Techday
This page was machine-translated and may differ from the original. View original

[Issue] Industrial IoT Security: Thinking of IT and OT Separately Will Leave You 'Vulnerable'

Google 우선 소스Published2017.08.21 11:48
Industrial IoT Focused on Functionality Alone, Security Lacking
Expertise Strong, But Integrated Ecosystem Needed to Lead Market

"As interest in industrial IoT has grown, companies have focused on IoT's core functionality while security has been neglected. When IoT brings IT and OT together, dividing responsibility creates security difficulties. How to build partnerships and form an ecosystem will be the key to leading the market," said Choi Seung-hwan, Senior Director at Frost & Sullivan, in his outlook on Asia-Pacific industrial control systems at an industrial control systems security conference.

"Security-related business has a lifecycle. Fear of the unknown, distinguishing between fiction and reality, educational consulting services emerge. After verification institutions for these services are established, actual revenue is generated. Currently, ICS (Industrial Control Systems) security appears to be in the educational consulting phase."

He cited government legislation, uncertainty regarding hacking, and solution awareness as reasons to accelerate ICS security adoption. He also predicted that ICS security will grow differently from IT.

"Until last year, I thought it would grow similarly. Looking at each vendor's technical approach this year, the security domain is expanding beyond software to hardware as well. It's a much larger scope than IT. It's a competitive landscape where industrial workers with various technologies are vying."

N&NS demonstrated a
unidirectional security gateway at the industrial control systems security conference

Yoon Sam-soo, Senior Executive at FireEye, introduced actual hacking cases and emphasized systematic ICS security strategy.

"Manufacturers are well-equipped with firewalls, IPS, APT and other solutions, but intrusion paths typically start from simple routes such as USB from related companies or employees' web browsing and emails."

Hackers prefer methods with high "value for effort"—good effectiveness relative to effort—rather than seeking ways to penetrate firewalls. Most cases involve viruses infiltrating through emails and USBs that employees inadvertently accessed.
Yoon Sam-soo, Senior Executive at FireEye, explaining attack cases

According to him, while not publicly disclosed, hacking incidents have occurred in manufacturing, nuclear power plants, and piping operations, resulting in confidential data leaks, and domestic companies have been attacked by automobile manufacturers and parts suppliers. Not only control-related personnel but all employees must recognize vulnerabilities, suspect network connections and processor management operations, and visualize security to manage issues.

"Attacks typically occur at stage 2, the control stage. Attackers will always get in 100%. However, you only realize it when the scenario unfolds. If you don't identify it beforehand, problems will emerge."
To request a correction, reply or follow-up report on this article, see how to file a request. Previously published statements are collected in corrections & replies.
김자영 Reporter