAN-side IP address.

The gateway address is the IP address of the device that connects a local network to an external network, typically a router. Configuring IP address settings involves defining the IP address, subnet mask, and default gateway for devices within the network. This ensures proper communication between devices within the local network and establishes a secure connection with external networks. For the LAN-side devices, the gateway address should be the IP address of the LAN port of the IP router.

Understanding IP firewall settings, port forwarding, NAT, and gateway address settings is essential for maintaining a secure network environment. If the gateway address is missing or misconfigured, it will prevent internet access for the LAN-side devices. Additionally, any port forwarding and NAT settings will not work without the proper gateway address setting. Port forwarding and NAT settings provide a means to traverse the firewall – hence the firewall needs to be enabled to use these settings. If the firewall is disabled, then the router is just connecting two subnets together and the devices on either side can access each other directly using the actual IP address provided they have the correct gateway setting at both the source and destination device. 

Contemporary Controls' Skorpion Series of IP routers provide access to these features in an easy to configure webpage format. 

@ccontrolsgmbh #Pauto #CyberSecurity

Tuesday, 16 May 2023

Enhanced Perimeter Defence for DCS.

NextGen Smart Firewall offers greater bandwidth, updated user-friendly interface and more granular roles for robust, easy-to-configure perimeter security

Perimeter security for the DeltaV™ distributed control system (DCS) is being improved by Emerson, with its new NextGen Smart Firewall, a purpose-built control system firewall designed to provide easy-to-install and easy-to-maintain perimeter security for all industries. More ruggedised construction, increased bandwidth, and role-based access provide users with increased performance and more granular access control.

Manufacturers need to secure their networks without complexity that would otherwise add administrative overhead to already busy operations teams. Emerson’s NextGen Smart Firewall features a user-friendly HTML5 web-based user interface, easy-to-understand set-up menus, and pre-defined DeltaV application rules. The ease-of-use helps DeltaV administrators and control engineers with no security or information technology (IT) expertise create secure connections for DeltaV applications.

“A critical element of Emerson’s vision of boundless automation architecture is secure connectivity between systems in the plant and across the enterprise,” said Claudio Fayad, vice president of technology for Emerson’s process systems and solutions business. “Emerson’s NextGen Smart Firewall delivers intuitive set-up and interfaces to provide plants with access to a much wider array of technologies – from control, to reliability, to sustainability and more – without the need to maintain a dedicated IT presence.”

Gigabit connections support improved performance for applications that require higher bandwidth. Ruggedised construction is well suited for harsh manufacturing environments. Emerson’s NextGen Smart Firewall’s advanced features include:

  • Virtual private networks – increasing flexibility and security for geographically dispersed networks
  • Network address translation – protecting network IP schemes and conserving addresses
  • More granular user roles – administrators have full control, engineers may add or modify application rules, and auditors have read-only access to logs.
@EMR_Automation @Emerson_News @EmersonExchange @HHC_Lewis #PAuto #Cybersecurity

Monday, 16 August 2021

Unbreaking the record for cyber-attacks.

Matthew Hawkridge, chief technology officer at Ovarro, the supplier and manufacturer of remote monitoring technologies, explains why secure RTUs can mitigate threats against critical national infrastructure.

According to Forbes, 2020 broke all records for data lost in breaches and sheer numbers of cyber-attacks on companies, individuals and governments. These threats are also becoming more sophisticated with emerging technologies like machine learning, artificial intelligence and 5G. Fortunately, remote telemetry units (RTUs) allow for better control and visibility when accompanied by advanced development and deployment techniques. 

But why the rise in incidents? One explanation is that the increased move towards digitalisation and Industry 4.0 has raised cyber-security risks.

Cyber-attacks can also affect critical network infrastructure (CNI) like energy, water or oil and gas networks — the British Government’s National Cyber Security Council (NCSC) is always concerned about the prospect of Russia or China hacking into Britain’s water supply chain. Cyberthreats to CNIs include espionage, targeted attacks from malicious actors, such as hostile states and criminals, and accidental data loss. All have the potential to disrupt our lives and damage the economy.

