Sony Pixel Power calrec Sony

Belden Research Shows at Patching for Industrial Cyber Security is a Broken Model

14/03/2013

ST. LOUIS--(BUSINESS WIRE)--Belden Inc. (NYSE: BDC), a global leader in signal transmission solutions for mission-critical applications, announces that its Tofino Security brand has published new research showing that patching is often ineffective in providing protection from the multitude of vulnerability disclosures and malware targeting critical infrastructure systems today. While patching such systems is important as part of an overall Defense in Depth strategy, the difficulties of patching for industrial systems mean that compensating controls such as Tofino Security Profiles are often a better method of providing immediate protection.

My research highlights the multiple challenges with patching for SCADA and ICS systems

Since the discovery of the Stuxnet malware in 2010, industrial infrastructure has become a key target for security researchers, hackers, and government agents. Designed years ago with a focus on reliability and safety, rather than security, Supervisory Control and Data Acquisition (SCADA) and Industrial Control Systems (ICS) products are often easy to exploit. As a result, there has been exponential growth in government security alerts for these systems in the past two years. In addition, they have attracted some of the most sophisticated (Stuxnet, Night Dragon, Flame) and damaging (Shamoon) cyberattacks on record.

Eric Byres, CTO and vice president of engineering at Tofino Security, investigated the effectiveness of patching for protecting control systems from vulnerability exploits and malware. His work revealed that:

The number of vulnerabilities existing in SCADA/ICS applications is high, with as many as 1,805 yet to be discovered vulnerabilities existing on some control system computers.

The frequency of patching needed to address future SCADA/ICS vulnerabilities in both controllers and computers likely exceeds the tolerance of most SCADA/ICS operators for system shutdowns. Unlike IT systems, most industrial processes operate 24x7 and demand high uptime. Weekly shutdowns for patching are unacceptable.

Even when patches can be installed, they can be problematic. There is a 1 in 12 chance that any patch will affect the safety or reliability of a control system, and there is a 60% failure rate in patches fixing the reported vulnerability in control system products. In addition, patches often require staff with special skills to be present. In many cases, such experts are often not certified for access to safety regulated industrial sites.

Patches are available for less than 50% of publically disclosed vulnerabilities.

Many critical infrastructure operators are reluctant to patch as it may degrade service and increase downtime.

When patching is not possible, or while waiting for a semi-annual or annual shutdown to install patches, an alternative is to deploy a workaround, also known as a compensating control'. Compensating controls do not correct the underlying vulnerability; instead, they help block known attack vectors. Examples of compensating controls include product reconfigurations, applying suggested firewall rules, or installing signatures that recognize and block malware.

Another compensating control is Tofino Security Profiles, available in Belden's Tofino Security product line. Tofino Security Profiles are rule and protocol definitions that address newly disclosed vulnerabilities. They provide a simple way for automation system vendors to create and securely distribute malware protection. Operators benefit from a single, easy-to-deploy package of tailored rules that can be installed without impacting operations. The result is that critical industrial infrastructure facilities can quickly and effectively defend themselves against new threats.

My research highlights the multiple challenges with patching for SCADA and ICS systems, remarked Eric Byres. To secure facilities, critical infrastructure operators should pursue a Defense in Depth strategy that includes patching when possible, and use compensating controls for protection when patching is not possible.

Starting today, Belden is publishing a series of blog articles on its patching research and is accompanying them with useful documents. These documents include:

Patching for Control System Security - A Broken Model?; a presentation that summarizes its patching research,

Patching for Control System Security - A Broken Model? a peer reviewed published paper,

and Solving the SCADA/ICS Security Patch Problem, a White Paper.

Visit: http://www.tofinosecurity.com/blog/scada-security-welcome-patching-treadmill for the first blog article.

