IT in Manufacturing


Securing critical industrial processes in real-time

September 2012 IT in Manufacturing

The susceptibility of critical scada systems to security issues confronts many organisations. While it may be rare to penetrate a control system directly from the Internet, corporate intranet connections, remote support links, USB keys, and laptops can all create pathways for the typical worm or hacker. Once inside, impacting an industrial control system is not difficult – in some cases, even the most basic scanning by a hacker or worm can wreak havoc.

Unfortunately, 99% of all scada and process control devices do not support even basic authentication and authorisation functions. Thus, these devices cannot take advantage of any of the security infrastructures offered by many corporate IT departments. Complicating the matter even more, many scada end users have found the common VPN solutions to be either unbelievably complex to manage in real-time or ill-suited for handling the protocols that are found in automation networks.

Security in aerospace manufacturing

A major aerospace manufacturer faced exactly these issues when securing the systems used in the production of its long-range passenger aircraft. Large, highly mobile crawlers with extensive PLC and HMI components are vital for the assembly of new aircraft. In order to coordinate that assembly, these PLCs require secure access to each other and real-time connection to the corporate network.

Since the PLCs are installed on mobile platforms, they require wireless access to communicate. However, the models of PLCs currently on the market cannot participate in the corporate public key infrastructure (PKI) system, which is a requirement for secure wireless communications. Furthermore, the plant security solution must modify security policy (and allow PLC to PLC connections) based on information from a large variety of sources that change rapidly. For example, the position of a crawler or the card scan of an operator will determine which PLCs can interconnect.

Scadanet Endboxes secure the PLCs

The solution is an architecture called Scadanet that provides a simple and secure encryption system between control devices. Each crawler is protected by a Scadanet Endbox. These Endboxes interconnect securely with other Endboxes over a variety of secure or insecure networks, including the corporate intranet, various cellular services or even the Internet. The Endboxes interact with the corporate IT security services, including the PKI system, to provide an encrypted overlay network between the PLCs assigned to them by the crawler operators.

F-Map ties it all together

Tying all the Endboxes together in a scalable manner is a central publish/subscribe repository of network information based on the interface metadata access protocol (IF-Map) technology. This Trusted Computing Group standard allows systems from different vendors to publish information that the Endboxes can use to determine security policy in real-time. For example, if the IP address of an Endbox changes because a crawler has moved into the range of a new wireless access point, then this information can be propagated to other Endboxes so that critical communications are not disputed. Or if an operator that is not approved for a given crawler swipes into the badge reader, the crawler can be immediately disconnected from the critical control network.

The Scadanet architecture, IF-Map and Tofino Endboxes provide a framework that allows the IT department to manage access to its services and yet let the scada engineers maintain full control over their network systems and devices.



Credit(s)



Share this article:
Share via emailShare via LinkedInPrint this page

Further reading:

Enhancing cyber security for industrial drives
Siemens South Africa IT in Manufacturing
The growing connection between production networks and office networks as part of IT/OT integration and the utilisation of IoT have many benefits for industrial companies. At the same time, they also increase the risk of cyber threats. Siemens ensures that your know-how and plants are protected at all times.

Read more...
Immersion cooling systems for data centres
IT in Manufacturing
The demand for data centres in Africa is growing. The related need for increasing rack densities brings with it escalating cooling requirements.

Read more...
Transforming pulp and paper with automation and digitalisation
ABB South Africa IT in Manufacturing
The pulp and paper industry in South Africa is undergoing a significant transformation from traditional manual processes to embracing automation technologies. Automation in pulp and paper mills aims to improve various production stages, from raw material preparation to final product creation.

Read more...
New world of process control: A completely web-based process control system
Siemens South Africa IT in Manufacturing
Control technology is crucial for gaining a competitive edge in the process industry. That’s why there’s SIMATIC PCS neo - the innovative ground-breaking process control system by Siemens.

Read more...
Protecting industrial networks with resilient defence
RJ Connect IT in Manufacturing
Network security is no longer just about preventing hacking or data breaches. For operational technology networks, resilient defence and consistent uptime are crucial. They are the core tenets that underpin Moxa’s guarded uptime and resilient defence (GUARD).

Read more...
The metaverse is now: are you ready to reimagine your business?
IT in Manufacturing
The convergence of the digital and physical worlds, driven by spatial computing and the metaverse, is rapidly reshaping business landscapes. This transformation extends beyond the mere novelty of virtual reality headsets and augmented reality filters, signalling a fundamental shift in how organisations operate, collaborate and innovate.

Read more...
AI and cyber security: South Africa’s next battleground
IT in Manufacturing
Artificial intelligence is rapidly becoming a double-edged sword in the world of cybersecurity. In South Africa, where cybercrime is on the rise, AI presents both an opportunity and a threat.Artificial intelligence is rapidly becoming a double-edged sword in the world of cybersecurity. In South Africa, where cybercrime is on the rise, AI presents both an opportunity and a threat.

Read more...
Technology won’t save your business from cyber threats
IT in Manufacturing
Artificial Intelligence is reshaping the landscape of information security, presenting both unprecedented opportunities and significant new threats.

Read more...
Addressing the cooling needs of the modern data centre
Schneider Electric South Africa IT in Manufacturing
The rise in hardware density in data centres is gaining speed and is largely driven by the demands of artificial intelligence and machine learning, requiring more powerful servers and specialised hardware.

Read more...
South Africa’s next cyber security frontier
IT in Manufacturing
AI-powered agents are rapidly transforming how South African businesses operate, from chatbots managing customer inquiries to automated systems processing financial transactions. While these AI-driven assistants increase efficiency and reduce operational costs, they also present a new, and often underestimated, cybersecurity challenge: identity management.

Read more...