(In Ireland the ransomeware attack on the Health Service Executive (HSE) of Ireland systems by cybercriminals during the worst experiences on the COVID 19 is a case in point as are several cases of penitration of US utilities around the same time. - Editor)

But how can CNI operators embrace digital transformation and all its benefits without inviting cybersecurity risks? The answer lies in RTUs and deployment with the latest NCSC Cyber Assessment Framework (CAF).

Secure ease-of-access
For decades, telemetry unit systems have been used for remote monitoring of power consumption and battery backup in networks for energy, water and telecommunications by gathering information about critical assets. They work on the simple premise that, if the condition of an asset is understood, then it can be managed efficiently and respond quickly to change. There is immense value in being able to optimise operations and to detect and respond faster to impending issues.

These systems are also equipped for Wi-Fi and the advent of 5G — for example, for process plants with servers in the cloud or in a nearby, air-conditioned control room, the RTU gathers information about critical assets. RTUs are emerging as one of the drivers for the IoT because they can gather and manage large volumes of data for analysis. Also, they are secure against cyber-attacks.

Ovarro’s TBox RTU is equipped with a Firewall with four levels of authority, HTTP session authentication and SSL/TLS & X.509 certificates. It also meets the IEEE802.1X standard for devices that connect with other devices on local area networks (LANs). Ovarro also works with highly qualified “CHECK” approved third party penetration testers, cybersecurity experts that help us investigate and discover potential vulnerabilities and weaknesses in our products’ defences. We also publish security advisories on new discoveries upon patching for complete transparency.

Going forward, Ovarro is committed to meeting the IEC-62443 standard to secure industrial automation and control technology systems. But how are these efforts applied in a real-world setting, and where do RTUs fit in?

Better Industry 4.0

PetroChina Southwest Oil and Gas Field Company approached Ovarro to support with a digital upgrade project at its Chongqing Gas Mine (CN). The mine is located in the jurisdiction of 277 industrial gas wells with a daily production capacity of 20 million cubic meters. Specifically, the customer wanted to improve remote monitoring of all its key gas wells with a better use of data. A key feature of this digital transformation would be the installation of an internet protocol (IP) camera at each site, giving regular images of the well head. But how could this be achieved securely?

Ovarro’s solution was to install a total of 70 solar-powered TBox RTUs within a supervisory control and data acquisition (SCADA) system. The RTUs have the responsibility of capturing and transmitting an image snapshot each hour, or upon an alarm. In the case of a communications outage, the historian capabilities of the RTU can store months-worth of historical data on pressure, process shut-off valve position and more. This can be backed-up and transmitted to the central control station later, helping protect against data loss.

PetroChina has praised the TBox’s built-in cyber security suite with authentication and encryption technology, which provides state-of-the-art protection of the customer’s assets and data. This example shows that CNI managers can embrace the advantages of Industry 4.0 without compromising cybersecurity. With the right technology like RTUs in place, let’s hope that 2020’s cyberattack records remain unbroken in the future.

@ovarro_ltd @NCSC @StoneJunctionPR @ForbesTech #PAuto #Cybersecurity

Tuesday, 5 June 2018

Protection from network-based attacks!

If people, machinery and industrial processes are intelligently linked, these networks are also more susceptible to attack. The Pilz SecurityBridge protects the configurable, safe small controllers PNOZmulti and the automation system PSS 4000 from network-based attacks and unauthorised access. Plant and machinery are thus not only safe, but also secure, which ensures the safety of employees and increases the availability of the machinery.

PNOZmulti

Safety needs to do both – not only ensure protection for humans and machinery, but also offer the necessary degree of flexibility and availability in the smart factory. This requires a holistic approach in terms of safety & security, which can be supported through hardware solutions such as the Pilz SecurityBridge.

