• About US
  • Terms of use
  • Cookie Policy
  • Privacy Policy
  • Advertising guide
No Result
View All Result
BBG Architecture Life
  • Architecture
  • Design
  • Interiors
  • Technology
  • Trends
  • Projects
  • Collections
  • Education
  • House
  • Restaurant
  • Greenhouse
  • Hotel
BBG Architecture Life
  • Interiors

    Miami Beach residence by SAOTA takes indoor-outdoor living to the extreme

    Vision unveiled for London school powered by Thames tide

    Erasmus exchange programme could remain open to UK students after Brexit

    Sou Fujimoto creates ornate bookshelves for Basel installation

    Frank Lloyd Wright merged eastern and western architecture at Tokyo’s Imperial Hotel

    Drone footage captures brutalist Robin Hood Gardens ahead of imminent demolition

    Dan Brunn renovates Frank Gehry-designed LA house for an illustrator

  • Design
    Screen Shot 2019-10-14 at 8.49.03 AM

    The Design Spark 2019 Product Showcase Set to Show Innovations Around Independent Living | Best Brothers Group of Companies

    Ho (left) and Chang sharing EcoWorld’s future plans at the Eco Sanctuary Gallery. (Photos by Low Yen Yeing/EdgeProp.my)

    Malaysia: Universal Design for EcoWorld’s Future Projects | Best Brothers Group of Companies

    A computer model of one of the accessible homes.

    How Gaming Technology is Helping Design More Accessible Homes | Best Brothers Group of Companies

    New Universal Design Guide Aims to make Public Spaces Pleasant for All | Best Brothers Group of Companies

    New Universal Design Guide Aims to make Public Spaces Pleasant for All | Best Brothers Group of Companies

    University Students Design Wheelchair Hand Warmer for Persons with Muscular Dystrophy | Best Brothers Group of Companies

    University Students Design Wheelchair Hand Warmer for Persons with Muscular Dystrophy | Best Brothers Group of Companies

    The Home Innovation Challenge

    UK-based Design Council Focuses on Accessible Home Innovation   | Best Brothers Group of Companies

    Private Transport Provider to Offer an Inclusive Experience in Malta   | Best Brothers Group of Companies

    Autonomous Vehicle Design Should Benefit Broader Group of Potential Drivers   | Best Brothers Group of Companies

    Ikea to Use 3-D Printing to Make Furniture More Accessible for Persons with Disabilities   | Best Brothers Group of Companies

    Ikea to Use 3-D Printing to Make Furniture More Accessible for Persons with Disabilities   | Best Brothers Group of Companies

    Toyota Improves Universal Design Taxicab for Quicker Wheelchair Access   | Best Brothers Group of Companies

    Toyota Improves Universal Design Taxicab for Quicker Wheelchair Access   | Best Brothers Group of Companies

  • Technology
    Dahua USA Releases New LincX2PRO Line Linking Homes with Professional Systems – Dahua Technology USA Inc | Best Brothers Group of Companies

    Dahua USA Releases New LincX2PRO Line Linking Homes with Professional Systems – Dahua Technology USA Inc | Best Brothers Group of Companies

    Dahua Helps Retail Operations Run Smoothly – Dahua Technology USA Inc | Best Brothers Group of Companies

    two people seated on a table and signing agreements Two people standing behind them on a stage.

    Mada Assistive Technology Centre Signs MoU with Korea Trade Promotion Agency | Best Brothers Group of Companies

    A computer model of one of the accessible homes.

