31
Are converged OT/IT Transport networks immune from attack? 2016 NYS Cyber Security Conference June 8-9, 2016

Are converged OT/IT Transport networks immune from attack? · Are converged OT/IT Transport networks immune from attack? 2016 NYS Cyber Security Conference June 8-9, 2016

  • Upload
    others

  • View
    0

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Are converged OT/IT Transport networks immune from attack? · Are converged OT/IT Transport networks immune from attack? 2016 NYS Cyber Security Conference June 8-9, 2016

Are converged OT/IT Transport networks

immune from attack?2016 NYS Cyber Security Conference

June 8-9, 2016

Page 2: Are converged OT/IT Transport networks immune from attack? · Are converged OT/IT Transport networks immune from attack? 2016 NYS Cyber Security Conference June 8-9, 2016

Critical Infrastructure

Chemical

Commercial Facilities

Communications

Critical Manufacturing

Dams

Defense Industrial Base

Emergency Services

Information Technology

Food & Agriculture

Government Facilities

Healthcare & Public Health

Transportation

Water & Wastewater

Nuclear Reactors, Materials & Waste

Financial Services

Energy

US Department of Homeland Security, December 2003

Page 3: Are converged OT/IT Transport networks immune from attack? · Are converged OT/IT Transport networks immune from attack? 2016 NYS Cyber Security Conference June 8-9, 2016

Current and Emerging Railway Services

Electronic Ticketing & Payment

WiFi Intelligent Transport Services

Video Surveillance Communication Based Train Control

Positive Train Control

Page 4: Are converged OT/IT Transport networks immune from attack? · Are converged OT/IT Transport networks immune from attack? 2016 NYS Cyber Security Conference June 8-9, 2016

Future - Urbanization

Population of the world’s cities

Present Day Projected for 2050

4.2 billion 7 billion

Demand for efficient and effective urban services will increase substantially.

Page 5: Are converged OT/IT Transport networks immune from attack? · Are converged OT/IT Transport networks immune from attack? 2016 NYS Cyber Security Conference June 8-9, 2016

Agenda

Introduction

Current Trends

Transport Communication Systems

Cyber Risk Management

Questions & Answers

Page 6: Are converged OT/IT Transport networks immune from attack? · Are converged OT/IT Transport networks immune from attack? 2016 NYS Cyber Security Conference June 8-9, 2016

Presenters

Anthony Concolino

QED National

Former Citi, Reuters

Systems EngineeringProduct ManagementIT/Risk [email protected]

212-481-6868x119

Ken Garmson

ARUP, Inc.

Former UK Ministries of Defense & Transport

Systems EngineeringIntelligent Transport

[email protected]

212-897-1548

Russell Kiernan

QED National

Former Merrill Lynch, Citi

Information SecurityRisk ManagementEnterprise [email protected]

212-481-6868x111

Page 7: Are converged OT/IT Transport networks immune from attack? · Are converged OT/IT Transport networks immune from attack? 2016 NYS Cyber Security Conference June 8-9, 2016

Transport Communication System Convergence

Ken Garmson

PAST

PRESENT

FUTURE

Page 8: Are converged OT/IT Transport networks immune from attack? · Are converged OT/IT Transport networks immune from attack? 2016 NYS Cyber Security Conference June 8-9, 2016

The Air Gap

Operational Communications

Corporate IT Network

Public Network

PAST

PRESENT

FUTURE

Page 9: Are converged OT/IT Transport networks immune from attack? · Are converged OT/IT Transport networks immune from attack? 2016 NYS Cyber Security Conference June 8-9, 2016

Operational SystemsPAST

PRESENT

FUTURE

Operational Communications

Network

Telephony

SCADA

CCTV

Signaling

Passenger InformationTicketing

Radio

Traction Power

Track Control

Page 10: Are converged OT/IT Transport networks immune from attack? · Are converged OT/IT Transport networks immune from attack? 2016 NYS Cyber Security Conference June 8-9, 2016

