Summary
The growing use of commercial information technologies in industrial applications exposes owners/operators to a constant barrage of threats that can only be mitigated with a comprehensive, holistic approach to cybersecurity. This ARC View provides an overview of the Kaspersky industrial cybersecurity portfolio and how – according to that company - the individual components can be combined to form an effective overall solution against cyberattacks.
Recent Cyberattacks Emphasize the Need for Vigilance
A wave of cyberattacks hit European industry in autumn 2019. In Germany, the Federal Office for Information Security (BSI) observed that criminals were again causing "considerable damage" to companies, administrations, and other organizations with Emotet malware.
The BSI was concerned that the recent attacks marked the beginning of a major campaign in which the attackers could paralyze significantly more systems and cause significantly more damage. The danger is considerable, said BSI President Arne Schönbohm: "If you don't prepare yourself for the threat situation, you are very likely to become a victim.”
Cybercriminals often use malware such as Emotet to distribute software, commonly referred to as “ransomware,” to blackmail organizations. They encrypt important files and demand a ransom for their release, which is usually paid in a cryptocurrency. Recent victims of this trick have included the aluminum producer Norsk Hydro, various hospitals, and municipal administrations.
Emotet spreads fear and terror because the victims are targeted. Cybercriminals first find out which organizations own the infected systems and adjust the ransom demand to the expected willingness to pay. Some small towns in the US, for example, transferred sums of around $500,000 to get their data back.
But the industry is not defenseless against digital blackmail. Security updates and anti-virus software can stop the spread of programs like Emotet. Backup and recovery exercises can help organizations get back up and running quickly in an emergency. And enterprise networks can (and should be) spread into several zones to make it more difficult for the ransomware to spread.
Employee training also plays an important role. For example, even when it appears that email senders are known, it’s important to use caution when opening any e-mail messages with attachments.
Kaspersky Industrial Cybersecurity (KIC) Portfolio
Security solutions that meet the specific requirements of industrial control systems and an industrial infrastructure can only be created by cybersecurity suppliers that understand the differences between OT and IT applications. Global cybersecurity provider, Kaspersky, claims to have the unique combination of threat intelligence, machine intelligence and learning, and human expertise needed to provide flexible protection against any type of threat in the industry. Clearly, Kaspersky offers a wide range of technologies and services designed to support users in all requirements around industrial cybersecurity. The company’s portfolio includes technology-based solutions such as KICS for Nodes, KICS for Networks, and the Kaspersky Cybersecurity Center; plus a range of expert security training and other service offerings. The aim is to avoid costly cyber-related downtime, optimize the human factor (secure behavior), and sensitize all employees to cybersecurity.
This comprehensive Kaspersky range of technology and services also meets many of the requirements of the IEC 62443 standard, which recommends regular system audits, patch management, and employee training.
KICS for Nodes
KICS for Nodes secures ICS/SCADA servers, human-machine interfaces, and engineering workstations. As an industrial endpoint protection solution, it is designed to secure industrial automation systems against human error, malware, targeted attacks or sabotage. KICS for Nodes supports a wide range of Windows OS, including older versions. In 2020, the solution will also be available for Linux machines.
The key factor that prevented operators from using traditional endpoint antivirus software on workstations was the operating system because the OS versions used were frequently incompatible with the available software. For the traditional endpoint antivirus solution to protect workstations properly, the information security team must upgrade the operating systems. These constant upgrades are expensive and risky because if an upgrade is not completed, the system remains an easy target for cyberattacks.
Moving to KICS for Nodes allows the organization to avoid the cost of software upgrades while helping ensure the necessary level of protection.
KICS for Networks
KICS for Networks monitors the OT communication protocols. The solution analyzes protocols in real time and detects anomalies. This helps operators recognize attacks and react in time. Furthermore, this solution is valuable for decrypting forensics after a cyberattack based on the alerts, events list, and asset map.