    How Gaming Technology is Helping Design More Accessible Homes | Best Brothers Group of Companies

    Government of Canada Announces New Accessible Technology Program Funding Recipients | Best Brothers Group of Companies

    Dahua Technology USA Announces Product Lineup for GSX 2019 – Dahua North America | Best Brothers Group of Companies

    Dahua Technology Partners with Pepper to Bring Heightened Security to Its Video IoT Devices – Dahua North America | Best Brothers Group of Companies

    Dahua Technology Partners with Pepper to Bring Heightened Security to Its Video IoT Devices – Dahua North America | Best Brothers Group of Companies

    India: Assistive Technology for All 2030 Conference Focuses in Infrastructure, Assistive Devices | Best Brothers Group of Companies

    India: Assistive Technology for All 2030 Conference Focuses in Infrastructure, Assistive Devices | Best Brothers Group of Companies

    Private Transport Provider to Offer an Inclusive Experience in Malta   | Best Brothers Group of Companies

    National Federation of the Blind Applauds Introduction of Greater Access and Independence through Nonvisual Access Technology (GAIN) Act | Best Brothers Group of Companies

  • Projects
    Ho (left) and Chang sharing EcoWorld’s future plans at the Eco Sanctuary Gallery. (Photos by Low Yen Yeing/EdgeProp.my)

    Malaysia: Universal Design for EcoWorld’s Future Projects | Best Brothers Group of Companies

    European Commission Provides 20 Cities with Funding for Innovative Projects on Inclusion  | Best Brothers Group of Companies

    European Commission Provides 20 Cities with Funding for Innovative Projects on Inclusion  | Best Brothers Group of Companies

    The Portland Art & Learning Studio Encourages Diverse Projects by Artists with Disabilities | Best Brothers Group of Companies

    The Portland Art & Learning Studio Encourages Diverse Projects by Artists with Disabilities | Best Brothers Group of Companies

    Yoocan Seeks Collaborative Partners, Highlights Projects at Naidex 2019   | Best Brothers Group of Companies

    Yoocan Seeks Collaborative Partners, Highlights Projects at Naidex 2019   | Best Brothers Group of Companies

    Vision unveiled for London school powered by Thames tide

    Climate change forces emergency repairs to “failsafe” Arctic seed vault

    Grenfell Tower fire deaths raise questions about safety of post-war renovations

    Santiago Calatrava’s World Trade Center Oculus continues to leak

    Note Design and Afteroom hack IKEA kitchens to make living room furnishings for Reform

No Result
View All Result
BBG Architecture Life
No Result
View All Result
Home BBG

Active Network Scanning in OT Environments

Admin by Admin
November 8, 2019
in BBG
0 0
0
Active Network Scanning in OT Environments
333
SHARES
2k
VIEWS
Share on FacebookShare on TwitterShare on Google Share on Linkedin
Active Network Scanning in OT Environments


By Zane Blomgren, Belden


Periodic active network scanning is generally essential to maintain an accurate picture of the network, as significant information is only available upon request and otherwise never present in normal traffic.


The reason for passive traffic analysis is that many industrial control systems (ICS) devices were really only designed to function as expected and are often not tested to maintain function when they receive traffic other than designed. For example, I’ve seen RFID controllers and Anybus modules lock up, simply by receiving packets that confused them.


Active network scanning can deliver much more information than passive scanning, and can be an incredibly valuable tool in any industrial environment. However, as I noted in a previous blog post, devices in the industrial environment – including VFD s , PLCs, I/O blocks, actuators and sensors – can be more sensitive than those in the office environment.


Standard IT methods for network scanning cannot be used in an industrial environment without planning and forethought.


Precautions need to be taken; for example, scanning should be done delicately and while machines are not operating due to the potential that the added traffic could add latencies and other issues. Yes, some machines could run just fine during an active scan, but it requires an additional study to verify that.


Operators can get all of the benefits of an active scan without concerns for their network by incorporating the proper proactive, responsible and knowledgeable planning before performing an active scan. Usually.


I say “usually” because my colleagues and I were recently involved in a situation that did not go 100% as planned. However, it had a fascinating outcome.


Example: Active network scanning achieved through partnership


We were brought in to perform an active scan on a network operated by a large automotive manufacturer. This client is very sophisticated and we have a close partnership with them.


They knew just what they wanted – an active network scan that would quickly and efficiently go deep into their network to identify every device and provide extremely detailed information. Their goal was to receive rich data about all of their systems along with thorough analysis and recommendations.


