Engineering-Grade OT Security by Andrew Ginter

THE SUMMARYAI-generated

Key Concepts

  • Operational Technology (OT) Security
  • Cyberinformed Engineering (CIE)
  • Pivoting Attacks
  • Network Engineering
  • Unidirectional Gateways
  • Risk Assessment (Consequence, Likelihood, Credibility)
  • Engineering Change Control
  • Security Process Hazard Analysis (PHA) Review
  • Design Basis Threat

Introduction

The webinar focuses on operational technology (OT) security, specifically addressing how to build secure systems from the ground up using a cyberinformed engineering approach. Andrew Ginter from Waterfall Security Solutions leads the discussion, emphasizing the importance of rethinking system design to eliminate entire classes of threats rather than just patching vulnerabilities.

What is Operational Technology (OT)?

  • OT refers to the computers that control physical processes, such as pipelines, water treatment plants, and critical infrastructure.
  • Modern automation relies heavily on embedded computers; even simple components like pumps and valves contain CPUs.
  • OT networks share similarities with business networks (IT), often using the same technologies like Windows.
  • However, the application and priorities differ significantly.

Differences Between IT and OT Security

| Feature | IT Networks (Business Networks) | OT Networks (Automation Networks) | | ---------------- | ------------------------------------------------------------- | ------------------------------------------------------------- | | Primary Asset | Information | Physical Asset (e.g., pipeline, refinery) | | Security Goal | Prevent cyber espionage (stealing information) | Prevent sabotage (damage to physical assets) | | Threat | Espionage | Sabotage | | Information Role | Asset | Threat | | Security Focus | Confidentiality, Integrity, Availability of Information (CIA) | Safe Operations, Reliable Operations, Efficient Operations |

  • In OT, the goal is to ensure safe and reliable operations, even at the expense of efficiency.
  • There's a natural tension between enterprise security teams (focused on constant change and patching) and engineering teams (focused on controlling change to manage risk).
  • Engineering change control is crucial in OT environments to prevent errors and emissions that can lead to catastrophic failures.

Example: Water Treatment Plant

  • The City of Detroit's water treatment system, controlled by operators monitoring screens, serves as an example of a real-world OT environment.
  • Operators visualize data from thousands of data points, drilling down to identify and address issues like device calibration problems.
  • Human oversight is often legally required for safety-critical processes.

The Purdue Model (IEC 62443)

  • The Purdue model, also known as the IEC 62443 model, is a common framework for organizing industrial networks.
  • It divides the network into levels:
    • Level 0: Physical process (pumps, valves)
    • Level 1: Computers connected to physical assets (PLCs, RTUs, protective relays, safety instrumented systems)
    • Level 2: Human-machine interface (HMI) for operator control
    • Level 3: Infrastructure shared across control systems
    • Level 4: Business network (IT)
    • Level 5: Internet
    • Level 6: Cloud (vendor services)

Threat Landscape

  • Waterfall's threat report identifies 76 publicly recorded attacks with physical consequences in heavy industry and critical infrastructure in the past year.
  • These attacks affected over a thousand sites, primarily due to ransomware.
  • A growing number of attacks are attributed to nation-states (six in the past year, compared to zero to two in previous years).
  • Ransomware typically targets physical operations randomly, while nation-states and activists deliberately target operations to cause physical consequences.

Modern Attack Pattern: Pivoting

  • The modern attack pattern involves pivoting:
    1. Compromise a machine on the enterprise network (IT) through stolen credentials or malicious links.
    2. Install a remote access Trojan (RAT) to establish a connection with a command and control center.
    3. Use the compromised machine to attack other equipment, pivoting through the network until reaching a valuable asset.
  • Today's pervasive threat is nation-state-grade pivoting attacks.

Cyberinformed Engineering (CIE)

  • CIE is a new initiative funded by the Department of Energy and carried out by Idaho National Laboratory.
  • It represents a convergence of engineering and cybersecurity principles.
  • Example: Protecting technicians working near boilers in a coal-fired power plant.
    • Traditional approach: Longer passwords on computers controlling furnaces.
    • CIE approach: Prioritize mechanical valves that relieve steam pressure, preventing explosions, supplemented by strong cybersecurity measures.
  • CIE emphasizes the importance of both cybersecurity and engineering tools, recognizing that engineering opportunities have been neglected.
  • CIE encompasses cyber-relevant elements of safety engineering, protection engineering, automation engineering, process engineering, network engineering, and cybersecurity.

