0% found this document useful (0 votes)
100 views49 pages

ICS & SCADA Security Fundamentals

Uploaded by

mario_behring
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
100 views49 pages

ICS & SCADA Security Fundamentals

Uploaded by

mario_behring
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd

Network

Security - ICS &


SCADA Base
Presentation

Version 1.0 February 2020


First name, Last name
Title, Company

Network Security
AGENDA

● Industry Trends

● Challenges To Industry

● Palo Alto Networks Approach To Securing Digital Transformation

● ICS Partnerships
Palo Alto Networks ICS/SCADA Deploys Are Found in

Electric
T&D (CC &SS),Generation (Fossil,
Renewable), AMI Head-end, Regulated &
Unregulated
Transportation
Rail, Airport

Manufacturing
F&B,Materials, Metals processing,
Chemicals, Pharma, Biotech,
Semiconductor, High-tech

Water Treatment
Water & Wastewater
Oil & Gas
Upstream, Midstream / Pipeline
Challenges With Legacy Approach To Cybersecurity in OT

Proprietary Protocols, Highly Customized Systems


Poor Visibility
Tightening Regulations:
Increasing
In ability
NERC toAttack
CIP patch,Surface
COTS, IT - OT
Integration
EU - General Data Protection Regulation
GDPR Advance
Stopping
Mainstream OS, High
Threats
Uptime Requirements
California Consumer Privacy Act CCPA
ICS & SCADA
Multiple Vendors,
Complexity & Scalability
No Central
of Point
Solutions
Management
Critical Infrastructure Cyber Attack Timeline
Crashoverride
(W) NotPetya

Syrain Hackitivist WannCr


Grp y Triton
Conflicker
German Steel Mill
(M,S-P) Nyrstar
SEIMENS Trojan
BlackEnergy cause
(M,SP)) not
OnionDo release
g OnionCity
(Malwar (Botnet, Trojan)
134M credit
cards stolen
Havex
e, worm)
3T +
Cybercrime
Flame (Malware,
600M predicted to
Worm) New Malicious reach $6 trillion
annually by
Stuxnet(Duqu
295 programs
registered 2021
Operation Night
, Flame, & Reported
Conficker
Gauss) Dragon
DUQU (Malware,
245 incidents to ICS-
Worm)
(Worm) From 2009 - CERT; 97
By 2013 59% of
2014 number of Critical
attacks aimed
incident Manufacturing;
at Energy
increased 27% 46Energy Sector
2009 -
2011 2012 2014 2015 - 16 2017 - 18 Present
10
French Navy, Exxon, Shell, BP Oil Ministry, Havex - Muli- Korea Pwr Grid Ukraine Nyrstar Mining
France Western National Oil, Target Kemuri Water Co. Dacia Car Manuf
Natanz counties, Middle Korea KGG Nuclear Fac Multi-Target
Nuclear Fac East, Asia Worldwide Ukraine &
Germany
Must-have Capabilities Of Next-generation ICS IoT Security

MINIMAL IMPACT APPLICATION AWARE CENTRALIZED INCLUSIVE

PERFORMANCE VISIBILITY & ADMINISTRATION THREAT


ACCESS PREVENTION
Support uptime & performance
goals of IT & OT
CONTROL Simple, intuitive administration Stops ICS-specific & IT threats
Central administration Rapidly stops new & evolving
Does not require “Rip-and- ICS-specific visibility & Role-
based access control threats
Replace” Native log correlation
Inspect payload Multiple kill points across the
Easily scales to meet operations Must reduce burden of attack chain
current & future size administrators
Support for ICS cybersecurity
laws and framework Protects legacy systems

SUPPORT ZERO TRUST DESIGN CONCEPTS &


Define business outcomes Design from insideARCHITECTURE
Determine who/what needs Inspect and log all
out access traffic
Support ZERO TRUST Design Concepts & Architecture

Define business Design from the Determine who/what Inspect and log
outcomes inside out needs access all traffic
Palo Alto Networks Approach
Stop Attacks With the Security Operating Platform

