Industrial Network Security

Höfundur: Eric D. Knapp (Útgáfa: 3)
Industrial Network Security

Kaup valmöguleikar

As the sophistication of cyber-attacks increases, understanding how to defend critical infrastructure systems—energy production, water, gas, and other vital systems—becomes more important, and heavily mandated. Industrial Network Security, Third Edition arms you with the knowledge you need to understand the vulnerabilities of these distributed supervisory and control systems. Authors Eric Knapp and Joel Langill examine the unique protocols and applications that are the foundation of Industrial Control Systems (ICS), and provide clear guidelines for their protection.

This comprehensive reference gives you thorough understanding of the challenges facing critical infrastructures, new guidelines and security measures for infrastructure protection, knowledge of new and evolving security tools, and pointers on SCADA protocols and security implementation. ". . . worth recommendation for people who are interested in modern industry control systems security. Additionally, it will be advantageous for university researchers and graduate students in the network security field, as well as to industry specialists in the area of ICS.

" --IEEE Communications Magazine All-new real-world examples of attacks against control systems such as Trisys, Pipedream, and more diagrams of systems Includes all-new chapters on USB security and OT Cyber Kill Chains, including the lifecycle of an incident response from detection to recovery Expanded coverage of network anomaly detection and Beachhead systems for extensive monitoring and detection New coverage of network spans, mirrors, and taps, as well as asset discovery, log collection, and industrial-focused SIEM solution.

Nánar um bókina

Útgefandi
Elsevier S & T
ISBN
9780443137389
Print ISBN
9780443137372
Format
ePub
Útgáfa
3
Höfundar
Eric D. Knapp
Tungumál
English
Útgefið
2024-03-26
Prent takmörkun á líftíma
10

