Paid Feature If you thought the industrial internet of things (IIoT) was the cutting edge of industrial control systems, think again. Companies have been busy allowing external access to sensors and controllers in factories and utilities for a while now, but forward-thinking firms are now exploring a new development; operating their industrial control systems (ICS) entirely from the cloud. That raises a critical question: who's going to protect it all?
Dave Masson, Director of Enterprise Security at Darktrace, calls this new trend 'ICSaaS'. "ICS for the cloud is starting to happen now. That represents a whole new world for industrial technology and security.
This trend has been possible for the last decade or so, he explains, but the uptake has been slow. Now, Masson is hearing from clients who are actioning it.
The move to cloud-controlled ICS took this long to begin in part because of the cultural differences in the ICS world. One mistake configuring the operational technology (OT) underpinning ICS can have profound effects, Masson says. Opening this infrastructure up to access from the internet was a bold enough step on its own, and took a big cultural shift. Putting the means of control in the cloud takes a further shift in mentality.
"Although there are positives, it will still impact reliability," says Masson. "There are ramifications for ICS performance, security, and therefore safety." Many of these environments can't tolerate any downtime at all.
Operational technology admins may be nervous about allowing cloud-based control of their infrastructures, but they're attracted by the potential benefits, Masson asserts. The pandemic has been a strong driver, allowing operators to remotely control industrial systems when they haven't been able to come on-site.
Organizations could enable remote access without cloud-based systems by punching holes in on- premises firewalls, but doing so made cloud-based access more plausible, opening up the conversation.
If operators are accessing ICS remotely anyway, then it makes it easier to consider cloud-based interfaces, Masson says. These make the management infrastructure cheaper and easier to operate. He points out the arguments now familiar to IT decision makers, including the opportunity to reduce operators' own hardware investments and potentially cut their data center real estate. Companies are now seriously considering taking advantage of these operational benefits for the first time.
In this scenario, the hardware components that make up ICS stay where they are. We're not talking about virtualizing programmable logic controllers here. It's the data governing their operation that moves to the cloud. That means the applications, databases, and other services that operators rely on to keep those components running smoothly. Instead of handling planning and scheduling using on-premises data, they'll do it using cloud platforms that then tunnel communications to those legacy systems in the field - which still expect to be spoken to via specialized protocols like Modbus.
Security is just as important in these new cloud-enabled environments as it was in the old legacy walled gardens, but the challenges facing defenders are different. The cloud is eroding the gap between IT and OT, explains Masson. OT is now part of what looks increasingly like a common IT network.
"Now, anybody can access this network from anywhere, so you've got to make sure you have good controls around who's got permission," he says. "This raises questions about data security, compliance, and regulation."
Security teams grappling with this face challenges including more complexity in their infrastructures as they bring different devices and protocols into the fray, with traffic running through different gateways. The number of OT devices can be staggering, far outnumbering the number of servers or endpoints that an IT security team has dealt with before.
OT admins, used to maintaining an iron grip on their infrastructure, now risk a loss of visibility and control, warns Masson. He calls the people looking after this management data in an ICS setting data historians.
"That data is now over the horizon and you need to know what people are doing with it in the cloud," he warns, pointing to a litany of problems with misconfigured databases and storage resources. The prospect of exposing ICS management data to the general public due to a dashboard misstep would turn most data historians grey.
There are organizational worries to consider beyond the technological ones, Masson adds. Converging IT/OT infrastructures is only part of the story. You must also decide who is managing security for the expanded network. Is it the IT security team, or the OT team, or both? Do they speak the same language? Will the organization have to contend with political strife and territorial battles?
When all these challenges combine, it's easy for security problems to slip through the gaps. It takes a cohesive approach with multiple checks and balances to ensure protection that extends from the physical equipment in the field through to the infrastructure that controls it in the cloud. It takes a sharp focus on access controls and permissions at all points in the ecosystem.
This new, more complex environment demands a new approach to security, according to Masson.
Zero trust architecture is a common talking point today when discussing cloud-based security, and that will be important, he says. Its focus on identity-based access, backed by account controls like multi-factor authentication, is valuable. "But that won't tell you when you've misconfigured something providing you with access to your ICS from the cloud," he points out.
He warns that IT teams can't rely on the same protective measures they used in the past. "They'll have one product for this and another for that, all using hard-coded predefined rules and signatures that aren't really designed to adapt with sudden transformation. The rules-based firewalls that might have offered some protection in the past will no longer cut it in a converged IT/OT cloud-based environment.
Darktraces AI technology flips this narrative, evaluating threats to complex systems not using a rigid set of rules, but instead leveraging unsupervised machine learning to constantly understand an organizations 'pattern of life'.
