Summary
Incident management has become a top priority for industrial cybersecurity professionals. Given the sophistication of modern attacks, it would be naïve to trust defenses to block all intrusions. The primary objective in protecting ICS environments is in preventing ICS incidents, i.e., make sure they “never happen.” For those you fail to prevent, minimizing the impact of the compromise is imperative. This requires a proven strategy for rapidly detecting and isolating intrusions and then remediating and restoring operations.
Effective incident management requires trustworthy information. This includes records of system events and messages, as well as master copies of backups, files, and database records. As time is of the essence, some companies implement security information and event management (SIEM) solutions to help defenders aggregate, filter, correlate, and analyze this voluminous information.
Smart attackers understand the value of this information and do their best to modify and erase all records of what they did. Limiting attacker access to these files is essential but challenging for industrial facilities. Aggregation solutions, like SIEMs and support tools, require local access to repositories, and enables the attacker the same access. Connectivity and confidentiality constraints often preclude offsite solutions, like cloud storage. Even with cloud backup, an attacker can access the data (as the backup system can) and delete or modify.
Executives from Waterfall Security Solutions focused on this issue during a recent briefing with ARC Advisory Group. The company’s flagship Unidirectional Security Gateways are well-recognized for fail-safe protection of critical systems. The company’s latest offering, Waterfall BlackBox, applies this technology to protect critical security information. This report summarizes the product’s key features that, according to the company, guarantee the security of critical incident management information.
More than Just Unidirectional Technology
Waterfall offers a comprehensive family of Unidirectional Security Gateway solutions. The core of these products is a unique, non-routable hardware-enforced, unidirectional communication technology. This provides high-speed, real-time, one-way information transfer from a sending network to a receiving network. This technology is designed to physically block all attempts to send messages in the reverse direction and protect the confidentiality of the information in-transit. While there are many applications for this technology, the use-case discussed in this report is the isolation of security data repositories, including those locally inside the ICS networks and centralized SIEMs, from the reach of an attack.
Agents Supervise Information Transfers
All Unidirectional Gateway products are combinations of hardware and software. Waterfall‘s sending and receiving software connectors limit and manage all information transferred across the Waterfall link. For the company’s unidirectional gateway, these connectors create real-time “mirror images” of specific information sources in the sending environment in the receiving environment. This provides a way to share plant information with corporate systems that doesn’t open pathways for external malware to enter. It also ensures that malware in the plant cannot communicate with command and control centers.
Waterfall provides a variety of off-the-shelf software connectors for its Unidirectional Gateways that understand common industrial information files and transfer needs. This includes agents designed specifically for popular HMIs and historians, database replication, and industrial protocols like OPC and Modbus.
BlackBox Reflects Expertise In Preventing ICS Incidents
Waterfall BlackBox uses unidirectional technology to provide a secure border between applications on the plant side and an internal storage system.
Software connectors embedded in the BlackBox software support the collection and transfer of critical information, for a wide range of sources, environments, and topologies, across an internal unidirectional gateway to secure storage within the device. This includes:
- Syslog, SNMP, Windows Logs, etc.
- FTP, CIFS, SFTP, system backups, etc.
- SQL Server, Oracle and other relational databases
- Other file sources & backups
- Network traffic and statistics
Connectors on the receiving end of the internal unidirectional link save this information in the on-board storage, with time stamps and optional encryption. Once data is sent past the internal Unidirectional Gateway, the data becomes inaccessible from the network, i.e., an attacker cannot access or manipulate it.
All “BlackBox’ed” tracks left by an attacker before and during the attack are untampered, trustworthy and available for incident response teams and forensics analysis. These agents also support secure retrieval of the information locally, at the BlackBox appliance, using a dedicated out-of-band port. Retrieved information can be used directly to support incident response efforts and compared to records retrieved directly from potentially compromised sources. Any differences between BlackBox and external records is a strong indicator of compromise.
Functionally, this provides the basic capabilities of a SIEM. However, according to the company, the distinguishing feature of the Waterfall BlackBox is its inherent protection of the information from any possible tampering.
The company indicates that the product can support up to 1GB per second transfer rates. Storage capacity is also expandable.
Recommendations
Waterfall Security Solutions’ family of unidirectional networking products demonstrates that the company has a deep understanding of industrial cybersecurity challenges. This provides a high level of confidence that the Waterfall BlackBox product can provide industrial end users with a solid, straightforward solution to a very significant cybersecurity challenge. ARC recommends that industrial companies consider how this product might be applied as a secure backup repository for other critical information, particularly in facilities with significant IP and/or regulatory restrictions on offsite information storage.
If you would like to buy this report or obtain information about how to become a client, please Contact Us
Keywords: Industrial Cybersecurity, Risk Management, Unidirectional Security Gateways, ARC Advisory Group.