Tofino Security provides practical and effective industrial network security and SCADA security products that are simple to implement and that do not require plant shutdowns. Its products include configurable security appliances with a range of loadable security modules plus fixed function security appliances made for specific automation vendor applications. Tofino Security products protect zones of equipment on the plant floor, and are complementary to Belden's Hirschmann brand, which leads industrial networking solutions. Both groups service and secure industrial networks in the oil and gas, utilities, transportation and automation industries. www.tofinosecurity.com

About Belden

St. Louis-based Belden Inc. designs, manufactures, and sells connectivity solutions for markets including industrial, enterprise, and broadcast. It has approximately 6,700 employees, and has manufacturing capabilities in North America, South America, Europe, and Asia, and a market presence in nearly every region of the world. Belden was founded in 1902, and today is a leader with some of the strongest brands in the signal transmission industry. For more information, visit www.belden.co
LINK: http://us.vocuspr.com/Newsroom/ViewAttachment.aspx?SiteName=belden&Ent...
See more stories from belden

Most recent headlines

04/08/2024

Dalet Appoints Santiago Solanas as CEO to Lead Next Era of Growth and Innovation

Dalet, a leading technology and service provider for media-rich organizations, is excited to announce Santiago Solanas as its new Chief Executive Officer (CEO)....

03/06/2024

Dalet and Veritone Reach Agreement to Distribute, Transact and Monetize Media Archives

Dalet, a leading technology and service provider for media-rich organizations, a...

25/05/2024

Get to Know This Summer's Filmmakers Through These 12 Sundance Films

(L-R) Writer-director Hannah Pearl Utt and co-writer Jen Tullock star as sisters in Before You Know It, which premiered at the 2019 Sundance Film Festival....

25/05/2024

Study: Digital Media Ad Spend Grew 18% in Q1 24

NEW YORK A new study from Guideline indicates that In Q1 2024, large US advertisers expanded their overall ad spend by 7% compared to the year prior and that di...

25/05/2024

Accedo Helps ITV Expand ITVX to Sony PlayStation 4 and 5

STOCKHOLM Global video solutions provider, Accedo has announced that it worked with ITV in the U.S. to expand the reach of the broadcasters streaming service, I...

25/05/2024

Broadband Forum Celebrates 20th Anniversary of TR-069 Standard

Broadband Forum has announced that it is celebrating the 20-year anniversary of its groundbreaking TR-069 standard that has paved the way for the open standards...

25/05/2024

TV Tech Weekly Tech Wrap-Up

Missed any of our coverage of new products, services and deployments during your busy week? The TV Tech weekly wrap-up provides links to all of our product cove...

25/05/2024

HBO Original Series 30 Coins Season Two Finished with DaVinci Resolve Studio

HBO Original Series 30 Coins Season Two Finished with DaVinci Resolve Studio Brie Clayton May 24, 2024 0 Comments Blackmagic Design announced today th...

25/05/2024

VideoProc Converter AI: Your Answer to Video Format Challenges and Quality Enhancement

VideoProc Converter AI: Your Answer to Video Format Challenges and Quality Enhan...

24/05/2024

The Hives Celebrate 50 Years of Sweden's Global Music Success With Spotify Singles Cover

On April 6, 1974, the Swedish pop quartet ABBA won the Eurovision Song Contest w...

24/05/2024

The U.K. Holds Firm in the Fight for Fair Competition With the DMCC Act, But It's Not Over Yet

For more than a year, the U.K. government has been working to redefine how the i...

24/05/2024

Alone Australia continues to build as it moves towards finale

Alone Australia continues to build as it moves towards finale 23 May, 2024 Media releases The program continues to deliver for SBS with significant uplifts...

24/05/2024

EditShare Introduces Expanded Product Line-Up at BroadcastAsia

EditShare Introduces Expanded Product Line-Up at BroadcastAsia Transforming innovations in workflow, server and delivery from storyboard to screen Boston, MA...

24/05/2024

ZEISS CinCraft Scenario Camera Tracking Now Compatible wi...

Scenario 2.0 introduces pre-calibrated lens templates and the Lens Template Finetuner, increasing flexibility and compability while also saving a great amount o...

24/05/2024

Chyron Unlocks a Complete Newsroom in the Cloud With News...

Based on a long-term, coordinated development effort, Chyron today announced sweeping improvements across its news workflow portfolio that empower broadcasters ...

