Security Considerations for Machine Builders

Preview:

DESCRIPTION

EtherNet/IP provides a single network technology for motion, safety, discrete, drives, and process applications streamlining machine network design and decreasing wiring costs. In this session, you will learn about security considerations and best practices for integration of these machines with end user networks. We will discuss trade offs and options for remote connectivity approaches, infrastructure features and segmentation methods.

Citation preview

Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved.

PUBLIC INFORMATION

Security Considerations for Machine Builders

Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved.

Agenda

3

Infrastructure Features

Remote Connectivity

Segmentation Approaches

Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved.

Advantages Disadvantages

Managed

Switches

Unmanaged

Switches

Embedded

Switches

• Segmentation services (VLANs)

• Diagnostic information

• Security services

• Prioritization services (QoS)

• Multicast management services

• Network resiliency

• Loop prevention

• Inexpensive

• Simple to set up

• More expensive

• Requires some level of support and configuration to start up

• No management capabilities

• No security

• No diagnostic information

• Difficult to troubleshoot

• No resiliency support

• No loop prevention

• Diagnostic information

• Prioritization services (QoS)

• Time Sync Services (1588 Transparent Clock)

• Network resiliency

• Loop prevention

• Limited management capabilities

• May require minimal configuration

Switch Considerations

Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved.

Topology Flexibility with EtherNet/IP

EtherNet/IP is topology neutral for maximum flexibility

HYBRID – Obtain maximum flexibility

LINEAR - Simplify cable management STAR– Connect broad range of devices

RING – Maximum availability

Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved.

Why Managed Switches for Machine Networks?

Robust/future proof the control network:

Reduce risk from interference from other devices on the network

Customer support & satisfaction

Security features for Network access to the Control System:

Enabler for remote access

Customer support/satisfaction

Equipment differentiation

Diagnostic Capability:

Reduce TTM

Increase equipment differentiation

Improve customer support/satisfaction and reduce risk

6

Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved. 7 7

Logix Interface

Rockwell Software Studio 5000® • Configuration (stored as part of project)

• Status

• Product identification

• I/O connection

• Port Status

• Alarms

• Maintenance - Save and restore

Logix Predefined Tags • Link Status

• Unauthorized device

• Threshold exceeded

• Bandwidth utilization

• Alarm relays

• Port Control

Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved.

Infrastructure Security Considerations

Physical Access Security Disable unused switch ports Lock a port to only allow specific devices to be

connected Change passwords from default settings

Access Control Lists and Firewall Features Limit access to secure areas of the network. Limit access to secure services on the network Block remote access to secured devices

VLANs Simplify security enforcement by creating function

groups Segment Network by function, by user, by location, etc.

Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved.

Machine Switch Best Practices

9

Best practices to improve

machine level Infrastructure

Security:

• Apply port security to protect open

ports on the switch

• Apply password to the switches to

prevent unauthorized changes

• Limit the size of broadcast domain

with segmentation

• Apply Security Policies to

communications coming into the

machine from outside

Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved.

Machine Network Segmentation for the Plant Network

ArmorBlock® I/O

PanelView™ Plus EOI

POINT I/O™

Plant Network CompactLogix™ L36ERM

Stratix 5700™

Cisco 3750 or Stratix 8300™

PowerFlex® 525

Kinetix® 5500

Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved.

Cell/Area Zone #3 Cell/Area Zone #4 Cell/Area Zone #1 Cell/Area Zone #2

Industrial Zone

DMZ

Enterprise Zone Enterprise

Network

Mobile User

Lightweight AP (LWAP)

AP as Workgroup Bridge (WGB)

ERP, Email, Wide Area Network (WAN)

