White Paper | Blueprint for Securing Industrial Control Systems

White Paper | Blueprint for Securing Industrial Control Systems

Learn how to secure industrial control systems (ICS) and critical infrastructure using the Purdue Model. Explore best practices for protecting IT and OT environments, strengthening network segmentation, reducing ransomware risk, and improving industrial cyber security resilience.

White Paper | Blueprint for Securing Industrial Control Systems

BLUEPRINT FOR SECURING INDUSTRIAL CONTROL SYSTEMS

2BLUEPRINT FOR SECURING INDUSTRIAL CONTROL SYSTEMS

Contents Preface 3

Overview 3

The Purdue Zones 4 IT Zone 4 OT Manufacturing Zone 4 Securing ICS Environments 5

Level 5 & 4: The Enterprise IT Network and Business Logistics Systems 6 Industry Example Incident: 6 Recommended Security Controls: 7

Level 3.5: The Industrial DMZ 7 Industry Example Incident: 7 Recommended Security Controls: 8

Level 3: Manufacturing Operations Systems 8 Recommended Security Controls: 9

Level 2 and 1: Securing Communications Between Levels 11 Industry Example Incident: 11 Recommended Security Controls: 12

Level 0: Physical Processes 13 Recommended Security Controls: 14

Architecture and Components Summary 14 1. ICS Discovery Engine 14 2. Firewalls 15 3. Security Management Server 16 4. IoT Cloud Services 16

5 Key Takeaways 16

3BLUEPRINT FOR SECURING INDUSTRIAL CONTROL SYSTEMS

Preface The frequency of cyberattacks targeting Critical Infrastructure and Industrial Control Systems (ICS) continues to rise, posing a significant threat to vital operations. The FBI’s report indicates that critical infrastructure faced one-third of all ransomware attacks in 2022, emphasizing the urgency for robust security solutions. The reason behind this surge is the high value attached to critical infrastructure, as attackers know that these entities cannot risk being locked out of their mission-critical applications and are more likely to pay the ransom.

The recent case of the Taiwan Semiconductor Manufacturing Company (TSMC) highlights the severity of the issue, with the LockBit ransomware group claiming responsibility for hacking their IT hardware supplier, Kinmax Technology, demanding an unprecedented $70 million ransom1. This is just one among several instances of such attacks making headlines, indicating the growing threat landscape faced by critical infrastructure globally.

This whitepaper is written as a guide to securing networks with Critical Infrastructure in order to prevent similar catastrophes from happening again.

Overview To secure Critical Infrastructure environments, it is vital to keep a holistic view and look at every part of the network, both the IT (Information Technology) and OT (Operational Technology) parts, investigate the systems and processes in each zone, analyze the attack vectors and risk, and provide recommended security controls.

To do so, we use the Purdue model, which was adopted from the Purdue Enterprise Reference Architecture (PERA) model by ISA-99 and used as a concept model for Computer Integrated Manufacturing (CIM). [3] It is an industry adopted reference model that shows the interconnections and interdependencies of all of the main components of a typical Industrial Control System, dividing the ICS architecture into 3 zones and subdividing these zones into 6 levels.

4BLUEPRINT FOR SECURING INDUSTRIAL CONTROL SYSTEMS

The Purdue Zones The two major zones are the Enterprise and Manufacturing Zones, also referred to as the IT and OT networks. In the Purdue model, these two major zones are separated by the third zone, the Industrial DMZ, where the intent is to prevent direct communication between IT and OT systems. This adds a layer of separation to the overall architecture so that if something were to compromise a system in the DMZ, then the compromise could be contained within the DMZ, ensuring production processes continue to operate normally.

IT Zone Level 5: Enterprise Network Technically not part of ICS, the enterprise zone relies on connectivity with the ICS networks to feed the data that drives the business decisions.

Level 4: Business Logistics Systems Enterprise Resource Planning (ERP) systems manage the business-related activities of the manufacturing operation. It establishes the basic plant production schedule, material use, shipping and inventory levels.

Industrial DMZ: The interconnect zone between IT and OT systems, this zone typically holds a jump host for secure remote access to ICS systems.