Unmatched Tightly Integrated Accurate and automated


Protection
Save time and reduce Analytics trigger
Visibility and control complexity by replacing automation for immediate,
everywhere: on- disconnected tools effective actions
premises, branch,
mobile, cloud

BUILT FOR SIMPLICITY


Securing Your Mission

Hybrid data SECURE SECURE


center THE THE CLOUD Secure access
Internet
ENTERPRISE
Perimeter SaaS
Branch & mobile
Public cloud
DATA
5G & IoT
LAKE

Endpoint

SECURE
THE FUTURE
Detection & Automation & Network traffic & Threat
response orchestration behavioral intelligence
analytics
Meeting <INDUSTRY NAME HERE> Priorities and Needs
Start Anywhere: Consistently secure your Enterprise, Cloud or
Future
SECURE PERIMETER SECURE DATA CENTERS
Firewall, Web filtering, IPS, North-south and east-west
Decryption, Advanced malware security
analysis, Zero Trust
SECURE BRANCHES
SECURE MOBILITY SD-WAN optimization; Cloud
and data center connection
security
SECURE ENDPOINTS
Traditional and SCADA, IOT, PoS
and other sensitive endpoints
SECURE PUBLIC CLOUDS
Consistent multi-cloud security;
GAIN VISIBILITY Cloud compliance and and
security governance
REDUCE ATTACK
SURFACE
PREVENT KNOWN
THREATS
DETECT AND SECURE CLOUD APPLICATIONS
PREVENT NEW DevOps security; Public cloud threat
THREATS protection

SECURE YOUR FUTURE


Collect, integrate and normalize SECURE ACCESS TO CLOUD
security data; Harness AI, ML, Cloud-connected branch and mobile
predictive analytics and automation workforce; Zero Trust cloud security
Security Platform Benefits For IT-OT Teams in ICS & SCADA

VISIBILITY INTEGRATION PREVENTION COMPLIANCE MANAGEABILITY

IT OT specific visibility IT – OT convergence Stop known and unknown Meet and exceed both Central management
System upgrading or threats, including industry internal and regulatory Highly scalable
migration path specific compliance Cost reduction
Future proofing
Next-generation Firewall - Unique Architecture

Secure ICS Protocols Enforce user and user Secure content, stop
and Applications group controls malicious content

APP-ID USER-ID CONTENT-ID

Segmentation
Gateway
NGFW
• Unique single pass, parallel • High-performance, low-latency,
processing engine (SP3) high-availability architecture

• The only true Next-gen Firewall • Native correlation of data


Natively Integrated Security Services

Protect unpatched & unpatchable systems


from known & unknown threats to ICS &
Threat Prevention: SCADA

Secure network access for mobile devices


in OT E.G. maintenance laptops, tablets,
GlobalProtect: HMIs

Quickly detect and stop 0-day malware


I.E. the next Black Energy, CrashOverride,
Wildfire: Wannacry

Safely enable internet access from OT


URL Filtering:
NGFW
E.G. to vendor support website

Safely enable internet access for OT support


DNS Filtering: staff and protect supply chain
ICS App-IDs with Function-Level
Variants

Decoders

Custom App-ID Decoders


DNP3, Modbus, ICCP

Generic Decoders
TCP & UDP-Unknown

, S7 Comm Plus
New

19 | © 2020 Palo Alto Networks, Inc. All rights


reserved.
Granular Control over ICS Protocol
DNP3 ICCP BACnet

S7
MODBUS

IEC “104”
ICS-Specific IPS Signatures

Product-Specific

ICS & SCADA

Risky Protocol Commands


ICS-Specific IPS Signatures

Anti-Spyware

ICS & SCADA

Antivirus
POWERFUL NETWORK SEGMENTATION WITH THE NGFW AND
SERVICES
• Maximize visibility over OT, IT, IOT, & IIOT traffic.

• Increase the protection surface of assets and system.