Instead of running every traffic pattern against a complex and often outdated series of signatures to detect malicious behaviour, Darktrace's tools look for activities that deviate from this pattern of life. If it detects communications between ICS systems that don't usually communicate, for example, or unusual access to ICS control systems in the cloud, its AI will investigate the activity in real time.
If granted permission, Darktrace's Antigena product will also take its own steps to contain the threat. It uses an AI-powered Autonomous Response mechanism that takes measured steps to neutralize malicious behaviour, all while allowing normal business operations to continue to run smoothly.
This approach has the advantage of not relying on deep packet inspection for its results. That's a big plus in an environment where tunnelled communications between cloud-based management systems and ICS components are often so obscure that they're effectively encrypted.
"There are tons of these protocols, some invented by people who are now dead," Masson says. "So we stay protocol agnostic."
While the company is learning some of the protocols for clients that demand it, the AI technology doesn't need to understand what's happening in a packet. Instead, Darktrace looks at what the packet is doing within the broader infrastructure, using its self-learning AI to assess deviations from the norm.
A number of cloud-first critical infrastructure organizations use Darktrace to defend their cloud environments one being Mainstream Renewable Power, a major player in wind and solar energy.
ICSaaS is only one part of a broader shift towards OT/IT convergence, says Masson. The advent of 5G, along with the development of edge computing, will accelerate the trend still further.
"Right now people focus on protecting the data that's in the cloud, but with 5G and edge computing that data won't always stay there; it will be on the edge where the computation is actually taking place. Masson argues that self-learning AI, built to maintain a picture of normality in volatile environments, will be well-placed to cope with the speed and complexity of edge-based scenarios.
ICS will be deeply ingrained in this new computing model, which will see local 5G-based networks supporting edge facilities and sensors with software-defined network functions including network slicing. With the world on the cusp of this change, new approaches to protecting it all from attack will be crucial.
Masson is certain that AI will be squarely in the middle of the picture, protecting the network from logic controllers in the field through to virtual servers in hyperscale cloud architectures - and everything in between.
This article is sponsored by Darktrace.
Excerpt from:
The future of OT security in an IT-OT converged world - The Register
- Setting up a Virtual Server on Ninefold - Video [Last Updated On: February 26th, 2012] [Originally Added On: February 26th, 2012]
- ScaleXtreme Automates Cloud-Based Patch Management For Virtual, Physical Servers [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- Secure Cloud Computing Software manages IT resources. [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- Dell unveils new servers, says not a PC company [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- Wyse to Launch Client Infrastructure Management Software as a Service, Enabling Simple and Secure Management of Any ... [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- As the App Culture Builds, Dell Accelerates its Shift to Services with New Line of Servers, Flash Capabilities [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- Terraria - Cloud In A Ballon - Video [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- Ethernet Alliance Interoperability Demo Showcases High-Speed Cloud Connections [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- RSA and Zscaler Teaming Up to Deliver Trusted Access for Cloud Computing [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- [NEC Report from MWC2012] NEC-Cloud-Marketplace - Video [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- IBM SmartCloud Virtualized Server Recovery - Video [Last Updated On: February 28th, 2012] [Originally Added On: February 28th, 2012]
- BeyondTrust Launches PowerBroker Servers Windows Edition [Last Updated On: February 29th, 2012] [Originally Added On: February 29th, 2012]
- Ericsson joins OpenStack cloud infrastructure community [Last Updated On: February 29th, 2012] [Originally Added On: February 29th, 2012]