OT Manufacturing Zone Level 3: Manufacturing Operations Systems The purpose of level 3 systems is to manage production workflows to produce the desired products. This includes batch management; manufacturing execution/operations management systems (MES/MOMS); laboratory, engineering stations, maintenance and plant performance management systems; data historians and related middleware.

Level 2: Control Systems Level 2 systems supervise, monitor and control the physical processes. This includes real-time controls and software; Distributed Control System (DCS), human machine interface (HMI); supervisory and data acquisition (SCADA) software.

Level 1: Intelligent Devices Level 1 systems sense and manipulate the physical processes. This includes process sensors, analyzers, actuators and related instrumentation such as PLCs, RTUs or IEDs.

Level 0: Physical Process Level 0 systems define the actual physical processes.

IT

Enterprise Zone

Industrial DMZ OT

L5 Enterprise Network

Business Logistics Systems

Manufacturing Operations System

Control Systems

Intelligent Devices

Physical Process

L4

L3

L2

L1

L0

5BLUEPRINT FOR SECURING INDUSTRIAL CONTROL SYSTEMS

Securing ICS Environments Securing ICS environments requires understanding the unique assets, functions, and network flows within each layer and how those zones connect and communicate with connecting layers. This helps describe possible attack vectors, security risks and recommended security controls to defend and increase visibility of the overall security posture.

6BLUEPRINT FOR SECURING INDUSTRIAL CONTROL SYSTEMS

In our example high-level representation of a typical IT/OT environment notice firewalls segment north- south connections between each layer. Also, note the discovery engine in the level 3 operations center.

Specialized discovery engines constantly monitor industrial control system (ICS/SCADA) network traffic and generate alerts for anomalous network behavior that indicates a malicious presence or changes that have the potential to disrupt industrial processes. Firewalls function as enforcement points, applying access control based on the principles of zero trust. This access control is determined by the asset information received from the discovery engines.

Also, a complete multi-layered cyber defense for ICS includes device-level security controls to enforce east-west connections.

Level 5 & 4: The Enterprise IT Network and Business Logistics Systems Industry Example Incident: In June 2019, an aircraft parts manufacturer called ASCO Industries fell victim to a ransomware attack. According to reports, most of the company’s systems, based in Zaventem, Belgium, were affected by the infection, leading to an entire month of inactivity in the IT infrastructure of all ASCO plants. This caused more than a thousand out of the 1,500 employees at ASCO’s headquarters in Belgium to be sent back to their homes, since conditions were not optimal to maintain operations.

Systems and Processes: This is the IT part of the network where the users, Data Center and cloud access are located. This is also the part of the organization where the Internet break-out is found.

Attack Vectors: Typical IT attack vectors, such as spear phishing via Email and Ransomware against users and endpoints.

Risks: Infrastructure attacks are a relevant and imminent threat to any organization. Many of the recent attacks on OT and ICS networks were found to be based on IT attack vectors.

7BLUEPRINT FOR SECURING INDUSTRIAL CONTROL SYSTEMS

Recommended Security Controls: As this is the IT network where the users reside and this is where the internet egress point is located, it is recommended to enable the most advanced end user protections to prevent sophisticated zero-day and social engineering attacks. This includes sandboxing with Content Disarm & Reconstruction to sanitize files as well as zero-day phishing prevention.

In addition, deploy signature-based protections such as IPS, antivirus, anti-bot and DNS security to prevent malware and detect attempts to move laterally within networks. Also enforce least privileged access and ensure safe use of web and applications with firewall, application and URL filtering and HTTPS inspection.

Additional endpoint security protections installed on user laptops will protect users when they leave the corporate headquarters while they work from home or remotely.

Finally, it is very important to secure public cloud services, as these are usually connected to corporate resources and therefore also a potential attack vector.

Tie this all together with unified security policy and threat management to ensure consistent policy and provide the greatest visibility across the entire organization.

Level 3.5: The Industrial DMZ Industry Example Incident: Thousands of critical energy and water systems exposed online for anyone to exploit.

Systems and Processes: Typically, this part of the network is used for technicians’ remote access connections. They can work for the company or the inbound connections that originate from the supplier of the equipment used in the OT network.