Pilz is expanding its product range with SecurityBridge to include the area of Industrial Security. It  protects the connections between the programming/configuration tools and the hardware controllers from manipulation by detecting unauthorised changes to the automation project, for example. The SecurityBridge acts as a firewall. However, unlike generic firewalls, they do not need complex configuration; thanks to application-specific default settings they are easy to commission using the plug-and-play principle.

As well as benefiting from the security aspect, users also enjoy higher plant availability because only the data that is necessary (authorised configuration and process data) is transmitted.

Pilz will also develop future products from the perspective of security, within a TÜV-certified process in accordance with IEC 62443-4-1. Aspects such as threat scenarios, strengths and weaknesses of protocols or encryption methods are taken into consideration from the outset. The following is true in networked plants: Without security, the machinery safety can also no longer be ensured.

The same applies for both security and safety: To ensure that technical measures can work, these must be accompanied by organisational measures such as handling instructions, procedures and training. The Pilz Academy also offers training courses on the topic of industrial security.

@Pilz_INT #PAuto #Cybersecurity

Wednesday, 21 September 2016

Secure data access across DMZs.

In today’s industrial automation world, it is standard practice for IT departments to lock down traffic between different networks. The most common method of selectively exchanging data between such secured networks is by using Demilitarized Zones (DMZs).

Key Benefits include:
• Works across multi-layered networks
• Eliminates traditional DCOM & firewall issues associated with DMZs
• Configurable data encryption
While DMZs offer a controlled method of exchanging data in the corporate world, they typically interfere with the exchange of control automation data between the operations and business networks. The Matrikon OPC DMZ Agent solves this challenge.

Matrikon OPC DMZ Agent facilitates the transfer of real-time and archived automation data through DMZs in a secure and controlled manner. Depending on the IT policies being enforced, DMZ Agent can either enable authorized enterprise applications to securely request the automation data needed or if this is not possible - to simply accept OPC data as it is sent (pushed) from the secured operations network.



@MatrikonOPC #PAuto #Cybersecurity

Wednesday, 25 May 2016

Protection from cyber-attacks.

The low cost and easy to install Floodgate Defender firewall appliance is available from Icon Labs. The compact Floodgate Defender Mark III (4 inches by 3.75 inches by 1.25 inches) provides a critical layer of security for legacy devices that comprise The Internet of Things including SCADA networks, military equipment, critical infrastructure controllers, and medical devices.
“A large portion of our critical infrastructure is controlled by legacy devices that were originally designed for use on closed networks and therefore contain little or no security. Even though they perform critical functions managing our power grid, factories, communication networks, and hospitals, most are easy targets for cyber-criminals and cyber-terrorism,” said Alan Grau, President of Icon Labs. “Many of these devices cannot be updated to include security, and replacing them with new secure versions will take years. The Floodgate Defender provides a simple and cost-effective solution to stop these attacks.”

The Floodgate Defender device is plugged in between the Internet or WAN and the device. It includes two Ethernet ports for easy installation. It can be easily configured with communication policies customized for the device it is protecting by using a web-based management interface. The Floodgate Defender enforces the policies, blocking attacks before a connection can be established with the target device, without requiring any change to the network or the target device. The Floodgate Security Manager, or other security management systems, can access the event log to audit and manage policies.

The Floodgate Defender’s patented technology protects legacy devices from a broad range of cyber-attacks.
Features include:
- Filtering by IP addresses, ports, and protocols
- Stateful packet inspection
- Deep packet inspection for ModbusTCP and other industrial protocols
- Detection and reporting of suspicious traffic
*Floodgate Security Manager
*McAfee ePO
*McAfee SIEM
- Integration with security management systems including:
- Ethernet pass-through upon power failure to facilitate continuous operation in critical environments
The Floodgate Defender includes an innovative security coprocessor from Maxim Integrated Products, Inc. that provides secure key storage and a cryptographic accelerator. This improves the resistance of encryption functions, enables secure boot, and ensures the security of both the Floodgate Defender device itself and the devices it is protecting.