• Stop known exploits, malware, C2 traffic

• Quickly discover and stop 0-day threats to both OT & IT infrastructure

Why you’re segmenting? How you enforce segmentation?


Define the protect surface Across layer 2-7
Security “Conduit” (IEC 62443)

Micro- POLICY

perimeter Segmentation POLICY MANAGER


Gateway
NGFW
Protect surface
Consistent Network Security Across Your Industrial Enterprise
VM-Series Virtualized NGFW PA-7000 SERIES

Panorama
Industrial Cloud OT
Network
(AWS, Azure, Google) Datacenter
Security
Management

PA-5200 SERIES

PA-3200 SERIES
Harsh
SCADA Core / Control Center /
Environments
PCN / MES
PA-800 SERIES
PA-220R
PA-220

Plant Perimeter / ICS Core


Plant Perimeter /
ICS Core
CONSISTENT SECURITY FOR INDUSTRIAL DEPLOYMENTS

Water Electric Transmission Oil & Gas PA-220R Manufacturing Transportation Power
Utilities Generation
& Distribution

Extended operating range Prevention of known and unknown


for temperature threats, including ICS-specific threats

Certified for industrial use Range of ICS / SCADA App-IDs


in harsh environments supported with PAN-OS

Fan-less design, no moving parts High availability and dual DC


for higher reliability power supplies for redundancy
Electric Transmission
Case Study: Electric Transmission Data Network (NERC CIP)
Customer Profile
• Major N. American Utility (Regulated)
SECURE PERIMETER
Challenges Firewall, Web filtering, IPS,
Decryption, Advanced malware
• Meeting and exceeding NERC CIP regulatory requirements analysis, Zero Trust

• Improving visibility and segmentation within OT


environments
• Rapidly detecting and stopping advanced threats
• Rising OPEX related to security administration across 2
control centers and 17 high-voltage transmission substations
Results with Palo Alto Networks
Operational
○ Ease-of-use/Consolidation/TCO reduction

Security
○ Facilitate NERC CIP Compliance
○ Layer-7 Visibility and Zero-trust segmentation
○ Advanced Threat Prevention
Case Study: Manufacturing – Steel SECURE PERIMETER
Firewall, Web filtering, IPS,
Customer Profile Decryption, Advanced malware
analysis, Zero Trust
• US Steel Manufacturer with plants in the US, Canada, and Europe
• Victims of espionage and loss of intellectual property
Challenges
• Improving visibility and access control in flat plant networks consisting
primarily of Allen-Bradley/Rockwell ICS
• Securing existing plants in a way that was minimally disruptive
• Deploying consistent approach across global plants (10 plants)
• Avoiding security sprawl, i.e. reducing number of point solutions
• Reducing administrative effort
• Rapidly detecting and stopping advanced threats
Case Study: Manufacturing – Steel SECURE PERIMETER
Firewall, Web filtering, IPS,
Decryption, Advanced malware
analysis, Zero Trust

Results with Palo Alto Networks


Security
○ Layer-7 Visibility and Zero-trust segmentation
■ Monitor and control OT traffic to business and internet
○ Eliminated risk related to VLAN hopping
○ Advanced Threat Prevention via WildFire
Operational
○ Ease-of-use/Consolidation/TCO reduction
○ Put Next-gen security into legacy network with minimal
disruption using VLAN insertion
○ High availability – Active/Passive on all NGFW locations
○ Unified platform for OT and IT - replaced Checkpoint at
IGW, Cisco ASAs in the DC
○ Centrally managing 200+ NGFWs and moving to ~300
BMS/BAS
Case Study – JBG Smith (S&P 400)

● Owns and manages millions of square feet of real


estate
● Extensive IT infrastructure spanning standard office
services
○ E.G. email and document management SECURE PERIMETER
○ REIT-specific applications SECURE MOBILITY Firewall, Web filtering, IPS,
Decryption, Advanced malware
○ Array of building automation and control systems SECURE ENDPOINT
analysis, Zero Trust