Attack Vectors: • Systems that are exposed directly without VPN technology can easily be exploited • Malware entering the organization’s OT network over a remote access connection • Denial of Service attacks on the remote access gateway

Risks: In some cases, OT equipment suppliers demand direct IP connectivity to OT equipment in Layer 2 and 1 for support, monitoring and maintenance. This can be a hazardous operation if there are no adequate security controls in place to properly inspect this traffic. If the security standards of a third party connecting straight into the OT environment are subpar, then this type of architecture could potentially lead to infections in the most critical part of the network.

8BLUEPRINT FOR SECURING INDUSTRIAL CONTROL SYSTEMS

Recommended Security Controls: To ensure maximum availability of the remote access gateway, allowing for third parties to remotely manage and monitor the OT equipment, it is vital to protect the gateway with an anti-DDoS solution (preferably on premises and cloud-based). In this blueprint, there is a jump server in the industrial DMZ. The VPN remote access server (RAS) sessions are terminated on the perimeter gateway in level 5. The gateway terminates VPN traffic, scans it for malware and only allows RDP traffic to the jump host. The jump host is then used to connect to operator workstations in level 2 for remote maintenance work. This approach is much safer than allowing inbound L3 VPN connections from the internet straight into level 2 and dramatically reduces the risk of the OT network becoming infected due to unsafe RAS connections originating from third parties. The jump server itself is protected by the gateway, which will only allow inbound RDP and has the necessary security controls enabled such as IPS, Anti-bot and application control.

Level 3: Manufacturing Operations Systems Industry Example Incident: An unnamed petrochemical plant in Saudi Arabia was hit by triton malware in the summer of 2017.

The hackers had deployed malicious software, or malware, that let them take over the plant’s safety instrumented systems. These physical controllers and their associated software are the last line of defense against life-threatening disasters. They are supposed to kick in if they detect dangerous conditions, returning processes to safe levels or shutting them down altogether by triggering things like shutoff valves and pressure-release mechanisms. The malware made it possible to take over these systems remotely. Had the intruders disabled or tampered with them, and then used other software to make equipment at the plant malfunction, the consequences could have been catastrophic.

Systems and Processes: In level 3, the manufacturing and operations systems are found, such as SCADA servers, Historian, Engineering stations, as well as an ICS Discovery Engine server (on a dedicated VLAN depicted on the right hand side of Level 3).

This is the place where operators are monitoring the industrial process 24/7 and adjusting it when required. Operators in this segment of the network can access the PLCs and RTUs in level 1. This is what the control room typically looks like:

Attack Vectors: • Ransomware on Endpoints, machines being abused for cryptocurrency mining, bot infections,

phishing via Email. • Bot infections of the operator workstation could lead to sabotage of the industrial process. • Unsecured USB ports.

9BLUEPRINT FOR SECURING INDUSTRIAL CONTROL SYSTEMS

Risks: • Unwanted modifications to the industrial process • Sabotage • Industrial espionage • Unpatched monitoring systems • Lack of visibility into what kind of equipment is in place and if it is running vulnerable firmware

Recommended Security Controls: The firewall in level 3 segments the IT from the OT part of the network and micro-segments level 3 itself. The plant management system, the operators, and the historian should all go in separate VLANs, while the gateway controls who is allowed to talk to who. In this area of the network, there is no need for ruggedized hardware. Regular 19’ racks are used here.

Advanced Discovery and Threat Prevention • Anti-bot

• IPS (typically used as a virtual patch to protect the monitoring stations of the operators)

• Sandboxing technologies to prevent Zero-day attacks (Check Point SandBlast)

• An application control security policy that only allows specific authorized commands to be sent from the operator workstation to PLCs.

• The use of Identity Awareness can add an extra layer of security to the policy by only allowing authenticated users, i.e. operators, to send specific commands to devices in Level 2.

• Encryption of the control traffic between operators in L3 and PLCs in L2 using IPsec to prevent eavesdropping and traffic replay attacks.