Kaflar

  • Industrial Network Security
  • Cover
  • Front Matter
  • Industrial Network Security
  • Table of Contents
  • Copyright
  • Biography
  • Acknowledgments
  • List of Illustrations
  • List of Tables
  • 1 : Introduction
  • Abstract
  • Keywords
  • Information in this chapter
  • Book overview and key learning points
  • Book audience
  • Diagrams and figures
  • The smart grid
  • OT, IoT, IIoT, and xIoT
  • How this book is organized
  • Chapter 2 : About Industrial Networks
  • Chapter 3 : Industrial Cyber Security, History, and Trends
  • Chapter 4 : Introduction to ICS Systems and Operations
  • Chapter 5 : ICS Network Design and Architecture
  • Chapter 6 : Industrial Network Protocols
  • Chapter 7 : Hacking Industrial Systems
  • Chapter 8 : Risk and Vulnerability Assessments
  • Chapter 9 : Establishing Zones and Conduits
  • Chapter 10 : OT Attack and Defense Lifecycles
  • Chapter 11 : Implementing Security and Access Controls
  • Chapter 12 : Exception, Anomaly, and Threat Detection
  • Chapter 13 : Security Monitoring of Industrial Control Systems
  • Chapter 14 : Standards and Regulations
  • Chapter 15 : Common Pitfalls and Mistakes
  • Changes made to the third edition
  • Conclusion
  • 2 : About Industrial Networks
  • Abstract
  • Keywords
  • Information in this chapter
  • The use of terminology within this book
  • Attacks, breaches and incidents; malware, exploits, and APTs
  • Assets, critical assets, cyberassets, and critical cyberassets
  • Security controls and security countermeasures
  • Firewalls and intrusion prevention systems
  • Industrial control system
  • Building control systems
  • DCS or SCADA?
  • Plants, mills, refineries, and lines
  • Industrial networks
  • Industrial protocols
  • The open systems interconnection (OSI) model
  • Networks, routable networks and non-routable networks
  • Enterprise or business networks
  • Zones and enclaves
  • Network perimeters or “electronic security perimeters”
  • Critical infrastructure
  • Utilities
  • Nuclear facilities
  • Bulk electric
  • Smart grid
  • Chemical facilities
  • Understanding “OT” versus “IT”
  • Common Industrial Security Recommendations
  • Identification of critical systems
  • Network segmentation/isolation of systems
  • Defense in depth
  • Access control
  • Advanced Industrial Security Recommendations
  • Security Monitoring
  • Policy whitelisting
  • Application whitelisting
  • Common Misperceptions About Industrial Network Security
  • Assumptions made in this book
  • Summary
  • 3 : Industrial Cybersecurity History and Trends
  • Abstract
  • Keywords
  • Information in this chapter
  • The convergence of OT and IT
  • Importance of securing industrial networks
  • The evolution of the cyber threat
  • APTs and weaponized malware
  • Industroyer
  • Night dragon
  • Stuxnet
  • TRISIS
  • Advanced persistent threats and cyber warfare
  • Still to come
  • Defending against modern cyber threats
  • The insider
  • Hacktivism, cybercrime, cyberterrorism, and cyberwar
  • Summary
  • 4 : Introduction to Industrial Control Systems and Operations
  • Abstract
  • Keywords
  • Information in this chapter
  • System assets
  • Programmable logic controller
  • Ladder diagrams
  • Sequential function charts
  • Remote terminal unit
  • Intelligent electronic device
  • Human–machine interface
  • Supervisory workstations
  • Data historian
  • Business information consoles and dashboards
  • Other assets
  • System operations
  • Control loops
  • Control processes
  • Feedback loops
  • Production information management
  • Business information management
  • Process management
  • Safety instrumented systems
  • The smart grid
  • Network architectures
  • Summary
  • 5 : Industrial Network Design and Architecture
  • Abstract
  • Keywords
  • Information in this chapter
  • Introduction to industrial networking
  • Common topologies
  • Network segmentation
  • Higher layer segmentation
  • Physical versus logical segmentation
  • Microsegmentation
  • Cryptographic microsegmentation
  • Network services
  • Wireless networks
  • Remote access
  • Performance considerations
  • Latency and jitter
  • Bandwidth and throughput
  • Type of service, class of service, and quality of service
  • Network hops
  • Network security controls
  • Safety instrumented systems
  • Special considerations
  • Wide area connectivity
  • Smart grid network considerations
  • Advanced metering infrastructure
  • Summary
  • 6 : Industrial Network Protocols
  • Abstract
  • Keywords
  • Information in this chapter
  • Overview of industrial network protocols
  • Fieldbus protocols
  • Modicon communication bus (Modbus)
  • What it does
  • How it works
  • Variants
  • Modbus RTU and Modbus ASCII
  • Modbus TCP
  • Modbus plus or Modbus+
  • Where it is used
  • Security concerns
  • Security recommendations
  • Distributed network protocol (DNP3)
  • What it does
  • How it works
  • Secure DNP3
  • Where it is used
  • Security concerns
  • Security recommendations
  • Process fieldbus (PROFIBUS)
  • Security concerns
  • Security recommendations
