Zibb
Subscribe to Control Engineering
FirstLight
Email
Print
Reprint
Learn RSS

Viruses and hackers and worms ... oh my!

Dennis Brandl, BR&L Consulting -- Control Engineering, 11/1/2003

Computer viruses and worms are big topics in the IT world. Recent worms and viruses have infected company LANs (local area networks) and even shut down businesses. While these concerns were already important in the IT environment, they had not been as important in the control system environment. With the increasing use of standard Ethernet and Microsoft operating systems in control systems, infection concerns now have to be considered in control system design and support. As proof of this, several companies have had to stop production because of recent attacks and because of actions taken in response to the attacks.

Part of the modern control system engineer's skill set must include knowledge of how to protect networked control systems. The ISA TR99.01 Technical Report on Security Technologies for Manufacturing and Control systems is a good place to read about technologies you will need to apply.

IT systems generally follow three rules for protection: Defend at the edges, detect in the interior, and protect at each system. Defending at the edges means stopping viruses and worms from entering the local network. This includes establishing firewalls, installing email scanners, closing unused ports, and requiring security access control on any communication through the firewall. Detecting in the interior is scanning of network traffic for suspect and non-normal activity. Detection can also involve scanning server systems to make sure that approved applications, and only the approved applications, are running. Protecting each system uses virus protection software and personnel firewalls or each system. These same rules can be applied to networked control systems with one important exception. The exception is "protecting at each system." Virus protection software requires continual updates of virus and worm electronic signatures. This usually involves downloading identification files and often requires installing software updates. Unfortunately, it is unacceptable to make these changes without extensive testing and revalidation on validated or critical control systems. Updates can occur several times per week, but testing and validation can take weeks, so it is nearly impossible to have current up-to-date virus protection software on validated or critical control systems.

Since we cannot follow the third rule on many networked control systems, the first two rules should be strengthened to take up the load. We can strengthen the first rule by adding firewalls between the control system networks and the rest of the corporate networks. Unprotected control systems are prime targets for infection, and they need multiple layers of protection. Control system networks which connect directly to other business system networks are at risk from viruses and worms and put other corporate systems at risk. Firewalls with limited ports provide one level of protection. Firewalls should be two-way—in addition to protecting control systems from infection by corporate systems, they must protect corporate systems from the control systems. Access control routers can also be added to augment firewall protection. Access control routers allow only specified systems on one side to access systems on the other side. The control system network can also be designed as a Virtual Local Area Network (VLAN) using intelligent switches. VLAN isolates traffic on the VLAN from other LANs, providing an additional measure of protection against broadcast storms and other denial of service (DOS) attacks.

Detection within the control system network should also be applied. This includes using Intrusion Detection Systems on the VLAN.

The cost of adding infection protection to control systems is small and available with off-the-shelf software. Control system professionals need to understand the technologies of infection protection and must work with IT departments to implement secure interfaces between the control networks and the corporate networks.


Author Information
Dennis Brandl is the president of BR&L Consulting, a consulting firm focusing on manufacturing IT solutions, based in Cary, N.C. dbrandl@brlconsulting.com

Email
Print
Reprint
Learn RSS

Talkback

We would love your feedback!

Post a comment

» VIEW ALL TALKBACK THREADS

Related Content

Related Content

 

By This Author

Sponsored Links

 

Advertisement
SPONSORED LINKS

More Content

  • Blogs
  • Discussions
  • Webcasts
  • Podcasts
  • Videos

Blogs

  • Matt Luallen and Steve Hamburg of Encari
    Industrial Cyber Security

    November 28, 2008
    NIST SP 800-82 Guide to Industrial Control Systems Security (Section 6)
    This is the last review of NIST SP 800-82 Guide to Industrial Control Systems Security prior to the public comment expiring on November 30, 2008.&n......
    More
  • Peter Welander
    Pillar to Post: Peter Welander's Blog

    November 26, 2008
    Cornell corners chemical car competition
    For a light bit of reading before your Thanksgiving holiday (assuming you can take the time off) you might want to know that Cornell won the 10th a......
    More
  • View All BlogsRSS

Webcasts

Engineering-driven Ethernet
This Control Engineering Roundtable Webcast will address the engineering issues you should be aware of when exploring the adoption of Ethernet or when looking to expand its use in your facility.

Bridging gaps with wireless
Discover how you can create stronger, flexible and cost-effective wireless connections for your entire plant. Register today!

View All Webcasts
Advertisements





NEWSLETTERS

Get engineering industry news, trends, and business-critical information delivered directly to your inbox!

Click on a title below to learn more.

Weekly News (Weekly)
Process Instrumentation & Sensors (Monthly)
System Integration Monthly (Monthly)
Process & Advanced Control (Monthly)
Machine Control (Monthly)
Information Control (Monthly)
Automation Control (Monthly)
Product Review (Monthly)
Simplified Safety
Fieldbus Facts
PROFInews North American Edition
About Us   |   Advertising Info   |   Site Map   |   Contact Us   |   Useful Sites   |   FREE Subscription   |   RSS
© 2008 Reed Business Information, a division of Reed Elsevier Inc. All rights reserved.
Use of this Web site is subject to its Terms of Use | Privacy Policy
Please visit these other Reed Business sites