Traditional and SCADA, IoT, Pos and


other sensitive endpoint
● Prior security architecture
○ WebSense content filters
■ Expensive, outdated and didn’t support cloud strategySECURE PUBLIC CLOUD SECURE ACCESS TO CLOUD
Consistent multi-cloud Cloud-connected mobile
○ Cisco ASA with FirePower security; Compliance and
and security governance
workforce; Zero Trust cloud
security
■ Performance and central management issues
■ Non-support for REIT-specific apps
○ Microsoft AV (endpoint)
■ Ineffective at stopping unknown threats

31 | © 2018 Palo Alto Networks, Inc. All Rights Reserved.


Case Study – JBG Smith
Adopted Security Operating Platform
● Next-generation firewalls
○ Internet edge, data centers, SECURE PERIMETER
○ Segment BMS (HVAC, Power, Water, etc) & property SECURE MOBILITY
management offices
● Cloud-delivered security services SECURE ACCESS TO CLOUD
○ Threat Prevention + WildFire + URL Filtering + SECURE ENDPOINT
GlobalProtect
● Traps advanced endpoint protection SECURE PUBLIC CLOUD

● VM-series in Azure cloud


● Aperture for SaaS security
● Panorama Central Management
Case Study – JBG Smith

● Results
○ End-to-end security for network assets, endpoints, cloud apps
○ Safely enabled key business applications
○ Automated prevention of known and unknown threats
○ Mitigated risk of end-user induced ransomware infection and data
exfiltration
○ Ensures consistent policy enforcement while saving administration time.

SECURE PERIMETER

SECURE MOBILITY

SECURE ACCESS TO CLOUD


SECURE ENDPOINT

SECURE PUBLIC CLOUD


Learn More

Link Link Link


Oil & Gas
Case Studies Oil and Gas: Full-Platform SECURE PERIMETER
Firewall, Web filtering, IPS,
Deployment
Customer Profile
Decryption, Advanced malware
SECURE MOBILITY
analysis, Zero Trust

● Supports 48 remote locations, two data centers, satellite hub, and a DR SECURE ENDPOINT
Traditional and SCADA, IoT, Pos and
center other sensitive endpoint

Challenges
● To secure a fault-tolerate controls network and maintain high-availability
● Future proofing process control and field networks for internal/external
growth
● Securing remote access to plant and SCADA networks

To learn more about this case study go to [Link] and search for “Protecting ICS and SCADA Networks with
PAN-OS 8.0”
Case Study For Oil & Gas 2006: Full Platform Deployment
SECURE PERIMETER
Results with Palo Alto Networks Firewall, Web filtering, IPS,
Operational Decryption, Advanced malware
analysis, Zero Trust
○ Cost savings for operations: Panorama central management SECURE MOBILITY
■ Reduced time on maintenance and change management of firewalls SECURE ENDPOINT
■ Reduction in errors and time spend troubleshooting control systems Traditional and SCADA, IoT, Pos and
other sensitive endpoint
○ Capital and operational savings for company: Traps implementation extend
life of existing equipment increasing ROI
Security
○ Better visibility into traffic ingress/egressing entire controls network
○ Able to apply subscriptions as needed on key security zones
Multi-Factor: Affordable, effective, and SECURE PERIMETER
Firewall, Web filtering, IPS,
flexible security
Customer Profile SECURE MOBILITY
Decryption, Advanced malware
analysis, Zero Trust

• Major Oil and Gas Pipeline company currently using NGFW to protect remote
SECURE ENDPOINT
sites ICS, PCN, and SCADA networks Traditional and SCADA, IoT, Pos
• Customer now wants to implement MFA to better protect applications at and other sensitive endpoint

these remote sites from unauthorized access from the business and 3rd
party support
Challenges
• 80% or more of the legacy applications at these locations do not support
2FA interaction