  • Industrial ethernet protocols
  • Ethernet industrial protocol (EtherNet/IP)
  • Security concerns
  • Security recommendations
  • PROFINET
  • Security concerns
  • Security recommendations
  • EtherCAT
  • Security concerns
  • Security recommendations
  • Ethernet POWERLINK
  • Security concerns
  • Security recommendations
  • SERCOS III
  • Security concerns
  • Security recommendations
  • Backend protocols
  • Object linking and embedding for process control
  • What it does
  • How it works
  • Where it is used
  • Security concerns
  • Security recommendations
  • Intercontrol center communications protocol (ICCP/IEC 60870-6 TASE.2)
  • What it does
  • How it works
  • Where it is used
  • Security concerns
  • Security improvements over Modbus
  • Security recommendations
  • IEC 61850, 60870-5-101, and 60870-5-104
  • How they work
  • 60870-5-101 and 60870-5-104
  • IEC 61850
  • Security concerns
  • Security recommendations
  • AMI and the smart grid
  • Security concerns
  • Security recommendations
  • Industrial protocol simulators
  • Modbus/TCP
  • DNP3
  • OPC
  • ICCP/TASE.2
  • Physical hardware
  • Summary
  • 7 : Hacking Industrial Control Systems
  • Abstract
  • Keywords
  • Information in this chapter
  • Motives and consequences
  • Consequences of a successful cyberincident
  • Cybersecurity and safety
  • Common industrial targets
  • The evolution of the industrial cyberattack
  • Common attack methods
  • Attack phases
  • Initial attack phases
  • Industrial attack phases
  • Cyber-physical attacks
  • Rogue access devices
  • Keylogging/keystroke injections/HID attacks
  • Man-in-the-middle attacks
  • Denial-of-service attacks
  • Replay attacks
  • Compromising the human-machine interface
  • Compromising the engineering workstation
  • Blended attacks
  • Weaponized industrial cyberthreats
  • Stuxnet
  • Dissecting stuxnet
  • What it does
  • Lessons learned
  • Shamoon/DistTrack
  • Flame/flamer/skywiper
  • Dragonfly
  • BlackEnergy
  • Industroyer
  • TRISIS/TRITON
  • Industroyer2
  • Incontroller/pipedream
  • Attack trends
  • Evolving vectors
  • Supply chain vulnerabilities
  • Adobe Portable Document Format
  • Macros
  • Secure sockets layers
  • Log4j
  • Ransomware and industrial control systems
  • Industrial application layer protocols
  • Antisocial networks: A new playground for malware
  • Polymorphic and adaptive malware
  • Dealing with an infection
  • Summary
  • 8 : Risk and Vulnerability Assessments
  • Abstract
  • Keywords
  • Information in this chapter
  • Cybersecurity and risk management
  • Why risk management is the foundation of cyber security?
  • What is risk?
  • Standards and best practices for risk management
  • Methodologies for assessing risk within industrial control systems
  • Security tests
  • Security audits
  • Security and vulnerability assessments
  • Establishing a testing and assessment methodology
  • Tailoring a methodology for industrial networks
  • Theoretical versus physical tests
  • On-line versus off-line physical tests
  • System characterization
  • Data collection
  • Scanning of industrial networks
  • Device scanners
  • Vulnerability scanners
  • Traffic scanners
  • Live host identification
  • “Quiet”/“friendly” scanning techniques
  • Potentially “noisy”/“dangerous” scanning techniques
  • Port mirroring and span ports
  • Command line tools
  • Hardware and software inventory
  • Data flow analysis
  • Threat identification
  • Threat actors/sources
  • Threat vectors
  • Threat events
  • Identification of threats during security assessments
  • Vulnerability identification
  • Vulnerability scanning
  • Configuration auditing
  • Vulnerability prioritization
  • Common vulnerability scoring system
  • Process vulnerabilities
  • Risk classification and ranking
  • Consequences and impact
  • How to estimate consequences and likelihood?
  • Risk ranking
  • Cyber-physical threat modeling
  • How does one model a cyber-physical threat?
  • Using simulations versus labs for threat modeling
  • Cybersecurity HAZOP
  • Risk reduction and mitigation
  • Summary
  • 9 : Establishing Zones and Conduits
  • Abstract
  • Keywords
  • Information in this chapter
  • Security zones and conduits explained
  • Identifying and classifying security zones and conduits
  • Recommended security zone separation
  • Network connectivity
  • Control loops
  • Supervisory controls
  • Plant-level control processes
  • Control data storage
  • Trading communications
  • Remote access
  • Users and roles
  • Protocols
  • Criticality
  • Establishing security zones and conduits
  • Using microsegmentation to establish zones and conduits
  • Creating a zone and conduit map
  • Summary
  • 10 : OT Attack and Defense Lifecycles
  • Abstract
  • Keywords
  • Information in this chapter
  • Attack lifecycles and kill chains
  • Obtaining access to industrial networks
  • Planning
  • Preparation
  • Intrusion
  • Enablement
  • Execution
  • Manipulation of industrial networks
  • Development and test
  • Delivery, installation, and modification
  • Execution