Security PHA Review

  • Security PHA (Process Hazard Analysis) review is an example of using engineering tools within CIE.
  • It involves adding a column to existing PHA spreadsheets to identify trigger conditions that can be caused by cyberattacks.
  • If a trigger can be caused by a cyberattack, the next step is to assess whether all mitigations can be subverted by a cyberattack.
  • If all mitigations are subvertible, stronger cybersecurity measures or electromechanical/analog mitigations are needed.
  • Example mitigations: Spring-loaded valves, centrifugal force switches.

Network Engineering and Consequence Boundaries

  • Network engineering is crucial for preventing pivoting attacks at consequence boundaries (connections between networks with dramatically different worst-case consequences of compromise).
  • Example: Predictive maintenance for steam turbines.
    • Connect vibration sensors to the IT network or directly to the internet, not the control network.
    • Even if the sensors are compromised, attackers cannot pivot into the control system.
    • The worst-case scenario is a business loss (suboptimal maintenance), which can be covered by insurance.

Unidirectional Gateways

  • Unidirectional gateways are a key network engineering technology for preventing attacks from pivoting through consequence boundaries.
  • They use hardware (fiber optic laser transmitter and receiver) to physically allow information flow in only one direction (from the industrial network to the outside world).
  • Software replicates servers, sending snapshots of data through the gateway to an enterprise version of the server.
  • This allows data sharing without exposing the live system to attacks.

Risk Assessment

  • Risk is the language of business.
  • The classic formula (Risk = Consequence x Likelihood) is insufficient for high-impact, low-frequency attacks.
  • The concept of "credible threat" needs to be added.
  • Credibility is defined as what it is reasonable to believe about threats, attacks, and consequences.
  • Standards bodies are moving towards incorporating the concept of credibility into risk assessments.
  • Design Basis Threat: Defines the threats that a security program is designed to defeat with a high degree of confidence.

Cyber Insurance

  • Cyber insurance is changing.
  • It is no longer possible to buy unlimited general damages coverage that includes cyber risks.
  • Cyber coverage is now typically limited to a specific amount (e.g., 200 million pounds by Lloyd's).
  • This change is driven by the increasing risk and cost of cyberattacks, as demonstrated by the 2017 NPETA attack.

Security Programs for Different Scenarios

  • Small Shoe Factory:
    • Robots are physically unable to harm people if safety measures are in place (yellow tape, infrared barriers, physical power switches).
    • The worst-case scenario is a ransomware attack causing downtime and financial loss.
    • The right security program is to buy insurance and follow the insurer's recommendations.
  • Large Automobile Factory:
    • A shutdown can result in significant financial losses (e.g., Honda's $300-400 million loss).
    • Even without safety risks, the cost of a stronger security program is less than the potential loss.
    • Network engineering or other electromechanical engineering should be implemented to prevent shutdowns.
  • Small Water Treatment Plant:
    • Engineering protections are crucial (e.g., large finished water reservoir, backup sampling regime).
    • These measures provide a buffer against tampering and ensure water quality.

How Much Security is Enough?

  • If all consequences are acceptable, protect physical assets the same way as the IT network, buy insurance, and follow the insurer's demands.
  • If there are unacceptable consequences, consider the credible threats.
  • The pervasive threat is nation-state-level ransomware.
  • Defend against the pervasive threat and deploy physical measures and network engineering as much as practical.
  • Implement a cyber near-miss program to learn from errors and emissions.

Conclusion

When public safety is at risk, it is reasonable to protect it thoroughly using deterministic, engineering-style protections wherever practical. Critical networks should be designed to carry a specified threat load until the next opportunity to upgrade, with a large margin for error. Network engineering is a key tool for achieving this. Due care, defined as what any other reasonable person would have done in similar circumstances, is the standard that will be applied in legal proceedings following a disaster.

AI summaries can miss context or contain errors. Check important details against the original video.

Go a little deeper.

Have a question about this video? Load its transcript to open the video chat.