As industrial systems become increasingly connected in this age of digitalization, operators must be trained to deal with potential threats stemming from more connectivity. This is especially true when working with third-party contractors that support OT networks. In the future, operators will want a better understanding of communications in the OT network to allow early detection of attacks on the network to avoid major damage. But reviewing systems for cybersecurity risks is costly and time consuming. Systems that constantly monitor automation and document changes are needed. Clearly, endpoint protection of an ICS component alone is no longer enough. Industrial anomaly and breach detection solutions such as KICS for Networks can help fulfill the needed requirements.
Digitalization Increases Need for Effective Cybersecurity
The digitalization of industry will continue. Key elements of digitalization initiatives cover architecture of the digital factory with processes and operations traceability together with digital twins of product, production and performance. With this approach an asset owner gains insight to increase labor productivity and optimize core industrial vertical and horizontal chains.
This requires more sensors and distributed computer systems to collect and pre-process the data. The number of interfaces within the system and to the internet will increase. All these interfaces are vulnerable, and sensor data can be manipulated.
In the future, intelligent, self-learning systems will be needed to ensure the integrity of automation systems. Only in this way can the required future cybersecurity be achieved.
In the future, software functions such as machine learning and anomaly detection will be used together with cybersecurity solutions. This software will also detect other anomalies such as faulty devices and human errors and thus avoid costly plant downtime, which will have a further positive effect on the efficiency of the methods used.
Kaspersky Solutions for Future Security Challenges
Kaspersky is constantly assessing future challenges with asset owners to enhance security solutions. Some of these challenges are described below.
Cyber-immunity
Industry develops and changes every year. Today, industry is facing challenges that nobody could imagine five years ago. Cyber-threats are growing in frequency and complexity.
According to Kaspersky, the current cybersecurity situation requires a drastically different approach - a transition from cybersecurity to "cyber-immunity," which implies that the cost of a cyber-attack should exceed the cost of the damage that it could inflict.
Secure-by-design
The closer integration of machines, products, and processes generates data and creates the basis for digital business models. However, data integrity and secure data exchange are mandatory. Compared with office IT, industrial security requires high plant availability and real-time functionality. An important factor is the time needed to detect and react to malicious communication. At the Hanover Fair 2019, Kaspersky and its partners presented what they claim to be the first industrial gateway with a “secure-by-design” architecture. Furthermore, a Vulnerability Monitor App was launched to display cyber-vulnerabilities in real time.
Kaspersky Interactive Protection Simulation (KIPS)
The Kaspersky Interactive Protection Simulation (KIPS) solution provides users with an opportunity to learn and optimize cybersecurity decisions in a safe, but realistic offline environment. This simulation explains the various automation components, their vulnerability to cyberattacks, and the significance of the decisions made in case of emergency.
KICS & MLAD: Insight into Condition-based Monitoring
Asset owners are constantly looking for opportunities to increase the productivity of production sites by improving the uptime of components and achieving failure-free production. Kaspersky has developed an anomaly detection tool called MLAD (machine learning for anomaly detection), powered by KICS, that targets process control applications and makes it possible to detect situations that may influence production sites negatively, including cyberattacks.
With the MLAD information, operators can carry out condition-based maintenance that leads to less unscheduled machine downtime. By increasing the efficiency of the machines and reducing the spare parts inventories required, ROI could potentially be achieved within just 12 months according to the company.
Conclusion
Kaspersky, a trusted IT security provider and partner to many leading industrial companies, also works with leading industrial automation suppliers. The company’s goal is to develop specialized methods and collaborative frameworks to protect industrial systems from cyberthreats, including targeted attacks.
Kaspersky Industrial Cybersecurity combines different protection methods within a coordinated security framework to provide a holistic approach to industrial cybersecurity. This includes predicting potential attack vectors and rapidly detecting and defending against cyber-incidents. But since effective technology alone is often not adequate, this security offering also includes operator training to help eliminate vulnerabilities related to human error.
ARC Advisory Group clients can view the complete report at ARC Client Portal
If you would like to buy this report or obtain information about how to become a client, please Contact Us
Keywords: Digitalization, Kaspersky Industrial Cybersecurity, Endpoint Protection, Industrial Network Monitoring, Anomaly and Breach Detection, IEC 62443, ARC Advisory Group.