24/05/2024

Cobalt Expands its Reach into the AV Market with Plans to...

Cobalt Digital, known for its vast array of signal processing products, is strengthening its position in the Pro AV market by exhibiting at InfoComm 2024 for th...

24/05/2024

IHSE USA Earns Coveted Awards at the 2024 NAB Show

HSE USA today announced that the company s JPEG-XS IP Core for KVM and kvm-tec Scalable Pro Line 5K were honored with three awards at this year's NAB Show i...

24/05/2024

Aputure Gears Up for the 2024 Cine Gear Expo

Aputure, creators of LED lighting for filmmakers, is excited to showcase its award-winning lineup of professional lighting solutions at the upcoming Cine Gear E...

24/05/2024

EVERTZAV JOINS GPA GLOBAL PARTNER PROGRAM

EvertzAV (https://av.evertz.com), a division of Evertz, the global leader in providing professional A/V over IP solutions, is proud to announce its partnership ...

24/05/2024

Metropolis Studios Upgrades To Prism Sound Dream ADA-128...

With 25 Prism Sound ADA-8XR multichannel converters already in use across its five studios, the internationally acclaimed Metropolis Studios in London is no str...

24/05/2024

Leader Expands LVB440 IP Analyzer with New Measurement To...

Leader Electronics Corporation, globally active innovator of broadcast-quality test and measurement instrumentation, announces an expansion to the capabilities ...

24/05/2024

Digital Alert Systems and Inovonics Partner on Joint Solu...

Digital Alert Systems, the global leader in emergency communications solutions for video services providers, and broadcast equipment provider Inovonics today an...

24/05/2024

Time in Pixels Updates OmniScope with New Twin Peaks Scope for Professional Colorists and DITs

Time in Pixels Updates OmniScope with New Twin Peaks Scope for Professional Co...

24/05/2024

ZEISS CinCraft Scenario Camera Tracking Now Compatible with Most Popular Lens Brands

ZEISS CinCraft Scenario Camera Tracking Now Compatible with Most Popular Lens Br...

24/05/2024

Inaugural Gnome Opener in Greenville TONIGHT

Tonight's the night! The Greenville Yard Gnomes open their inaugural home season at Guy Smith Stadium! Join the Gnomes for all the fun and excitement of t...

24/05/2024

Boston Conservatory Plays a Leading Role at the 41st Annual Elliot Norton Awards

Boston Conservatory Plays a Leading Role at the 41st Annual Elliot Norton Awards With five wins and eight additional nominations, the Conservatory's theat...

24/05/2024

UK's Media Bill heads towards Royal Assent

An amendment to the Bill includes retaining the Reithian principles of public service broadcast, ensuring PSBs continue to inform, educate and entertain By Jen...

24/05/2024

BCE appoints Sylvain Merle as CTO

Merle joins BCE following a 30 year career including roles at Orange/Globecast and beIN Media Group By Matthew Corrigan Published: May 24, 2024 Merle join...

24/05/2024

FCC Chair Rosenworcel Proposes FCC Require Disclosure of AI Content in Political Ads

WASHINGTON, D.C. As concerns grow about the potential impact of fake AI-generate...

24/05/2024

Robin Davis Named Senior VP, Chief Distribution Officer for Scripps

CINCINNATI The E.W. Scripps Company has named Robin Davis as its senior vice president, chief distribution officer....

24/05/2024

Nilesat Chooses PlayBox Neo Solutions for Major Service Expansion

CAIRO, Egypt PlayBox Neo has announced that it is providing technologies for the expansion of the broadcast channel management and playout infrastructure at the...

24/05/2024

FCC's Carr Opposes Effort to Require Disclosure of AI-Content in Political Ads

WASHINGTON, D.C. FCC Commissioner Brendan Carr has come out against a proposal b...

24/05/2024

FCC Commissioner Simington Announces Staff Changes

WASHINGTON, D.C. Federal Communications Commission commissioner Nathan Simington has announced several staff changes with one departure from his office, one new...

