Home » Business » How Industrial Firewalls Protect Manufacturing and Process Networks

How Industrial Firewalls Protect Manufacturing and Process Networks

Historically, many manufacturing floors and process plants were connected only to local isolated networks. Programmable logic controllers, human-machine interfaces and supervisory systems communicated via proprietary protocols with no real relation to the world outside of that MicroNet wall, and isolation itself was a type of security. That isolation has largely disappeared. Modern plants are connecting operational technology into enterprise IT systems for production analytics, remote diagnostics, predictive maintenance and supply chain visibility  and almost every single one of those connections becomes a potential conduit to an attacker who should have never ever been allowed onto the plant floor in the first place.

Purpose-built protection for this environment looks different from a typical office firewall. An industrial firewall in manufacturing networks has to understand the protocols that control systems actually speak, tolerate physical conditions an office deployment never faces, and enforce segmentation in a way that keeps a compromised device from ever reaching safety-critical controls.

The Convergence Problem

Real operational value is catalyzing this push to connect IT to OT systems. Production data should be flowing into business intelligence dashboards in-near real-time for plant managers, and maintenance teams want the ability to diagnose equipment issues remotely without a technician having to drive out to a remote site. Industrial control systems (ICS) weren’t engineered with confidentiality or authentication in mind decades ago; they were designed for availability and safety, and many of the protocols that continue to run on plant floors today lack even basic in-built security controls. A firewall at the boundary of IT and OT, or between zones within OT itself, may be the only safeguard standing between an exposed IT vulnerability and a process mechanism that operates physical equipment.

Grounding Practices in Established Guidance

Inevitably, this is not a novel problem even if the pace at which the connectivity that drives it has accelerated recently. In the case of typical enterprise IT security, one area where NIST has performed a great service is in the guidance it lays out around SCADA and process control security, making clear that the performance, reliability and safety requirements for industrial control systems would be distinct when compared against what would come into play in many other data-centric situations. That distinction is important to the deployment of a firewall, because a control system firewall that delays packets or occasionally loses packets will result in negative physical consequences in the same way as an office network interruption simply does not.

The United Kingdom’s National Cyber Security Center has put out its own operational technology cyber security guidelines that detail how organizations should manage the risk added as OT environments are more connected to enterprise networks and the internet. The two sets of recommendations overlap at one fundamental principle: segmentation and visibility need to be built into the architecture not tacked on once connectivity is already established.

What Sets Industrial Firewalls Apart

A typical enterprise firewall analyzes common IT protocols such as HTTP and DNS, but typically has no contextual understanding of Modbus, DNP3, OPC-UA or the hundreds of other protocols driving valves, motors and sensors on a plant floor. Industrial firewalls are constructed with packet inspection engines that understand these protocols semantically, allowing them to differentiate between a legitimate setpoint adjustment command and a malformed or malicious one as opposed to simply passing/blocking traffic based on port numbers.

In this environment, the segmentation logic also behaves differently. Most industrial security programs are built on the Purdue reference model of zones and conduits that reasonably isolates the enterprise network, site business network, supervisory control layer and basic control layer into separate segments with strictly controlled communication paths. Firewalls deployed at these boundaries enforce the segmentation, meaning that a hacked laptop on the corporate network cannot access a junction if it travels subsequently across several layers of the network.

Industrial firewalls are quite different from IT firewalls in that failure behavior is another area of difference. One that fails can go to a fail-safe, such as an enterprise firewall just blocking traffic until the device comes back online. For example, a firewall in front of a safety-critical process may be configured to fail so that it does not interrupt the process while it is still mid-cycle, since some industrial equipment can introduce new safety or equipment damage problems if brought from one operating state to another uncontrolled. To get this behavior right requires firewall hardware and configuration tuned to industrial operating requirements, not fifteen-year-old IT deployment adaptations done after-the-fact.

Where They Get Deployed

For example, industrial firewalls segment robotic welding and painting cells from the rest of the plant network in automotive assembly lines, where production continuity on a given line can cost thousands of dollars for every few seconds of unplanned downtime. Food and beverage manufacturers use them to segregate process control systems that regulate temperature, mixing and sanitation from IT systems that deal with day-to-day operations such as inventory and logistics because an interruption of process control in this industry can play out directly on the product’s safety. Industrial firewalls are used to protect supervisory control systems (SCADA) for water and wastewater treatment facilities from outside attacks as well as the growing assortment of remote access connections that vendors and contractors use to conduct maintenance. Pharmaceutical and chemical manufacturers take an analogous approach to secure batch control systems, where the consequences of an unauthorized change to a formula or processing parameter would extend far beyond a simple network outage.

The common link across all of these scenarios is the fundamental need. The firewall that exists in between IT and OT, or betwixt zones within OT itself, needs to comprehend the transactions it sees; apply segmentation appropriate to how the plant really has to run; and act predictably even when things fail  and they will fail because any conventional enterprise appliance will just drop the connection and continue on.

Frequently Asked Questions

A production network can not be protected by a standard enterprise firewall

Standard firewalls have no visibility into industrial protocols, such as Modbus and DNP3, which means they cannot know whether a command to control an Industrial Control System (ICS) asset originated from a legitimate-order/command user or not. They are also not designed for the availability and safety requirements of industrial environments.

What is the Purdue model, and why does it matter for firewall placement?

The Purdue model is structured into layers, starting from the enterprise network layer and going down to the basic control layer with firewalls de defining freedom of communication across these layers. This makes it so an attacker cannot spread as far if they only own one piece of the chain.

Learn why industrial firewalls are slowing down your plant operations

Industrial firewalls are specifically designed to inspect traffic without introducing significant latency, since in many process control environments, delays can have life-threatening implications! Failure behavior and configurations are usually tuned such that it does not affect the active processes.

Leave a Reply