• Endpoint protection including Port Protection

10BLUEPRINT FOR SECURING INDUSTRIAL CONTROL SYSTEMS

This screenshot shows the kind of information that can automatically be harvested about devices in levels 2 to 1.

The second screenshot shows a graphical representation of where the discovered devices are situated according to the Purdue model.

11BLUEPRINT FOR SECURING INDUSTRIAL CONTROL SYSTEMS

Level 2 and 1: Securing Communications Between Levels Industry Example Incident: July 2nd, 2019: Schneider Electric released a CVE describing vulnerabilities in their Modicon controllers. Successful exploitation of this vulnerability could result in a denial-of-service condition. The CVE states the following: To mitigate risks associated with this Modbus vulnerability, users should immediately set up network segmentation and implement a firewall to block all unauthorized access to Port 502/TCP.

Systems and Processes: The communication between level 1 and 2 is at the heart of the ICS network. This is where HMIs and PLCs are communicating using SCADA protocols and engineering traffic is sent to PLCs. While offering a security solution, we have to take into consideration latency issues, uptime of production equipment, processes and the sensitivity to any change which might affect the production.

Therefore, for most organizations, the most desirable security architecture is passive and non-intrusive.

It is possible to use the gateway that separates Level 1 and Level 2 in mirror port mode and be passively listening and communicating back to the discovery engine in Level 3. However, from a security point of view, it is strongly recommended to segment Level 1 (and Level 0) from Level 2 by connecting them to different interfaces on the gateway that connects to the upper level (example A).

In case Level 2, 1 and 0 are all located in a remote facility, then the ruggedized gateway can communicate with the level 3 over IPsec VPN, MPLS, cellular or broadband. It is possible to deploy these gateways in High Availability as well and have them take care of dynamic routing.

In case of a single facility with multiple production lines, it is recommended to micro-segment level 2 and 1 with a gateway per production line as depicted in the first drawing above.

12BLUEPRINT FOR SECURING INDUSTRIAL CONTROL SYSTEMS

Attack Vectors: • Denial of Service exploitation on HMIs, RTUs, IEDs or PLCs • Exploitation of known vulnerabilities of HMIs, RTUs, IEDs or PLCs • The use of unencrypted protocols leaves this segment vulnerable to sniffing, allowing

hackers to figure out passwords and use traffic replay attacks with modified payload data • Some intelligent devices have hardcoded passwords, and some admins do not even bother

to change the passwords of intelligent devices, even if it is possible. • Patching systems in this layer is often not done as the main focus is uptime, instead of

security leaving both the application and the OS vulnerable • Vulnerable machines in level 1 are often targets for hackers to use as crypto miners or

for ransomware • Malware able to send malicious commands to a PLC jeopardizing the industrial process

Risks: • Unwanted modifications to the industrial process • Sabotage • Industrial espionage

Recommended Security Controls: An inline gateway secures the communication between the local operator workstation and the different PLCs in different production lines. This is the recommended architecture as the gateway is not only able to detect, but also block unwanted traffic.

A firewall is connected to a switch via a mirror port (SPAN). From a visibility point of view, there is no difference between the previous example and this one. From a security point of view, there is. This gateway is unable to block unwanted traffic, it can only alert. A significant number of companies still prefer this approach because in OT environments, blocking legitimate traffic is something that needs to be avoided at all cost and the chance of a false positive due to a configuration mistake or human error is still a possibility.

• Use gateways running IPS to protect vulnerable systems as a virtual patch instead of patching the actual systems, causing downtime. A screenshot of such configuration is shown below:

13BLUEPRINT FOR SECURING INDUSTRIAL CONTROL SYSTEMS

• The communication between level 2 and 3 can be encrypted using IPsec to protect sniffing and replay attacks.

• A security gateway can be connected to a mirror (SPAN) port on a switch in this level, operating as a sensor, feeding information about asset discovery and anomaly detection to the discovery engine.

