Zibb
Subscribe to Control Engineering
FirstLight
Email
Print
Reprint
Learn RSS

Goodbye Windows NT

Dennis Brandl, BR&L Consulting -- Control Engineering, 12/1/2006

Jan. 1, 2007, is a significant day for automation and control systems. It is the day that Microsoft drops all support for Windows NT 4.0.

Microsoft stopped general support (security or bug fixes) of Windows NT 4.0 in January 2005, but there was a pay-per-incident plan available until December 31, 2006. As of January 1st, there will be no more support, and this is a problem for automation systems that have not yet reached their end of life.

The typical automation system will have a useful life of 15 to 20 years—much longer than the typical nine years of computer operating system support. With no support, Windows NT systems will become increasingly vulnerable to virus and worm attacks, exploits, rootkits, and server failures that require expertise and assistance to restore operations.

While targeted viruses and worms will gradually disappear, many recent attacks have been backward compatible and affect current and older versions of Windows and applications.

One approach to addressing the loss of support is to follow the “I AM FEARLESS” approach. This is short for Isolate, Apply Major patches, Fix, Enhance, Abandon, or Retire Legacy Shopfloor Systems. (Thanks to Jeff Lucatorto of Merck for the acronym.) I AM FEARLESS provides a quick reminder of the remediation approaches that should be taken for Windows NT phase-out.

Short-term solution: isolate

“Isolation,” which means disconnecting the system from the corporate network, is only a short-term solution. This does not guard against server failure, but does provide time to implement long-term solutions. “Applying major patches” requires obtaining the last set of patches for Windows NT 4.0 (Windows NT Rollup Security Path 6a, from October 2006), testing the patches, and applying them to the production systems. This will provide some security and additional stability, but is still not a long-term solution.

“Fixing the problem” is a long-term solution. It requires updating Windows NT and applications to newer supported versions. This is often the lowest cost alternative, but it is not always possible, especially when the applications are no longer available or there is no upgrade path. When a fix is not possible, then enhancing is the next best choice.

Long-term options

“Enhancing the system” means to update Windows NT and the applications to new versions with enhanced user functionality. Many users of older systems can justify the expense of adding new functionality at the same time the system is updated. Enhancements are often possible when there is an application upgrade path. If no upgrade path exists, then the choices are to abandon the system or replace it.

“Abandon” means to retire the server and the application. While the application was probably essential when it was initially installed, often other, newer applications duplicate the older application's functionality, but do not have the functions turned on. The older applications were kept in place because it was less painful to keep them going than to eliminate them and use the alternative. With the loss of Windows NT support, it is better to switch to supportable applications.

“Replace” means to replace the existing application and server with a new supported application. This is usually the most expensive and time-consuming alternative, but it is the choice when all else is eliminated. If the application is critical, there is economic justification for replacement. If the application is not critical, then it should be abandoned, because it is a security risk and will shortly be unmaintainable.

Use I AM FEARLESS to help define your upgrade decisions. And if you have already taken care of Windows NT 4.0 applications, then get ready for the next upgrades when Windows 2000 support is dropped.


Author Information
Dennis Brandl, brandl@brlconsulting.com, is president of BR&L Consulting in Cary, NC, which is focused on manufacturing IT issues.

Email
Print
Reprint
Learn RSS

Talkback

We would love your feedback!

Post a comment

» VIEW ALL TALKBACK THREADS

Related Content

Related Content

 

By This Author

Sponsored Links

 

Advertisement
SPONSORED LINKS

More Content

  • Blogs
  • Discussions
  • Webcasts
  • Podcasts
  • Videos

Blogs

  • Matt Luallen and Steve Hamburg of Encari
    Industrial Cyber Security

    November 17, 2008
    NIST SP 800-82 Guide to Industrial Control Systems Security
    The National Institute of Standards and Technology has posted the Final Public Draft of NIST SP 800-82, Guide to Industrial Control Systems (ICS) S......
    More
  • Peter Welander
    Pillar to Post: Peter Welander's Blog

    November 14, 2008
    Engineers can't light a light bulb?
    Last evening my wife told me about a video she'd seen where a group of MIT engineering graduates showed that they could not figure out how to solve......
    More
  • View All BlogsRSS

Webcasts

Engineering-driven Ethernet
This Control Engineering Roundtable Webcast will address the engineering issues you should be aware of when exploring the adoption of Ethernet or when looking to expand its use in your facility.

Bridging gaps with wireless
Discover how you can create stronger, flexible and cost-effective wireless connections for your entire plant. Register today!

View All Webcasts
Advertisements





NEWSLETTERS

Get engineering industry news, trends, and business-critical information delivered directly to your inbox!

Click on a title below to learn more.

Weekly News (Weekly)
Process Instrumentation & Sensors (Monthly)
System Integration Monthly (Monthly)
Process & Advanced Control (Monthly)
Machine Control (Monthly)
Information Control (Monthly)
Automation Control (Monthly)
Product Review (Monthly)
Simplified Safety
Fieldbus Facts
PROFInews North American Edition
About Us   |   Advertising Info   |   Site Map   |   Contact Us   |   Useful Sites   |   FREE Subscription   |   RSS
© 2008 Reed Business Information, a division of Reed Elsevier Inc. All rights reserved.
Use of this Web site is subject to its Terms of Use | Privacy Policy
Please visit these other Reed Business sites