“We are pleased to partner with Icon Labs to incorporate our secure microcontroller into this new compact firewall that protects installed networked devices with insufficient security. This exclusive combination of our technology with Icon Labs’ software is a significant advancement in creating the “Internet of Secure Things,” said Christophe Tremlet, Senior Business Manager, Maxim Integrated.


"Embedded devices have failed to maintain pace with the increasing number of attacks targeting them, making them easy targets for industrial espionage, hacktivists or even terrorist groups. These devices need the same level of security used to protect enterprise networks,” said Jared Weiner - Analyst, M2M Embedded Software & Tools, VDC Research. “Floodgate Defender provides these devices with a critical, missing layer of security.”

#IconLabs #PAuto #Cybersecurity

Tuesday, 14 October 2014

Distributor for industrial security system for Britain!

"The industry has come a long way since StuxNet."

Electroustic now distributes Tofino's Xenon industrial firewall. Manufactured by Hirschmann, the Tofino Xenon security system is the latest addition to the Tofino family and is purpose built to provide comprehensive network protection for production systems.

The Tofino Xenon security system is both versatile and rugged, allowing it to withstand the harshest of environments, making it ideal for any industry in which maximum data security is required. This includes plant and process engineering, the transportation sector, oil and gas, power transmission and renewable energy applications such as wind farms.

Security in industry has become of paramount importance in recent years. The cost of cyber attacks on critical infrastructure is now measured in billions of dollars worth of damage.   

With Tofino's Plug-n-Protect technology, Xenon is incredibly simple to implement. The application can be installed in a live network with no special training, pre-configuration or changes to the network itself, eradicating expensive downtime.  

The industrial firewall's security stems from stateful packet inspection (SPI) that not only examines a packet based on its header, as with traditional static filtering, but rather packet contents, to establish more information than simply source and destination. SPI tracks each connection - traversing all interfaces of the firewall and ensuring its validity. 

Furthermore, as an added security measure against port scanning, the SPI closes off ports until connection to a specific one is requested.

"Here at Electroustic we provide industrial Ethernet solutions to a variety of industries," reported Paul Carr, managing director and owner. "Security is currently a very pertinent and prominent issue for nearly all the sectors we supply to.

“That's why we recommend Tofino products that help customers meet and exceed NERC CIP (North American Electric Reliability Corporation Critical Infrastructure Protection) requirements and ISA/IEC-62443 Standards. The Xenon firewall delivers peace of mind, which is essential – the industry has come a long way since StuxNet." 

In addition to the Xenon's in built features, optional deep packet inspection (DPI) is available. This feature allows the user to implement detailed filters within their system. Tofino’s flexible architecture goes beyond traditional firewall security by providing tailored protection zones to protect critical system components.   

Friday, 18 October 2013

Secure connection of redundant networks!

The new security module Scalance S627-2M from the Siemens protects automation networks from unauthorised access by means of a firewall. In this way, redundant network structures, for example redundant rings, can also be securely connected for the first time according to MRP (Media Redundancy Protocol) or HRP (High Speed Redundancy).

• Security module Scalance S627-2M protects against unauthorized access, also inside redundant network structures, by means of a firewall
• Connection of electrical and optical connections to a device
• Flexible use in line and ring structures
• Fault-tolerant connections with two security modules operated in parallel
Scalance S627-2M is equipped with three fixed electrical ports, including one secure and one DMZ (Demilitarised Zone) port, as well as two slots for media modules which can be optionally connected. As an option, the user can add up to two electrical or optical ports per media module and thus integrate the security module directly in optical networks. Furthermore, fault-tolerant connections can be realized by means of two units used in parallel. As soon as one security module fails, the second device is automatically activated from standby mode and takes over data traffic.

With up to seven ports in total, Scalance S627-2M enables protection of the most varied network topologies with firewalls and therefore the flexible implementation of security concepts. For example, the security module can connect redundant rings with a backbone cable or two ring structures, as well as link individual automation cells to a higher-level network. With the help of various media modules, mixed networks can also be set up with electrical and optical connections both in long-range single-mode and in multi-mode with more bandwidth.