• Customers willing to consider inline security gateways in level 1 could separate local operator workstations and HMIs from PLCs and RTUs ensuring no unauthorized commands can be sent to them. When using a gateway connected to a mirror port, this can also be detected, but not prevented. An example of such an application control policy is shown below:

• Endpoint security can be considered on machines with supported operating systems. • Appropriate L2 security on switches • Consider the use of an out-of-band network solely used for management traffic, signature updates

and firmware updates of equipment in this level. Only SCADA protocols should be seen in Level 1. • Do not allow remote technicians to directly connect to the level 1 network, prefer the use of a jump

host in the DMZ in level 3.5: When unmanaged assets connect to this network, the security posture is unknown and can therefore not be trusted.

Level 0: Physical Processes

Systems and Processes: This is where the physical process is taking place. Here we find field devices that communicate with intelligent devices in level 1. The devices in level 0 are not intelligent; field devices can be valves, sensors, actuators and so forth. Some of them are active like a valve, some of them are passive like a temperature or pressure sensor.

Attack Vectors: As long as the field devices in level 0 are directly connected to the PLCs or RTUs in level 1 using analog links, the likelihood of a cyber-breach occurring here is fairly low. In case something would go wrong, it would most likely be due to a physical security breach. In case the field devices are connected to level 1 using IP and switches are involved, security controls between the 2 levels are recommended. The purpose here would be to have an additional pair of eyes. For example: if a PLC receives an instruction from level 3 and sends it down to a field device in level 0, there should be consistency.

Risk: Disruption or modification of the physical process.

14BLUEPRINT FOR SECURING INDUSTRIAL CONTROL SYSTEMS

Recommended Security Controls: It is recommended to use point to point connections between the intelligent devices in level 1 and the field devices in level 0. In case the communication between level 1 and level 0 is done over IP, prefer point to point connections. If point-to-point links are not possible and Ethernet switches are used in level 0, ensure the appropriate L2 security is enforced: admin down of all unused switch ports, MAC authentication on used switch ports, consider the use of additional security gateways between Level 1 and Level 0. The use of a trusted baseline policy with application control can warn an admin if an unknown command is sent to a field device.

Architecture and Components Summary

1. ICS Discovery Engine: The Power of Network Awareness Incorporating a specialized third-party discovery engine brings a transformative level of network asset management and anomaly detection to your ICS (Industrial Control Systems) environment. This integration ensures swift and precise situational awareness, empowering you with real-time alerts that matter.

15BLUEPRINT FOR SECURING INDUSTRIAL CONTROL SYSTEMS

When seamlessly integrated with Check Point firewalls through a robust API, our ICS Discovery Engine becomes your network's silent guardian. It goes beyond mere detection, taking a proactive stance. Here's how it works:

1. Learning/Understanding: The discovery engine learns your network's topology and communication patterns. It meticulously models your network's unique characteristics, creating a finely detailed behavioral baseline that defines what constitutes legitimate traffic.

2. Insights: Armed with this knowledge, the system becomes your secret weapon. It not only spots anomalies but provides you with vital insights into network hygiene, configuration vulnerabilities, and asset weaknesses.

3. Transition to Operational Mode: Following a thorough learning period, the system can shift into an operational mode. Any deviation from the established baseline triggers immediate alerts.

4. Actionable Alerts: Each notification is actionable, crystal clear, and context rich. This means that your security and control teams gain rapid situational awareness, enabling them to respond to potential or actual process disruptions efficiently.

2. Firewalls In the previous example, the Check Point firewall operates as a sensor for SCADA device discovery and anomaly detection in the subnet/broadcast domain it resides in. This information is then sent to the discovery engine.

Multiple networks or VLANs can be monitored by spanning the traffic to a mirror port on this gateway. Multiple PLCs in different VLANs can be connected via a switch to the gateway using an 802.1q trunk. The gateway can apply policies between the VLANs and can sniff traffic in all VLANs for device discovery. The security gateways serve multiple purposes, depending on the way they are deployed.

When inline, firewalls can segment the different zones or even microsegment within one zone. Communications between the different segments is accomplished using firewall access rules, intrusion prevention (IPS) and application filtering on specific SCADA commands and parameters. Logs are presented in the management server.

Firewalls can also operate in passive modes when connected to a mirror port with one single interface. This mode is passive, non-intrusive and easy to deploy. However, the gateway can neither take action nor block unwanted traffic.