System Architecture

Station Systems SCADA

Traction Power

Control Center Signaling

Radio

LineCu/OF

(Voice, Video & Data)

Corporate IT

Network

Public Network

PAST

PRESENT

FUTURE

Safety Controls

Page 11: Are converged OT/IT Transport networks immune from attack? · Are converged OT/IT Transport networks immune from attack? 2016 NYS Cyber Security Conference June 8-9, 2016

Systems CommunicationPAST

PRESENT

FUTURE

Telephony

SCADA

CCTV

Signaling

Passenger Information

Page 12: Are converged OT/IT Transport networks immune from attack? · Are converged OT/IT Transport networks immune from attack? 2016 NYS Cyber Security Conference June 8-9, 2016

SDH Communication Systems

Telephony

SCADA

CCTV

Signaling

Passenger Information

SDH/SONET

PAST

PRESENT

FUTURE

Page 13: Are converged OT/IT Transport networks immune from attack? · Are converged OT/IT Transport networks immune from attack? 2016 NYS Cyber Security Conference June 8-9, 2016

SDH Transmission PathsPAST

PRESENT

FUTURE

… CCTV Pass. Info …

... SCADA Phone …

SCADA Phone CCTV Pass. Info

SDH … Virtual Container• Path Fixed (Direct

Connection)• Mixed Traffic Types

CCTV

Passenger Information

SCADA

CCTV

SCADAPhone

Phone

Passenger Information

Page 14: Are converged OT/IT Transport networks immune from attack? · Are converged OT/IT Transport networks immune from attack? 2016 NYS Cyber Security Conference June 8-9, 2016

Migration to IP based Communication Systems

PAST

PRESENT

FUTURE

RS 485 Video Audio

Modbus SCADA RTU

Legacy to IP converter

Page 15: Are converged OT/IT Transport networks immune from attack? · Are converged OT/IT Transport networks immune from attack? 2016 NYS Cyber Security Conference June 8-9, 2016

Present Systems Support

VoIP

Ticketing

WiFi

SCADA/RTUPublic Address

Passenger/Train Information

Internet

PAST

PRESENT

FUTURE

Page 16: Are converged OT/IT Transport networks immune from attack? · Are converged OT/IT Transport networks immune from attack? 2016 NYS Cyber Security Conference June 8-9, 2016

IP Network Communication System

PAST

PRESENT

FUTURE

Core & Edge

Internet

Private WiFi

Ticketing

SCADA/RTUPassenger/Train

Information

Remote Maintenance Access

Corporate Business Network

Operational Controls (including safety) are not eroded, while new risks are introduced.

Page 17: Are converged OT/IT Transport networks immune from attack? · Are converged OT/IT Transport networks immune from attack? 2016 NYS Cyber Security Conference June 8-9, 2016

Convergence of the Air GapPAST

PRESENT

FUTURE

Operational Communications

Corporate IT Network Public Network

Page 18: Are converged OT/IT Transport networks immune from attack? · Are converged OT/IT Transport networks immune from attack? 2016 NYS Cyber Security Conference June 8-9, 2016

Air Gap ReplacementPAST

PRESENT

FUTURE

Page 19: Are converged OT/IT Transport networks immune from attack? · Are converged OT/IT Transport networks immune from attack? 2016 NYS Cyber Security Conference June 8-9, 2016

Improving Critical Infrastructure Cybersecurity

“The cyber threat to critical infrastructure continues to grow and represents one of the most serious national security challenges we must confront.”

