ICS & SCADA Security Fundamentals
ICS & SCADA Security Fundamentals
Network Security
AGENDA
● Industry Trends
● Challenges To Industry
● ICS Partnerships
Palo Alto Networks ICS/SCADA Deploys Are Found in
Electric
T&D (CC &SS),Generation (Fossil,
Renewable), AMI Head-end, Regulated &
Unregulated
Transportation
Rail, Airport
Manufacturing
F&B,Materials, Metals processing,
Chemicals, Pharma, Biotech,
Semiconductor, High-tech
Water Treatment
Water & Wastewater
Oil & Gas
Upstream, Midstream / Pipeline
Challenges With Legacy Approach To Cybersecurity in OT
Define business Design from the Determine who/what Inspect and log
outcomes inside out needs access all traffic
Palo Alto Networks Approach
Stop Attacks With the Security Operating Platform
Endpoint
SECURE
THE FUTURE
Detection & Automation & Network traffic & Threat
response orchestration behavioral intelligence
analytics
Meeting <INDUSTRY NAME HERE> Priorities and Needs
Start Anywhere: Consistently secure your Enterprise, Cloud or
Future
SECURE PERIMETER SECURE DATA CENTERS
Firewall, Web filtering, IPS, North-south and east-west
Decryption, Advanced malware security
analysis, Zero Trust
SECURE BRANCHES
SECURE MOBILITY SD-WAN optimization; Cloud
and data center connection
security
SECURE ENDPOINTS
Traditional and SCADA, IOT, PoS
and other sensitive endpoints
SECURE PUBLIC CLOUDS
Consistent multi-cloud security;
GAIN VISIBILITY Cloud compliance and and
security governance
REDUCE ATTACK
SURFACE
PREVENT KNOWN
THREATS
DETECT AND SECURE CLOUD APPLICATIONS
PREVENT NEW DevOps security; Public cloud threat
THREATS protection
IT OT specific visibility IT – OT convergence Stop known and unknown Meet and exceed both Central management
System upgrading or threats, including industry internal and regulatory Highly scalable
migration path specific compliance Cost reduction
Future proofing
Next-generation Firewall - Unique Architecture
Secure ICS Protocols Enforce user and user Secure content, stop
and Applications group controls malicious content
Segmentation
Gateway
NGFW
• Unique single pass, parallel • High-performance, low-latency,
processing engine (SP3) high-availability architecture
Decoders
Generic Decoders
TCP & UDP-Unknown
, S7 Comm Plus
New
S7
MODBUS
IEC “104”
ICS-Specific IPS Signatures
Product-Specific
Anti-Spyware
Antivirus
POWERFUL NETWORK SEGMENTATION WITH THE NGFW AND
SERVICES
• Maximize visibility over OT, IT, IOT, & IIOT traffic.
Micro- POLICY
Panorama
Industrial Cloud OT
Network
(AWS, Azure, Google) Datacenter
Security
Management
PA-5200 SERIES
PA-3200 SERIES
Harsh
SCADA Core / Control Center /
Environments
PCN / MES
PA-800 SERIES
PA-220R
PA-220
Water Electric Transmission Oil & Gas PA-220R Manufacturing Transportation Power
Utilities Generation
& Distribution
Security
○ Facilitate NERC CIP Compliance
○ Layer-7 Visibility and Zero-trust segmentation
○ Advanced Threat Prevention
Case Study: Manufacturing – Steel SECURE PERIMETER
Firewall, Web filtering, IPS,
Customer Profile Decryption, Advanced malware
analysis, Zero Trust
• US Steel Manufacturer with plants in the US, Canada, and Europe
• Victims of espionage and loss of intellectual property
Challenges
• Improving visibility and access control in flat plant networks consisting
primarily of Allen-Bradley/Rockwell ICS
• Securing existing plants in a way that was minimally disruptive
• Deploying consistent approach across global plants (10 plants)
• Avoiding security sprawl, i.e. reducing number of point solutions
• Reducing administrative effort
• Rapidly detecting and stopping advanced threats
Case Study: Manufacturing – Steel SECURE PERIMETER
Firewall, Web filtering, IPS,
Decryption, Advanced malware
analysis, Zero Trust
● Results
○ End-to-end security for network assets, endpoints, cloud apps
○ Safely enabled key business applications
○ Automated prevention of known and unknown threats
○ Mitigated risk of end-user induced ransomware infection and data
exfiltration
○ Ensures consistent policy enforcement while saving administration time.