16BLUEPRINT FOR SECURING INDUSTRIAL CONTROL SYSTEMS

3. Security Management Server The Security Management server manages the security policies to all firewalls in the network. A dedicated IoT layer in the security policy can be added to secure the ICS environment.

When integrated with the Discovery Engine, objects identified by the Discovery Engine are available to security admins for policy creation and also enrich the security logs, providing better visibility of the OT environment.

4. IoT Cloud Services The Check Point IoT Protect cloud service provides enables organizations to have a comprehensive, holistic security solution for connected devices in any organization network, adapting protections to any IoT or OT device across smart-office, smart-building, medical and industrial environments.

The IoT Protect cloud service connects Discovery Engines with Check Point security management and Check Point firewalls in the OT environment. With features such as deep ICS asset visibility, tailored discovery engines for precise device analysis, and granular device fingerprints encompassing protocol, brand, model, and more, this solution provides a more robust assessment of risk. Detecting anomalies through behavioral baselines, IoT Protect exposes risk indicators. It also provides intuitive Zero Trust segmentation, dynamic grouping for rule creation, and remote access management. Virtually patch unpatched firmware, prevent unauthorized access, and stay ahead of OT-targeted malware using Check Point’s ThreatCloud for real-time threat intelligence.

5 Key Takeaways Ensure proper segmentation is in place. Remember that this is not about having a lot of different VLANs and / or subnets and then just enabling routing between them. It is about having the correct security controls in place and enabled between the segments. To recap: Sandboxing technologies at the perimeter (level 5), including SSL/TLS inspection. On internal segments (level 4 and below), Firewall, IPS, Identity Awareness and Application Control should be the minimum. Sandboxing is vital to protect against zero- day attacks, a common attack vector used by hackers to target critical infrastructure.

1. Threat Prevention is vital. Detection only informs you when the damage has already been done.

2. The IPS blade contains several signatures that are specifically aimed at securing ICS environments.

17BLUEPRINT FOR SECURING INDUSTRIAL CONTROL SYSTEMS

Worldwide Headquarters 5 Shlomo Kaplan Street, Tel Aviv 6789159, Israel | Tel: +972-3-753-4599

U.S. Headquarters 959 Skyway Road, Suite 300, San Carlos, CA 94070 | Tel: 1-800-429-4391

www.checkpoint.com

© 2023 Check Point Software Technologies Ltd. All rights reserved.

3. Enable IPS in prevent mode wherever possible and make sure to specifically monitor alerts for these signatures.

References [1] The Norsk Hydro cyber attack is about money, not war, https://www.wired.co.uk/article/norsk-hydro-cyber-attack [2] Industrial Cybersecurity, https://subscription.packtpub.com/book/networking_and_servers/9781788395151/1/ch01lvl1sec10/the-

purdue-model-for-industrial-control-systems [4] What was that Purdue Model stuff, anyway? http://scadamag.infracritical.com/index.php/2018/03/01/purdue-model-history/

4. Application control supports several SCADA protocols up to command-level and even parameter-level. This allows for the creation of a security policy that authorizes only specific commands to be sent to PLCs and deny everything else.

5. Visibility is key to security. Ensure there is enough manpower to monitor the environment. Tools like Check Point SmartEvent, a 3rd party Discovery Engine and a dedicated SIEM can reveal a lot of information that may otherwise go unnoticed.

Bookmark 1 Zero Trust and Why You Should Embrace It Preface Overview The Purdue Zones IT Zone OT Manufacturing Zone

Securing ICS Environments Level 5 & 4: The Enterprise IT Network and Business Logistics Systems Industry Example Incident: Recommended Security Controls:

Level 3.5: The Industrial DMZ Industry Example Incident: Recommended Security Controls:

Level 3: Manufacturing Operations Systems Recommended Security Controls:

Level 2 and 1: Securing Communications Between Levels Industry Example Incident: Recommended Security Controls:

Level 0: Physical Processes Recommended Security Controls:

Architecture and Components Summary 1. ICS Discovery Engine 2. Firewalls 3. Security Management Server 4. IoT Cloud Services

5 Key Takeaways


Item Type: pdf