24/05/2024

The Increasingly Important Role of IPTV in College & University Sports Venues

The Increasingly Important Role of IPTV in College & University Sports Venues Andy Wagner May 23, 2024 0 Comments According to Nielsen data, college b...

24/05/2024

Disguise Launches New Generation of EX Media Servers to Power the Future of Entertainment

Disguise Launches New Generation of EX Media Servers to Power the Future of Ente...

24/05/2024

Graded on Baselight 6.0 - rase Una Vez En El Caribe (Once Upon a Time in the Caribbean)

Graded on Baselight 6.0 - rase Una Vez En El Caribe (Once Upon a Time in the Ca...

24/05/2024

Local News Close-Up: South Central Pa.'s HLLY' Market Is on the Rise

Harrisburg-Lancaster-Lebanon-York is one of just two four-city DMAs in Nielsen's top 50, and the so-called HLLY market (pronounced hilly ) offers small-tow...

24/05/2024

Calif. Court Dismisses Michael Kassan's Slander Suit Against UTA Lawyer

Former MediaLink head Michael Kassan's slander and libel suit against a lawyer for UTA has been dismissed....

24/05/2024

Mission Broadcasting Terminates Agreement To Buy WADL Detroit

Mission Broadcasting has sent a letter to Adell Broadcasting terminating Mission's agreement to purchase WADL Detroit for $75 million....

24/05/2024

Host Patton Oswalt On How To Win on The 1% Club' Game Show

The 1% Club, a game show hosted by Patton Oswalt, debuts on Prime Video May 23 and then on Fox June 3. The show is not so much about answering trivia questions,...

24/05/2024

Pete Hegseth, Fox & Friends Weekend' Co-Host, Publishes New Book

Pete Hegseth, Fox & Friends Weekend co-host, releases his book The War on Warriors: Behind the Betrayal of the Men Who Keep Us Free June 4. Published by Fox New...

24/05/2024

The CW Orders More Wild Cards'

The CW has renewed drama Wild Cards for a second season. Vanessa Morgan and Giacomo Gianniotti are in the cast. There will be 13 episodes....

24/05/2024

COBALT DIGITAL at InfoComm 2024 - Booth # C8483

COBALT DIGITAL at InfoComm 2024 - Booth # C8483 May 24, 2024 InfoComm Booth # C8483 Journalists: Click to schedule a visit to Cobalt Cobalt Expands its Reac...

24/05/2024

Add Punch & Snap to Drum Hits

By Craig Anderton A Pro EQ3 stage's gain can respond dynamically to incoming signal level, so that louder inputs kick the gain higher (or lower). But Studi...

24/05/2024

Yahsat Awarded Highest Tier 4 Certification from World Teleport Association

The certification underscores world-class standards of services at Yahsat's Abu Dhabi Teleport Abu Dhabi, United Arab Emirates, 21 May 2024: Al Yah Satelli...

24/05/2024

Tribeca Festival and Canva Announce Return of Kickstart With Canva a Creative Program in Collaboration with Tribeca

May 24th, 2024 Press Materials Available Here TRIBECA FESTIVAL AND CANVA ANNOU...

24/05/2024

Indy 500: NBC Sports Introduces Virtual Car, Pit-Box SpyCams to Memorial Day Tradition

Indy 500: NBC Sports Introduces Virtual Car, Pit-Box SpyCams to Memorial Day Tra...

24/05/2024

The New Big Sports (Video) Scene: Las Vegas Sports Venues Fire Up the Entertainment Capital of the World

The New Big Sports (Video) Scene: Las Vegas Sports Venues Fire Up the Entertainm...

24/05/2024

Inside DAZN's Host Broadcast of the UEFA Women's Champions League Final

Inside DAZN's host broadcast of the UEFA Women's Champions League Final By George Bevir Friday, May 24, 2024 - 09:00 Print This Story Dave Wade, D...

24/05/2024

UEFA Europa League Final 2024: Broadcast Facts and Figures for Atalanta BC vs Bayer 04 Leverkusen

UEFA Europa League Final 2024: Broadcast facts and figures for Atalanta BC vs Ba...