Through their relationship with Belden, the client chose to work with Tripwire specifically due to our experience and knowledge in this space. We scheduled the scan activity during a period that the line  was down for scheduled maintenance. The scan was designed to be performed in a slow, gentle manner throughout the network.


We expected the impact on the network to be the equivalent of a light breeze. Yet, it was soon reported that a VFD tripped. Of course, we were concerned. Could our scan have caused this? Fortunately, everyone involved looked at the situation objectively and quickly concluded that the extraordinarily gentle scan could not – or should not – have caused the failure.


As it turns out, the source was an existing, hidden vulnerability in the VFD that could have been triggered by a multitude of disruptive situations, including a broadcast storm or a series of malformed packets. It was incredibly fortunate that it was triggered harmlessly in this circumstance – if it had been triggered while the line was up, it could have been a serious issue, potentially shutting down production.


Our analysis confirmed for the client where the issue was stemming from and they approached the VFD manufacturer. To their credit, the manufacturer was grateful for the knowledge and agreed that what happened during our scanning activity should not have occurred. They tested the VFDs in their labs and addressed the issues, proactively correcting other reliability issues with modifications and firmware.


The end result is a better product and more reliable operation for all.


 


What would you do?


The reason I am discussing this situation is that active network scanning still has a bad reputation due to situations where IT professionals have applied the active monitoring methods common in the office environment without adapting to the sensitive nature of the OT environment, causing adverse device interactions.


With this reputation still lingering, it could have been natural for the automotive network operator to assume that when the VFD tripped, it was the result of a poorly executed active scan. Fortunately, they were involved in and knowledgeable about the very careful precautions taken to alleviate any potential negative impacts while getting all the benefits of active network scanning.


With open eyes, they investigated the situation and accurately identified the source of the issue. And that was the first step towards solving the problem and ensuring that it doesn’t happen again. I must also give credit to the drive manufacturer, who took the opportunity to address the situation and improve further upon a quality product. Truth is, this could have been a story where everyone was angry and finger pointing. But instead, it was a partnership where everyone looked in the right direction and ultimately benefited from the situation.


So I’d like to ask—if this happened in your facility, what would you have done? Would you have jumped to conclusions, or investigated the situation? I welcome a dialog.




Related Links

Did you Enjoy this Article?

Check out our free e-newsletters
to read more great articles.

Subscribe Now

Active Network Scanning in OT Environments


By Zane Blomgren, Belden


Periodic active network scanning is generally essential to maintain an accurate picture of the network, as significant information is only available upon request and otherwise never present in normal traffic.


The reason for passive traffic analysis is that many industrial control systems (ICS) devices were really only designed to function as expected and are often not tested to maintain function when they receive traffic other than designed. For example, I’ve seen RFID controllers and Anybus modules lock up, simply by receiving packets that confused them.


Active network scanning can deliver much more information than passive scanning, and can be an incredibly valuable tool in any industrial environment. However, as I noted in a previous blog post, devices in the industrial environment – including VFD s , PLCs, I/O blocks, actuators and sensors – can be more sensitive than those in the office environment.


Standard IT methods for network scanning cannot be used in an industrial environment without planning and forethought.


Precautions need to be taken; for example, scanning should be done delicately and while machines are not operating due to the potential that the added traffic could add latencies and other issues. Yes, some machines could run just fine during an active scan, but it requires an additional study to verify that.


Operators can get all of the benefits of an active scan without concerns for their network by incorporating the proper proactive, responsible and knowledgeable planning before performing an active scan. Usually.


I say “usually” because my colleagues and I were recently involved in a situation that did not go 100% as planned. However, it had a fascinating outcome.


Example: Active network scanning achieved through partnership


We were brought in to perform an active scan on a network operated by a large automotive manufacturer. This client is very sophisticated and we have a close partnership with them.


They knew just what they wanted – an active network scan that would quickly and efficiently go deep into their network to identify every device and provide extremely detailed information. Their goal was to receive rich data about all of their systems along with thorough analysis and recommendations.