Catalyst 2960 Series PoE-8

SYST

DUPLX

SPEED

MODE

COC IS

1 2

POWER OVER ETHERNET

13X

14X

11X

12X

23X

24X

STAT

RPS

PoE

1X

2X

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24

Catalyst 2960 Series PoE-8

SYST

DUPLX

SPEED

MODE

COC IS

1 2

POWER OVER ETHERNET

13X

14X

11X

12X

23X

24X

STAT

RPS

PoE

1X

2X

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24

CISCO ASA 5510

POWER STATUS ACTIVE VPN FLASH

Adaptive Security Appliance

SERIES

CISCO ASA 5510

POWER STATUS ACTIVE VPN FLASH

Adaptive Security Appliance

SERIES

Cisco 4400 Series

WIRELESS LAN CONTROLLER

MODEL 4402 12 APCONSOLE

STATUS

ALARM

PS1

PS2

LINK ACT

SERVICE

LINK ACT

UTILITY 1 2

LINK

ACT

2

.Rx

-Tx

. 4

A

G

H z

ANTENNA

2

. Rx -Tx

.4

A

GH

zANTENNA

2

. Rx -Tx

.4

B

GH

zANTENNA

2

. Rx -Tx

.4

C

GH

zANTENNA

2

.Rx

-Tx

. 4

C

G

H z

ANTENNA

2

.Rx

-Tx

. 4

B

G

H z

ANTENNA

STATUS RADIOETHERNET

C OCIS

2

.Rx

-Tx

. 4

A

G

H z

ANTENNA

2

. Rx -Tx

.4

A

GH

zANTENNA

2

. Rx -Tx

.4

B

GH

zANTENNA

2

. Rx -Tx

.4

C

GH

zANTENNA

2

.Rx

-Tx

. 4

C

G

H z

ANTENNA

2

.Rx

-Tx

. 4

B

G

H z

ANTENNA

STATUS RADIOETHERNET

C OCIS

MODE

STACKSPEEDDUPLXSTATMASTRRPSSYST

Catalyst 3750 SERIES

1 2 3 4 5 6 7 8 9 10 11 12

1X

2X

11X

12X

13 14 15 16 17 18 19 20 21 22 23 24

13X

14X

23X

24X

1 2 3 4

MODE

STACKSPEEDDUPLXSTATMASTRRPSSYST

Catalyst 3750 SERIES

1 2 3 4 5 6 7 8 9 10 11 12

1X

2X

11X

12X

13 14 15 16 17 18 19 20 21 22 23 24

13X

14X

23X

24X

1 2 3 4

Converged Network Segmentation

Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved.

Network Address Translation

Machine 1 NAT

10.104.x.x :

192.168.1.x

Machine 2 NAT 10.104.x.x : 192.168.1.x

192.168.1.104 192.168.1.104

10.104.100.23

192.168.1.100

Within a Machine Between Machine and Line Network

Send message

to Machine 2

CMX 10.104.2.100

192.168.1.100

Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved.

Connectivity to Plant Network Virtual vs. Physical Segmentation

13

PowerFlex 4/40 AC Drive

PV+ or PV+ Compact

Plant VLAN

10.10.10.10

CompactLogix 5370 L3 PowerFlex 4/40 AC Drive

PV+ or PV+ Compact

Plant

10.10.10.10 192.168.1.2

Virtual

Pros:

• Little/No machine level switch configuration needed

• Removes “single point of failure” plant network

connectivity

• Designed to allow network services (SNMP, VPN,

DNS, DHCP)

Cons:

• IP addressing must be unique at the machine level

Physical

Pros:

• IP Addresses private to machine (not visible

outside of machine network)

• Clear Demarcation

Cons:

• Additional cost

• Some additional complexity and management

• Multiple network identities for a single device

Machine VLAN

Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved.

Remote Access Approaches

14

Direct to ICS

Inside-Out Terminal Services

Outside-In

modems

VPN Technology

Through IT Infrastructure

Inside-Out

Conferencing technology (WebEx)

Terminal Services

Outside-In VPN Technology

Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved.

Remote Access/Asset “Technology Recommendation” Process

15

Technology Recommendation

Risk Mitigation

Techniques and Policies

Business Case

Risk

Assessment

Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved.

Strategic Planning and Justification

16

Cost of Downtime

Cost to train someone locally/run a dedicated line to remote asset

# of assets exposed to remote access

Functions exposed to remote access

Safety risk/reward? If someone got this access they could potentially do this and cause

a safety issue. If I have to send someone out to this unmanned location it would pose a

risk to their safety (confined spaces, other hazards present, etc.)

Productivity improvement potential

MTTR reduction potential

Cost of Hardware

Maintenance cost

What confidential information may be at risk and how can I mitigate that risk

Impact to operations in the event of a breech and how to mitigate/recover from that

Compliance and regulatory obligations

Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved. 17

Remote Access Technology Considerations

Speed Security Features

IT Involvement and support

Firewall Setup Needs

Unmanned Site

Hardware Costs

Service Costs Application

Needs Auditing

Capabilities

Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved. 18

Common Technology Approaches

Application

Presentation

Session

Transport

Network

Data Link

Physical

Layer 7

Layer 6

Layer 5

Layer 4

Layer 3

Layer 2

Layer 1

TCP - UDP

IP

IEEE 802.3

TIA - 1005

Layer Name Layer No. Function

CIP

Application Layers

Data Transport Layers

SSH

SSL/TLS

IPSec

Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved.

Additional Material Rockwell Automation

19

Networks Website: http://www.ab.com/networks/

EtherNet/IP Website: http://www.ab.com/networks/ethernet/

Publications:

ENET-UM001-EN-P EtherNet/IP Network Configuration

ENET-AP005-EN-P Embedded Switch application guide

ENET-RM002-EN-P EtherNet/IP Design Considerations

Network and Security Services Website:

http://www.rockwellautomation.com/services/networks/

http://www.rockwellautomation.com/services/security/

ODVA Website

http://www.odva.org

Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved.

Additional Material Cisco and Rockwell Automation Alliance

21

Education Series Webcasts

The Trend - Network Technology and Cultural Convergence

What every IT professional should know about Plant Floor Networking

What every Plant Floor Controls Engineer should know about working with IT

Industrial Ethernet: Introduction to Resiliency

Fundamentals of Secure Remote Access

for Plant Floor Applications and Data

Securing Architectures and Applications

for Network Convergence

Available Online

http://www.ab.com/networks/architectures.html

Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved.

We care what you think!

On the mobile app:

1. Locate session using

Schedule or Agenda Builder

2. Click on the thumbs up icon on

the lower right corner of the

session detail

3. Complete survey

4. Click the Submit Form button

22

Please take a couple minutes to complete a quick session survey to tell us how we’re doing.

2

3

4

1

Thank you!!

Copyright © 2014 Rockwell Automation, Inc. All Rights Reserved.

www.rsteched.com

Follow RSTechED on Facebook & Twitter. Connect with us on LinkedIn.

PUBLIC INFORMATION

Questions?

Recommended