- ScaleXtreme Cloud-Based Patch Management Open for New Customers [Last Updated On: March 1st, 2012] [Originally Added On: March 1st, 2012]
- RootAxcess - Getting Started - Video [Last Updated On: March 1st, 2012] [Originally Added On: March 1st, 2012]
- How to Create a Terraria Server 1.1.2 (All Links Provided) - Video [Last Updated On: March 1st, 2012] [Originally Added On: March 1st, 2012]
- Dell #1 in Hyperscale Servers (Steve Cumings) - Video [Last Updated On: March 1st, 2012] [Originally Added On: March 1st, 2012]
- Managing SAP on Power Systems with Cloud technologies delivers superior IT economics - Video [Last Updated On: March 1st, 2012] [Originally Added On: March 1st, 2012]
- AMD Acquires Cloud Server Maker SeaMicro for $334M USD [Last Updated On: March 3rd, 2012] [Originally Added On: March 3rd, 2012]
- Web Host 1&1 Provides More Flexibility with Dynamic Cloud Server [Last Updated On: March 3rd, 2012] [Originally Added On: March 3rd, 2012]
- Leap Day brings down Microsoft's Azure cloud service [Last Updated On: March 3rd, 2012] [Originally Added On: March 3rd, 2012]
- RightMobileApps White Label Program - Video [Last Updated On: March 3rd, 2012] [Originally Added On: March 3rd, 2012]
- bzst server ban #2 - Video [Last Updated On: March 3rd, 2012] [Originally Added On: March 3rd, 2012]
- “Cloud storage served from an array would cost $2 a gigabyte” [Last Updated On: March 6th, 2012] [Originally Added On: March 6th, 2012]
- More Flexibility with the 1&1 Dynamic Cloud Server [Last Updated On: March 6th, 2012] [Originally Added On: March 6th, 2012]
- Hub’s future jobs may be in cloud [Last Updated On: March 6th, 2012] [Originally Added On: March 6th, 2012]
- Cloud computing growing jobs, says Microsoft [Last Updated On: March 6th, 2012] [Originally Added On: March 6th, 2012]
- TurnKey Internet Launches WebMatrix, a New Application in Partnership with Microsoft [Last Updated On: March 6th, 2012] [Originally Added On: March 6th, 2012]
- Cebit 2012: SAP Cloud Computing Strategy - Introduction - Video [Last Updated On: March 6th, 2012] [Originally Added On: March 6th, 2012]
- Dome9 Security Launches Industry's First Free Cloud Security for Unlimited Number of Servers [Last Updated On: March 7th, 2012] [Originally Added On: March 7th, 2012]
- Servers Are Refreshed With Intel's New E5 Chips [Last Updated On: March 7th, 2012] [Originally Added On: March 7th, 2012]
- Samsung's AllShare Play pushes pictures from phone to cloud and TV [Last Updated On: March 7th, 2012] [Originally Added On: March 7th, 2012]
- Google drops the price of Cloud Storage service [Last Updated On: March 7th, 2012] [Originally Added On: March 7th, 2012]
- New Intel Server Technology: Powering the Cloud to Handle 15 Billion Connected Devices [Last Updated On: March 7th, 2012] [Originally Added On: March 7th, 2012]
- Swisscom IT Services Launches Cloud Storage Services Powered by CTERA Networks [Last Updated On: March 7th, 2012] [Originally Added On: March 7th, 2012]
- KineticD Releases Suite of Cloud Backup Offerings for SMBs [Last Updated On: March 7th, 2012] [Originally Added On: March 7th, 2012]
- First Look: Samsung Allshare Play - Video [Last Updated On: March 7th, 2012] [Originally Added On: March 7th, 2012]
- Bill The Server Guy Introduces the New Intel XEON e5-2600 (Romley) Server CPU's - Video [Last Updated On: March 7th, 2012] [Originally Added On: March 7th, 2012]
- New Cisco servers have Intel Xeon E5 inside [Last Updated On: March 8th, 2012] [Originally Added On: March 8th, 2012]
- Cisco rolls out UCS servers with Intel Xeon E5 chips [Last Updated On: March 8th, 2012] [Originally Added On: March 8th, 2012]
- From scooters to servers: The best of Launch, Day One [Last Updated On: March 8th, 2012] [Originally Added On: March 8th, 2012]
- Computer Basics: What is the Cloud? - Video [Last Updated On: March 9th, 2012] [Originally Added On: March 9th, 2012]
- Could the digital 'cloud' crash? [Last Updated On: March 10th, 2012] [Originally Added On: March 10th, 2012]
- Dome9 Security Launches Free Cloud Security For Unlimited Number Of Servers [Last Updated On: March 10th, 2012] [Originally Added On: March 10th, 2012]
- Cloud computing 'made in Germany' stirs debate at CeBIT [Last Updated On: March 11th, 2012] [Originally Added On: March 11th, 2012]
- New Key Technology Simplifies Data Encryption in the Cloud [Last Updated On: March 11th, 2012] [Originally Added On: March 11th, 2012]
- Can a private cloud drive energy efficiency in datacentres? [Last Updated On: March 12th, 2012] [Originally Added On: March 12th, 2012]