To learn more about this case study go to [Link] and search for “Protecting ICS and SCADA Networks with
PAN-OS 8.0”
Multi-Factor: Affordable, effective, and flexible security
SECURE PERIMETER
Results with Palo Alto Networks
Firewall, Web filtering, IPS,
Solution: To implement 2FA interaction process at the network level Decryption, Advanced malware
analysis, Zero Trust
○ Used the NGFW running PAN-OS 8 MFA; MFA is launched when specific SECURE MOBILITY
criteria are met within ruleset
SECURE ENDPOINT
Traditional and SCADA, IoT, Pos and
Security Benefits other sensitive endpoint
○ Now able to enable MFA by User or AD Groups and enforce strict access
control
○ Use Dynamic Address Groups (DAGs) Log Forwarding Profiles to create
flexible policies which adapt to changes
○ Failed authentication attempts are quarantined
Industry 4.0: IaaS & PaaS Implementation In OT
Environment SECURE PERIMETER
Firewall, Web filtering, IPS,
Decryption, Advanced malware
analysis, Zero Trust
SECURE MOBILITY
Customer Profile
• Global Integrated O&G Company (Upstream,
SECURE ENDPOINT
Midstream, Downstream) Traditional and SCADA, IoT, Pos and
• 70,000 + Employees, with More than 30,000 other sensitive endpoint

Contractors
• 100’s of Billions of Dollars in Revenue
Challenges
• OT infrastructure has multiple challenges regarding
• Cloud Adoption
data acquisition • Different Protocols
• Antiquated network infrastructure • Latency and Point of Presence Concerns
• Legacy data - business needs better info • Only Publicly Available PaaS Endpoints
• Latency - data is not arriving on time • Data Privacy and Data Ownership
• IoT Devices – security challenges • Domain Knowledge for Process Control Engineers
• Business ahead of security
• PaaS vs IaaS confusion and security
Industry 4.0: IaaS & PaaS Implementation In OT SECURE PERIMETER
Firewall, Web filtering, IPS,
Environment Decryption, Advanced malware
analysis, Zero Trust
Results with Palo Alto Networks SECURE MOBILITY

Solution: Deployed a Hybrid Cloud Solution by implementing Palo SECURE ENDPOINT


Traditional and SCADA, IoT, Pos and
Alto Networks NGFW VM on Azure cloud and customized MQTT other sensitive endpoint
application signatures

Security Benefits
Development and deployment of a secure IaaS to PaaS
infrastructure based on Purdue Model which has made possible:
● Migration from traditional OT to Cloud-enabled architecture
possible
● Automated deployment of design to the different business
units consistent and secure
● Quicker adoption within the business

INCREASE REVENUES > 10 BILLION DOLLARS PER


YEAR
Network Services

NTP/DNS Directory
Services

2. DNS Response
1. DNS Request LB IP
for IoT Hub

IoT Hub

IoT Edge Secure Load Balancer


Network
4. NGFW decrypts
3. Gateway Sends and enforces
5. NGFW performs
MQTT to LB IP MQTT policy
FQDN NAT to
Public IP of IoT
Hub
Dynamic Meshing of IPSec Tunnels: SECURE PERIMETER
Firewall, Web filtering, IPS, Decryption,
Affordable, effective, and flexible security Advanced malware analysis, Zero Trust
SECURE MOBILITY
Customer Profile SECURE ENDPOINT
• Major Oil and Gas Pipeline with multiple locations which require IPSec connectivity toTraditional and SCADA, IoT, Pos and
multiple data centers and must leverage existing MPLS over Internet connections other sensitive endpoint

Challenges
• Provide a solution that will not be an administrative burden to configure and
maintain SECURE PUBLIC CLOUDS
• Support fully meshed network currently in use Consistent multi-cloud security;
Cloud compliance and and
• If possible, not introduce another point of failure by adding an appliance in front of security governance
firewall to handle routing or dynamic tunnels