SECURE PERIMETER
SECURE MOBILITY
● Supports 48 remote locations, two data centers, satellite hub, and a DR SECURE ENDPOINT
Traditional and SCADA, IoT, Pos and
center other sensitive endpoint
Challenges
● To secure a fault-tolerate controls network and maintain high-availability
● Future proofing process control and field networks for internal/external
growth
● Securing remote access to plant and SCADA networks
To learn more about this case study go to [Link] and search for “Protecting ICS and SCADA Networks with
PAN-OS 8.0”
Case Study For Oil & Gas 2006: Full Platform Deployment
SECURE PERIMETER
Results with Palo Alto Networks Firewall, Web filtering, IPS,
Operational Decryption, Advanced malware
analysis, Zero Trust
○ Cost savings for operations: Panorama central management SECURE MOBILITY
■ Reduced time on maintenance and change management of firewalls SECURE ENDPOINT
■ Reduction in errors and time spend troubleshooting control systems Traditional and SCADA, IoT, Pos and
other sensitive endpoint
○ Capital and operational savings for company: Traps implementation extend
life of existing equipment increasing ROI
Security
○ Better visibility into traffic ingress/egressing entire controls network
○ Able to apply subscriptions as needed on key security zones
Multi-Factor: Affordable, effective, and SECURE PERIMETER
Firewall, Web filtering, IPS,
flexible security
Customer Profile SECURE MOBILITY
Decryption, Advanced malware
analysis, Zero Trust
• Major Oil and Gas Pipeline company currently using NGFW to protect remote
SECURE ENDPOINT
sites ICS, PCN, and SCADA networks Traditional and SCADA, IoT, Pos
• Customer now wants to implement MFA to better protect applications at and other sensitive endpoint
these remote sites from unauthorized access from the business and 3rd
party support
Challenges
• 80% or more of the legacy applications at these locations do not support
2FA interaction
To learn more about this case study go to [Link] and search for “Protecting ICS and SCADA Networks with
PAN-OS 8.0”
Multi-Factor: Affordable, effective, and flexible security
SECURE PERIMETER
Results with Palo Alto Networks
Firewall, Web filtering, IPS,
Solution: To implement 2FA interaction process at the network level Decryption, Advanced malware
analysis, Zero Trust
○ Used the NGFW running PAN-OS 8 MFA; MFA is launched when specific SECURE MOBILITY
criteria are met within ruleset
SECURE ENDPOINT
Traditional and SCADA, IoT, Pos and
Security Benefits other sensitive endpoint
○ Now able to enable MFA by User or AD Groups and enforce strict access
control
○ Use Dynamic Address Groups (DAGs) Log Forwarding Profiles to create
flexible policies which adapt to changes
○ Failed authentication attempts are quarantined
Industry 4.0: IaaS & PaaS Implementation In OT
Environment SECURE PERIMETER
Firewall, Web filtering, IPS,
Decryption, Advanced malware
analysis, Zero Trust
SECURE MOBILITY
Customer Profile
• Global Integrated O&G Company (Upstream,
SECURE ENDPOINT
Midstream, Downstream) Traditional and SCADA, IoT, Pos and
• 70,000 + Employees, with More than 30,000 other sensitive endpoint
Contractors
• 100’s of Billions of Dollars in Revenue
Challenges
• OT infrastructure has multiple challenges regarding
• Cloud Adoption
data acquisition • Different Protocols
• Antiquated network infrastructure • Latency and Point of Presence Concerns
• Legacy data - business needs better info • Only Publicly Available PaaS Endpoints
• Latency - data is not arriving on time • Data Privacy and Data Ownership
• IoT Devices – security challenges • Domain Knowledge for Process Control Engineers
• Business ahead of security
• PaaS vs IaaS confusion and security
Industry 4.0: IaaS & PaaS Implementation In OT SECURE PERIMETER
Firewall, Web filtering, IPS,
Environment Decryption, Advanced malware
analysis, Zero Trust
Results with Palo Alto Networks SECURE MOBILITY
Security Benefits
Development and deployment of a secure IaaS to PaaS
infrastructure based on Purdue Model which has made possible:
● Migration from traditional OT to Cloud-enabled architecture
possible
● Automated deployment of design to the different business
units consistent and secure
● Quicker adoption within the business
NTP/DNS Directory
Services
2. DNS Response
1. DNS Request LB IP
for IoT Hub
IoT Hub
Challenges
• Provide a solution that will not be an administrative burden to configure and
maintain SECURE PUBLIC CLOUDS
• Support fully meshed network currently in use Consistent multi-cloud security;
Cloud compliance and and
• If possible, not introduce another point of failure by adding an appliance in front of security governance
firewall to handle routing or dynamic tunnels
To learn more about this case study go to [Link] and search for “Protecting ICS and SCADA Networks with
PAN-OS 8.0”
Dynamic Meshing of IPSec Tunnels: Affordable, effective, and
flexible security
Results with Palo Alto Networks
Operational benefits: By implementing GlobalProtect Cloud Services customer was able to:
○ Build a managed, scalable service to dynamically mesh remote ICS SCADA sites with IPSec/SSL tunnels
○ Removes the complexity from cloud deployment (firewall, portals, and gateways) while allowing for central management through
Panorama
○ Greatly simplify data center architecture
Security
○ Protects both remote business and ICS SCADA sites with a system that allows for automation to reduce operational costs and incident
response fatigue
○ Able to leverage subscriptions as needed based on locations business operations
○ GlobalProtect Cloud Service also includes a cloud-based logging, so all activity is recorded
SECURE PERIMETER
Firewall, Web filtering, IPS, Decryption,
Advanced malware analysis, Zero Trust
SECURE MOBILITY
SECURE MOBILITY
“Palo Alto Networks in providing value well beyond addressing our initial need for PCI compliance, and we expect that value
to continue to grow as Warren Rogers pursues new business opportunities.” --Matthew McLimans, Computer Engineer
The Way Forward:
Defending the Mission
Cyber Leadership for the New Battlefront
• Resource center
• Hands-On-Workshop
• Cyber Ranges
Implement:
[Link]
m