- Porticor's new key technology simplifies data encryption in the cloud [Last Updated On: March 12th, 2012] [Originally Added On: March 12th, 2012]
- Borders + Gratehouse Adds Three New Clients in Cloud Sector [Last Updated On: March 12th, 2012] [Originally Added On: March 12th, 2012]
- Dell to invest $700 mn in R&D, unveils 12G servers [Last Updated On: March 13th, 2012] [Originally Added On: March 13th, 2012]
- Defiant Kaleidescape To Keep Shipping Movie Servers [Last Updated On: March 13th, 2012] [Originally Added On: March 13th, 2012]
- Data Centre Transformation Master Class 3: Cloud Architecture - Video [Last Updated On: March 13th, 2012] [Originally Added On: March 13th, 2012]
- DotNetNuke Tutorial - Great hosting tool - PowerDNN Control Suite - part 1/3 - Video #310 - Video [Last Updated On: March 13th, 2012] [Originally Added On: March 13th, 2012]
- Cloud Computing - 28/02/12 - Video [Last Updated On: March 13th, 2012] [Originally Added On: March 13th, 2012]
- SYS-CON.tv @ 9th Cloud Expo | Nand Mulchandani, CEO and Co-Founder of ScaleXtreme - Video [Last Updated On: March 13th, 2012] [Originally Added On: March 13th, 2012]
- Oni Launches New Cloud Services for Enterprises Using CA Technologies Cloud Platform [Last Updated On: March 14th, 2012] [Originally Added On: March 14th, 2012]
- SmartStyle Advanced Technology - Video [Last Updated On: March 14th, 2012] [Originally Added On: March 14th, 2012]
- SmartStyle Infrastructure - Video [Last Updated On: March 14th, 2012] [Originally Added On: March 14th, 2012]
- The Hidden Risk of a Meltdown in the Cloud [Last Updated On: March 14th, 2012] [Originally Added On: March 14th, 2012]
- FireHost Launches Secure Cloud Data Center in Phoenix, Arizona [Last Updated On: March 14th, 2012] [Originally Added On: March 14th, 2012]
- Panda Security Launches New Channel Partner Recruitment Campaign: "Security to the Power of the Cloud" [Last Updated On: March 14th, 2012] [Originally Added On: March 14th, 2012]
- NetSTAR, Inc. Announces Safe and Secure Web Browsers for iPhones, iPads, and Android Devices [Last Updated On: March 14th, 2012] [Originally Added On: March 14th, 2012]
- Amazon Cloud Powered by 'Almost 500,000 Servers' [Last Updated On: March 15th, 2012] [Originally Added On: March 15th, 2012]
- NetSTAR Announces Secure Web Browsers For iPhones, iPads, And Android Devices [Last Updated On: March 15th, 2012] [Originally Added On: March 15th, 2012]
- Be Prepared For When the Cloud Really Fails [Last Updated On: March 15th, 2012] [Originally Added On: March 15th, 2012]
- Dr. Cloud explains dinCloud's hosted virtual server solution - Video [Last Updated On: March 15th, 2012] [Originally Added On: March 15th, 2012]
- New estimate pegs Amazon's cloud at nearly half a million servers [Last Updated On: March 15th, 2012] [Originally Added On: March 15th, 2012]
- Amazon’s Web Services Uses 450K Servers [Last Updated On: March 15th, 2012] [Originally Added On: March 15th, 2012]
- Saving File On Internet - Cloud Computing - Video [Last Updated On: March 15th, 2012] [Originally Added On: March 15th, 2012]
- DotNetNuke Tutorial - Great hosting tool - PowerDNN Control Suite - part 2/3 - Video #311 - Video [Last Updated On: March 15th, 2012] [Originally Added On: March 15th, 2012]
- Linux servers keep growing, Windows & Unix keep shrinking [Last Updated On: March 15th, 2012] [Originally Added On: March 15th, 2012]
- Cloud Desktop from Compute Blocks - Video [Last Updated On: March 16th, 2012] [Originally Added On: March 16th, 2012]
- Amazon EC2 cloud is made up of almost half-a-million Linux servers [Last Updated On: March 17th, 2012] [Originally Added On: March 17th, 2012]
- HP trots out new line of “self-sufficient” servers [Last Updated On: March 17th, 2012] [Originally Added On: March 17th, 2012]
- Cloud Web Hosting Reviews - Australian Cloud Hosting Providers - Video [Last Updated On: March 17th, 2012] [Originally Added On: March 17th, 2012]
- Using Porticor to protect data in a snapshot scenario in AWS - Video [Last Updated On: March 17th, 2012] [Originally Added On: March 17th, 2012]
- CDW - Charles Barkley - New Office - Video [Last Updated On: March 17th, 2012] [Originally Added On: March 17th, 2012]
- Nearly a Half Million Servers May Power Amazon Cloud [Last Updated On: March 17th, 2012] [Originally Added On: March 17th, 2012]
- Morphlabs CEO Winston Damarillo talks about their mCloud Rack - Video [Last Updated On: March 20th, 2012] [Originally Added On: March 20th, 2012]
- AMD reaches for the cloud with new server chips [Last Updated On: March 20th, 2012] [Originally Added On: March 20th, 2012]