To learn more about this case study go to [Link] and search for “Protecting ICS and SCADA Networks with
PAN-OS 8.0”
Dynamic Meshing of IPSec Tunnels: Affordable, effective, and
flexible security
Results with Palo Alto Networks
Operational benefits: By implementing GlobalProtect Cloud Services customer was able to:
○ Build a managed, scalable service to dynamically mesh remote ICS SCADA sites with IPSec/SSL tunnels
○ Removes the complexity from cloud deployment (firewall, portals, and gateways) while allowing for central management through
Panorama
○ Greatly simplify data center architecture
Security
○ Protects both remote business and ICS SCADA sites with a system that allows for automation to reduce operational costs and incident
response fatigue
○ Able to leverage subscriptions as needed based on locations business operations
○ GlobalProtect Cloud Service also includes a cloud-based logging, so all activity is recorded

SECURE PERIMETER
Firewall, Web filtering, IPS, Decryption,
Advanced malware analysis, Zero Trust

SECURE MOBILITY

SECURE PUBLIC CLOUDS


Consistent multi-cloud security;
Cloud compliance and and
security governance
Industrial - Public Cloud
Case Studies Oil and Gas:
SECURE PERIMETER
Customer Profile Firewall, Web filtering, IPS, Decryption,
Advanced malware analysis, Zero Trust
● Warren Rogers Associates pioneered the development of Statistical Inventory
Reconciliation Analysis (SIRA) and Continual Reconciliation for monitoring
underground fuel tanks and associated lines. These methods are certified in
accordance with EPA and used by petroleum marketers for 25 + years. Today,
Warren Rogers specializes in statistical analysis and precision fuel system
diagnostics for the retail petroleum industry. SECURE MOBILITY

Challenges SECURE PUBLIC CLOUDS


Consistent multi-cloud security;
● To safely migrate to a cloud based data center Cloud compliance and and
● To achieve PCI compliance for thousands of remote data collection devices at security governance
fueling stations
● Segmenting traffic and preventing malicious network traffic from penetrating
company’s cloud based corporate data center
● Reduce and simplify administrative task and responsibility
Case Studies Oil and Gas: Cloud Infrastructure

Results with Palo Alto Networks


○ Ensures PCI compliance by guaranteeing that customer cardholder data is not collected on the Warren Rogers network
○ Save hours of administration time with single-point policy management
○ Increases availability with multiple virtualized gateways in the AWS Cloud
○ Preventing cyber threats from infiltrating the cloud-based data center
○ Streamlines onboarding of new customers with uniform security approach SECURE PERIMETER
Firewall, Web filtering, IPS, Decryption,
SECURE PUBLIC CLOUDS Advanced malware analysis, Zero Trust
Consistent multi-cloud security;
Cloud compliance and and
security governance

SECURE MOBILITY

SECURE PUBLIC CLOUDS


Consistent multi-cloud security;
Cloud compliance and and
security governance

“Palo Alto Networks in providing value well beyond addressing our initial need for PCI compliance, and we expect that value
to continue to grow as Warren Rogers pursues new business opportunities.” --Matthew McLimans, Computer Engineer
The Way Forward:
Defending the Mission
Cyber Leadership for the New Battlefront

• Develop 3-5 year cyber plan

• Be agile for changing developments: New


enemies, New conflict targets, New
technology enablers

• Learn from proactive commercial, civilian


government and military leadership

Navigating the Digital Age: The Definitive


Cybersecurity Guide for Directors and
Officers
Tools to Help you Protect your Digital Way of Life
Learn & Evaluate:

• Resource center

• Hands-On-Workshop

• Prevention Posture Assessment

• Security Lifecycle Reviews

• Cyber Ranges

Implement:

• Customer Product Councils

• Best Practice Assessment

• Threat Intelligence: Autofocus, Minemeld


ICS & SCADA Industry Resources
Fuel User Group ([Link]
• Global community of 20,000+ users of Palo Alto Networks
• Online Special Interest Groups (i.e ICS/SCADA) + local user groups
• Local chapter events, user meetings, webinars + other resources

Roundtables: By industry or topic Industry white papers,


Industry sessions: To customers by customers surveys, best practices
[Link]
[Link]/industries
Thank you

[Link]
m

You might also like