SCADA Security
Eric Chan Fortinet SouthEast Asia & HK
SCADA Security Eric Chan Fortinet SouthEast Asia & HK SCADA - - PowerPoint PPT Presentation
SCADA Security Eric Chan Fortinet SouthEast Asia & HK SCADA Network Architecture CONFIDENTIAL INTERNAL ONLY 2 Where are the Threats Coming From? External Sources SCADA systems are often interconnected to other SCADA systems and
Eric Chan Fortinet SouthEast Asia & HK
SCADA Network Architecture
2 CONFIDENTIAL – INTERNAL ONLY
Where are the Threats Coming From?
RTU’s/MGMT stations via public networks RTU s/MGMT stations via public networks
systems
3 CONFIDENTIAL – INTERNAL ONLY
yp p
How to Protect your SCADA Environment
Control application/ communication into/out of the network
»Includes ICCP and DNPV3
quickly
4 CONFIDENTIAL – INTERNAL ONLY
Summary: Defense-in-Depth Security
RTU and the network level
Deploy security systems that offer tightly integrated multiple detection mechanisms:
» IPS » Antivirus » Antispam
Corporate LAN
» Antispam » Application control » Identity based policies » Web filtering
Remote Terminal Human Machine Interface (HMI)» DB » Stateful firewall » VPN » Wireless
Pump/fan speed Pressure Flow Rate Oil levels and Maintenance alarms Remote Terminal Unit Unit
» Wireless » Strong Authentication
IPS signature databases
Pump/fan speed Pressure Flow Rate Oil levels and Maintenance alarms
5 CONFIDENTIAL – INTERNAL ONLY
FortiGate Rugged
IEC 61850 3
I t i P ti
y g
6 CONFIDENTIAL – INTERNAL ONLY
Application Awareness for SCADA Protocols
Supported Protocols Protocols ICCP Modbus DNP3 Ethernet.IP EtherCAT
7 CONFIDENTIAL – INTERNAL ONLY
About Fortinet
»by industry analyst: Gartner IDC Frost&Sullivan »by industry analyst: Gartner, IDC, Frost&Sullivan
»5 ICSA Labs security certifications »NSS UTM certification »ISO 9001:2008 certification »12 Virus Bulletin (VB) 100% awards »12 Virus Bulletin (VB) 100% awards »IPV6 certification for FortiOS 4.0 »Common Criteria Evaluation Assurance Level 4 Augmented (EAL 4+) for FortiOS 4.0 »FIPS PUB 140-2 »NEBS Level 3
8 CONFIDENTIAL – INTERNAL ONLY
9 CONFIDENTIAL – INTERNAL ONLY
More Security
Client Reputation Advanced Anti-malware Protection Advanced Anti malware Protection
10 CONFIDENTIAL – INTERNAL ONLY
Zero Day Attack Detection
Identify potential … zero-day attacks
Th t St t Multiple Scoring Vectors Reputation by Activity Threat Status
Real Time, Relative, Drill-down, Correlated
Ranking Identification Policy Enforcement Score Computatio n
11 CONFIDENTIAL – INTERNAL ONLY
n
Advanced Anti-Malware Protection
Hardware Accelerated Local Lightweight FortiGuard Botnet IP Hardware Accelerated & Code optimized Real time updated, 3rd party validated Local Lightweight Sandboxing Behavior / Attribute Based Heuristic Detection FortiGuard Botnet IP Reputation DB Cloud Based Sandboxing p y Signature DB Application Control – Botnet Category g
In box Enhanced AV Engine Cloud Based AV Service
Improves threat …. … detection
12 CONFIDENTIAL – INTERNAL ONLY
In-box Enhanced AV Engine Cloud Based AV Service