Through their relationship with Belden, the client chose to work with Tripwire specifically due to our experience and knowledge in this space. We scheduled the scan activity during a period that the line  was down for scheduled maintenance. The scan was designed to be performed in a slow, gentle manner throughout the network.


We expected the impact on the network to be the equivalent of a light breeze. Yet, it was soon reported that a VFD tripped. Of course, we were concerned. Could our scan have caused this? Fortunately, everyone involved looked at the situation objectively and quickly concluded that the extraordinarily gentle scan could not – or should not – have caused the failure.


As it turns out, the source was an existing, hidden vulnerability in the VFD that could have been triggered by a multitude of disruptive situations, including a broadcast storm or a series of malformed packets. It was incredibly fortunate that it was triggered harmlessly in this circumstance – if it had been triggered while the line was up, it could have been a serious issue, potentially shutting down production.


Our analysis confirmed for the client where the issue was stemming from and they approached the VFD manufacturer. To their credit, the manufacturer was grateful for the knowledge and agreed that what happened during our scanning activity should not have occurred. They tested the VFDs in their labs and addressed the issues, proactively correcting other reliability issues with modifications and firmware.


The end result is a better product and more reliable operation for all.


 


What would you do?


The reason I am discussing this situation is that active network scanning still has a bad reputation due to situations where IT professionals have applied the active monitoring methods common in the office environment without adapting to the sensitive nature of the OT environment, causing adverse device interactions.


With this reputation still lingering, it could have been natural for the automotive network operator to assume that when the VFD tripped, it was the result of a poorly executed active scan. Fortunately, they were involved in and knowledgeable about the very careful precautions taken to alleviate any potential negative impacts while getting all the benefits of active network scanning.


With open eyes, they investigated the situation and accurately identified the source of the issue. And that was the first step towards solving the problem and ensuring that it doesn’t happen again. I must also give credit to the drive manufacturer, who took the opportunity to address the situation and improve further upon a quality product. Truth is, this could have been a story where everyone was angry and finger pointing. But instead, it was a partnership where everyone looked in the right direction and ultimately benefited from the situation.


So I’d like to ask—if this happened in your facility, what would you have done? Would you have jumped to conclusions, or investigated the situation? I welcome a dialog.




Related Links

Did you Enjoy this Article?

Check out our free e-newsletters
to read more great articles.

Subscribe Now

© 2019, Best Brothers Group. All rights reserved.

Tags: ActiveEnvironmentsnetworkScanning
Admin

Admin

Canada 🇨🇦

0
Confirmed
0
Deaths
0
Recovered

Stay Connected

  • 1.4k Fan
  • 3 Follower
  • 35 Follower
  • 131 Follower

Popular Post

    Follow Our Page


    For all queries regarding print editions of BBG Architecture Life, including change of address, change of payment details requests and back issues, please contact +1-888-224-8688. Email: [email protected]
    • About US
    • Terms of use
    • Cookie Policy
    • Privacy Policy
    • Advertising guide

    Recent News

    Accessibility advocates say Peggy’s Cove viewing deck will ensure safe access for all - Halifax

    Accessibility advocates say Peggy’s Cove viewing deck will ensure safe access for all – Halifax

    January 24, 2021
    • Best Brothers Group
    • BBG Security Cameras
    • BBG Hub Home Automation
    • BBG Renovations
    • BBG Construction
    • BBG Business Partnership
    • BBG I/O Marketing
    • Security Cameras GK
    • Automatic Door Depot
    • About US
    • Terms of use
    • Cookie Policy
    • Privacy Policy
    • Advertising guide

    © 2018 BBG Architecture Life - supports the architecture industry on a daily news by Best Brothers Group.

    No Result
    View All Result
    • Interiors
    • Design
    • Technology
    • Projects

    © 2018 BBG Architecture Life - supports the architecture industry on a daily news by Best Brothers Group.

    Login to your account below

    Forgotten Password?

    Fill the forms bellow to register

    All fields are required. Log In

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In