Industrial control systems (ICSs) are the backbone of our industrial and critical infrastructures. As organizations connect their ICSs to the Internet, or integrate them with enterprise applications, the ICSs become vulnerable to cyberattack through everything from common malware to advanced persistent threats (APTs). Mitigating the risk of APTs in industrial control systems takes a special kind of firewall.
Industrial control systems (ICSs) are the backbone of our industrial and critical infrastructures. The oil and gas industry, for example, uses control systems to manage refining operations, remotely monitor the pressure and flow of pipelines and control the flow and pathways of gas transmission. Similar systems are used in manufacturing and chemical processing.
While ICSs share the basic constructs of enterprise information technology infrastructures, ICSs are technically, functionally and administratively more complex and unique than their enterprise counterparts.
SURVEY: ‘Advanced persistent threat’ concerns boosting security budgets
For the longest time, critical infrastructure and ICS security was based on two approaches: (1) protection against physical attacks, such as from sabotage within or the destruction and vandalism of physical controls; and (2) through physical segregation of control systems from enterprise networks and the Internet.
ICS security is no longer about restricting physical access to facilities. It is now about blocking cyberthreats and updating antivirus software, as well as monitoring network traffic, which can be difficult if not impossible to perform in legacy control systems.
In today’s highly interconnected world, many of the control systems that operate factories and critical infrastructure are being used in ways that were never intended. It’s not uncommon for enterprise or organizational functions to now rely on being able to access data and systems that interface with ICS networks. For example, customer information systems, asset management systems and geographic information systems (GIS) may draw data from industrial control systems.
As a result of this integration, industrial and critical infrastructures are now at risk from cyberattacks that threaten all enterprises — everything from the “trusted insider” to sophisticated advanced persistent threats (APTs) such as Stuxnet and Flame. Cyberthreats to control systems are continually evolving and growing. Just as in the enterprise and mobile computing environments, cybercriminals continually seek new targets. Industry and infrastructure are now in the crosshairs.
While attempting to mitigate APTs, one must recognize the key attribute of APT actors is stealth. The threat package goes to great lengths, often quite successfully, to masquerade as legitimate control and data monitoring users without generating the predictable network traffic often seen when malware propagates throughout a network. APT attacks are often explicitly developed to evade traditional anti-malware and intrusion detection and prevention solutions. Furthermore, they are uniquely compiled for a specific organization or industry, as was the case with Stuxnet.
It is a quandary for organizations with ICSs that traditional approaches for the detection of malicious behavior — such as monitoring network traffic and inspecting protocol specifications — cannot effectively and efficiently address process related threats in control systems. As with many breaches, a threat begins when an attacker gains user access rights and performs “supposed” legitimate actions that are actually intended to alter and/or disrupt processes in the control system(s). These process-related threats also include unintended mistakes by “trusted insiders” such as inserting a highly out-of-band value for a device parameter which ultimately causes process failure or worse.
Furthermore, many enterprise IT security technologies can adversely affect the operation of ICSs, such as having components freeze up while using port scanning tools or block encryption slowing down control system operation — an inadvertent basic denial of service (DoS) incident.
According to Francis Cianfrocca, CEO of Bayshore Networks, “APT attacks are both insidious and surreptitious. They typically start from email (spear-phishing) combined with XSS (Cross Site Scripting) or CSRF (Cross Site Request Forgery) attacks and proceed by exploiting known or unknown errors and vulnerabilities in applications, servers or network architectures. APT attacks are hard to detect because they typically look like normal network traffic. Unfortunately, many of today’s firewalls that focus on application recognition have no solutions for APTs.”
Cianfrocca says that APT firewalling is fundamentally different because it aims to detect threats that masquerade as legitimate traffic. The practice focuses on three critical areas: signatures, heuristics and proactive profiling. Of these, the most important approach is heuristics where the process(es) seeks to automatically characterize application behavior on numerous dimensions for the purpose of establishing a behavioral baseline. As a result, deviations from the baseline can be detected, reported and potentially blocked.
According to Cianfrocca, “we see a need to embed Layer-7 Application Layer policy enforcement directly into the network infrastructure, alongside and in addition to existing Layer-3 Network Layer and Layer-4 Transport Layer controls.” To establish a level of visibility and control within the ICS environment requires a new kind of firewall or gateway device that is capable of dissecting all of the many protocols used in ICSs (including Modbus, OPC, DNP3, BacNet, Profibus, IEC 61850, and many others).
Bayshore Networks’ SCADA Firewall is an internal application firewall that is designed to protect ICS applications from malicious attacks. The firewall is said to block APT and insider threats, mitigate vulnerabilities in SCADA industrial control systems and protect mission-critical applications.
The Bayshore approach addresses the fact that APT attacks with privilege escalation operate through application access that, to many network monitors, appear to be fully normal in terms of 1) network source addresses; 2) protocol syntax correctness; and 3) authentication/authorization. In other words, this means that many of the existing network monitoring and firewall products, including next-generation firewalls, are unable to detect and characterize APTs directed at ICSs.
As an APT mitigation tool, the Bayshore SCADA Firewall employs intelligent analytics based on heuristic baselines and behavioral analyses. Applied cross-organizationally within enterprise and ICS networks, the Bayshore firewall is said to improve the ability to predict, detect and defend against attacks in real time.
This firewall can be deployed within enterprise and control system networks, integrated with core IP switches and routers and/or field-deployed in close proximity to industrial equipment. This approach can be thought of as a secure network fabric where the firewall would do much more than control access to control systems based on IP addresses, ports and session authenticators. It also enforces fine-grained policy on the actual data values being sent to and received from control system equipment.
Brian Musthaler is a principal consultant with Essential Solutions Corporation. You can write to him at Bmusthaler@essential-iws.com.
______________________________________________________________
About Essential Solutions Corp:
Essential Solutions researches the practical value of information technology, and how it can make individual workers and entire organizations more productive. Essential Solutions offers consulting services to computer industry and corporate clients to help define and fulfill the potential of IT.