  • Defense lifecycles
  • Identify
  • Protect
  • Detect
  • Respond
  • Recover
  • The importance of understanding lifecycles
  • Minimizing MTTR
  • Summary
  • 11 : Implementing Security and Access Controls
  • Abstract
  • Keywords
  • Information in this chapter
  • Network segmentation
  • Zones and security policy development
  • Using zones within security device configurations
  • Implementing network security controls
  • Selecting network security devices
  • Implementing network security devices
  • Firewall configuration guidelines
  • Intrusion detection and prevention (IDS/IPS) configuration guidelines
  • Recommended IDS/IPS rules
  • Anomaly-based intrusion detection
  • Protocol anomaly detection
  • Application and protocol monitoring in industrial networks
  • Data diodes and unidirectional gateways
  • Implementing host security and access controls
  • Selecting host cybersecurity systems
  • Host firewalls
  • Host IDS
  • Antivirus
  • Application whitelisting/application allow-listing
  • Removable media
  • Policies
  • Controls
  • External controls
  • Patch management
  • Patching as a form of vulnerability management
  • Leave no vulnerability unturned
  • Maintaining system availability
  • Comprehensive predeployment testing
  • Automating the process
  • Malware detection methods
  • Signature-based detection
  • Heuristic analysis
  • Behavioral analysis
  • Sandboxing
  • Memory analysis
  • YARA
  • Machine learning and artificial intelligence
  • How much security is enough?
  • From theory to practice
  • Adding controls to production systems
  • When to implement security controls?
  • Summary
  • 12 : Exception, Anomaly, and Threat Detection
  • Abstract
  • Keywords
  • Information in this chapter
  • Exception reporting
  • Behavioral anomaly detection
  • Measuring baselines
  • Anomaly detection
  • Analyzing IT versus OT metrics
  • Anomaly detection tools
  • Behavioral whitelisting
  • User whitelists
  • Asset whitelists
  • Application behavior whitelists
  • Examples of beneficial whitelists
  • Smart-Lists
  • Advanced threat detection
  • Event correlation
  • Data enrichment
  • Normalization
  • Cross-source correlation
  • Tiered correlation
  • Correlating between IT and OT systems
  • Summary
  • 13 : Security Monitoring of Industrial Control Systems
  • Abstract
  • Keywords
  • Information in this chapter
  • Determining what to monitor
  • Security events
  • Assets
  • Process data and alarms
  • Configurations
  • Applications
  • Networks
  • User identities and authentication
  • Additional context
  • Behavior
  • Successfully monitoring security zones
  • Log collection
  • Direct monitoring
  • Inferred monitoring
  • Information collection and management tools
  • Syslog aggregation and log search
  • Log management systems
  • Security information and event management systems
  • Data historians and process alarms
  • Monitoring across secure boundaries
  • Information management
  • Queries
  • Reports
  • Alerts
  • Incident investigation and response
  • Log storage and retention
  • Nonrepudiation
  • Data retention/storage
  • Data availability
  • Summary
  • 14 : Standards and Regulations
  • Abstract
  • Keywords
  • Information in this chapter
  • Common standards and regulations
  • NERC CIP
  • CFATS
  • ISO/IEC 27002
  • NRC Regulation 5.71
  • NIST SP 800-82
  • ISA/IEC-62443
  • ISA 62443 Part 1: “General”
  • ISA 62443 Part 2: “Policies and procedures”
  • ISA 62443 Part 3: “System”
  • ISA 62443 Part 4: “Component”
  • Mapping industrial network security to compliance
  • Industry best practices for conducting ICS assessments
  • Department of Homeland Security (USA)/Center for Protection of National Infrastructure (UK)
  • National Security Agency (USA)
  • American Petroleum Institute (USA)/National Petrochemical and Refiners Association (USA)
  • Institute for Security and Open Methodologies (Spain)
  • Common Criteria and FIPS standards
  • Common Criteria
  • FIPS 140-2
  • Summary
  • 15 : Common Pitfalls and Mistakes
  • Abstract
  • Keywords
  • Information in this chapter
  • The basics
  • The KISS of death
  • Password123
  • People are people
  • The Air Gap myth
  • The future is now
  • IIoT is not spelled with a “d” in it
  • Lack of proper operationalization
  • Schrödingers event logs
  • Planning versus practice
  • Inadequate staffing
  • Lack of awareness
  • Driving without a map
  • One-and-done
  • We're not at risk
  • Driving too slow in the fast lane
  • Passing on the right
  • Misunderstanding vulnerability
  • Paralysis by vulnerability analysis
  • We've patched all the vulnerabilities
  • Software versus systems
  • Worlds are colliding!
  • Cybersecurity for OT is just like IT
  • All processes are fragile
  • My process is resilient: It's unhackable!
  • The mistake that you are making right now
  • Too much reading, not enough practice
  • Summary
  • Glossary
  • Index
  • A
  • B
  • C
  • D
  • E
  • F
  • G
  • H
  • I
  • J
  • K
  • L
  • M
  • N
  • O
  • P
  • Q
  • R
  • S
  • T
  • Page 502 U
  • V
  • W
  • Page 503 X
  • Y
  • Z