-Executive Order 13636

Russell Kiernan

Page 20: Are converged OT/IT Transport networks immune from attack? · Are converged OT/IT Transport networks immune from attack? 2016 NYS Cyber Security Conference June 8-9, 2016

NIST Cybersecurity – Framework Core

Identify

Protect

Detect

Respond

Recover

Page 21: Are converged OT/IT Transport networks immune from attack? · Are converged OT/IT Transport networks immune from attack? 2016 NYS Cyber Security Conference June 8-9, 2016

Core Framework - Identify

Identify

Protect

Detect

Respond

Recover

Asset Management

Business Environment

Governance

Risk Assessment

Risk Management Strategy

Page 22: Are converged OT/IT Transport networks immune from attack? · Are converged OT/IT Transport networks immune from attack? 2016 NYS Cyber Security Conference June 8-9, 2016

Core Framework – Protect

Identify

Protect

Detect

Respond

Recover

Access Control

Awareness and Training

Data Security

Information Protection

Processes & Procedures

Maintenance

Protective Technology

Page 23: Are converged OT/IT Transport networks immune from attack? · Are converged OT/IT Transport networks immune from attack? 2016 NYS Cyber Security Conference June 8-9, 2016

Core Framework – Detect

Identify

Protect

Detect

Respond

Recover

Anomalies and Events

Security Continuous

Monitoring

Detection Processes

Page 24: Are converged OT/IT Transport networks immune from attack? · Are converged OT/IT Transport networks immune from attack? 2016 NYS Cyber Security Conference June 8-9, 2016

Core Framework – Respond

Identify

Protect

Detect

Respond

Recover

Response Planning

Communications

Analysis

Mitigation

Improvements

Page 25: Are converged OT/IT Transport networks immune from attack? · Are converged OT/IT Transport networks immune from attack? 2016 NYS Cyber Security Conference June 8-9, 2016

Core Framework - Recover

Identify

Protect

Detect

Respond

Recover

Recovery Planning

Improvements

Communications

Page 26: Are converged OT/IT Transport networks immune from attack? · Are converged OT/IT Transport networks immune from attack? 2016 NYS Cyber Security Conference June 8-9, 2016

Implement/Enhance Cyber Capability

Step 1: Prioritize and Scope

Step 2: Orient

Step 3: Create a Current Profile

Step 4: Conduct a Risk Assessment

Step 5: Create a Target Profile

Step 6: Determine, Analyze, and Prioritize Gaps

Step 7: Implement Action Plan

Page 27: Are converged OT/IT Transport networks immune from attack? · Are converged OT/IT Transport networks immune from attack? 2016 NYS Cyber Security Conference June 8-9, 2016

Suggested Implementation

Simultaneous Approach

Perform Critical Cyber Assessments

EstablishCybersecurity

Capability

Page 28: Are converged OT/IT Transport networks immune from attack? · Are converged OT/IT Transport networks immune from attack? 2016 NYS Cyber Security Conference June 8-9, 2016

Perform Critical Cyber Assessments

Vulnerability Assessment

External Penetration Testing

Internal Penetration Testing

Wireless Assessment

Breach/Intrusion Detection

Assess

Risk

Treatment

Page 29: Are converged OT/IT Transport networks immune from attack? · Are converged OT/IT Transport networks immune from attack? 2016 NYS Cyber Security Conference June 8-9, 2016

Critical Cyber Assessments – Outcome

Report & Remediate

RISK RATING TABLE

IMPACT

PROBABILITY

Page 30: Are converged OT/IT Transport networks immune from attack? · Are converged OT/IT Transport networks immune from attack? 2016 NYS Cyber Security Conference June 8-9, 2016

Enhanced Security and Resilience

A comprehensive and persistent capability to more effectively address cybersecurity risk for processes, information, and systems directly involved in the delivery of critical infrastructure services.

Page 31: Are converged OT/IT Transport networks immune from attack? · Are converged OT/IT Transport networks immune from attack? 2016 NYS Cyber Security Conference June 8-9, 2016

Summary

Collective responsibility of all stakeholders involved

Air Gap erosion through the convergence of networks

Evaluate risks of newly converged systems

Implement enhanced controls

Develop comprehensive and persistent Cyber Risk capability