Skip to content

Protecting Industrial Networks: Analyzing a Cyber Attack on a Factory

The integration of IT and OT networks has brought significant benefits to industrial processes, including increased efficiency, real-time data access, and improved decision-making. However, this integration also brings serious security challenges that could threaten equipment availability and the integrity of factory data. Manufacturers rely on data to make critical business decisions, which can cause production delays, equipment failures, and even safety hazards if the data is compromised.

This blog post reviews and analyzes a potential cyber attack on a production factory and demonstrates how it could be detected using GREYCORTEX Mendel. It serves as an example of how network detection and response solutions can effectively protect against massive cyber attacks.

Traditional security approaches, such as air-gapping or DMZ, are no longer effective in protecting OT networks. Although existing security solutions are attempting to close the gap between IT and OT infrastructures, unfortunately, it is highly problematic to achieve. Industrial equipment is more outdated as its lifecycle is much longer than that of IT devices (which, in some cases, can be 20 years or more). Furthermore, IT professionals are responsible for network security in both IT and OT, whereas OT professionals are more concerned with maintaining smooth operations and data integrity than cybersecurity. And the lastly, IT and OT professionals have difficulty communicating and understanding each other due to the use of different terminologies, technologies, and educational orientations.

About the Factory

For this scenario, we will imagine that GREYCORTEX Mendel has been installed in a bakery consisting of three separate locations: the main office building, the storage and production building, and the packaging and logistics building. Although separate, the IT and OT networks of these locations are interconnected.

Attack Description

The cyber attack took place over the weekend. The attackers, who may have been amateurs, cybercriminals, or hackers hired by a competitor, were able to connect to a device that had an outdated operating system on the private office network via public Wi-Fi. Using the infected device, they launched a network scan and discovered production machines in remote facilities. The attackers gained control over the oven and packing line and made changes to their configuration.

Detection in GREYCORTEX Mendel

The first thing that IT or OT specialists would see in GREYCORTEX Mendel is a representation of the industry standard MITRE ATT&CK® Security Framework. It is a dashboard designed to be a connection point for IT and OT specialists as it uses terminology that is understandable for both sides. Here, they can detect security alerts concerning industrial equipment.

By going to the event section in Mendel, the analysts can filter all events related to the OT network and this cyberattack. Here, they detect that the attacks were able to infiltrate the internal network and, upon scanning, discover both IT and OT infrastructures. The cybercriminals found devices that were open and could be used to initiate a connection.

Security Alert: Temperature Change in the Oven

The attackers tested their ability to make changes to the machine settings. They connected to a device controlling the oven and altered the temperature.

Continuing in the incident investigation, the analysts observe that Mendel detected the change in the oven temperature. Upon analyzing this event, they discover that there was a connection from the engineering workstation from the IT network to a machine in the Storage and Preparation network over the MODBUS protocol. In the application layer, they detect that the attackers set a high temperature, which could result in the cookies coming out burnt.

Security Alert: Change in Packaging Settings

Similar to the oven, the attackers in this example attempted to connect to the packaging line and change its configuration.

Mendel also detected that the cybercriminals changed the default number of pieces per package. They connected to a system within the Packaging and Logistics network via the MODBUS protocol, and upon analyzing the application layer, it was discovered that only eight pieces would be placed in one box instead of the usual ten.

Mendel alerted the analysts to these changes because the default values for the oven were set to 200 degrees Celsius and ten pieces for a single package. Thus, Mendel is capable of detecting any changes that occur in the OT network.

Empower Your IT and OT Security

Industrial networks need to operate continuously without unscheduled interruption, making security a secondary concern. However, failing to secure industrial networks can lead to devastating consequences, including production downtime, equipment damage, and even physical harm. The reason why cyber attacks can happen in the first place is that OT protocols are not designed with security in mind, making them vulnerable to cyberattacks.

We have described just two examples of what potential attackers could do, but they could take multiple actions, such as infiltrating the system and testing their abilities to make minor changes in the configuration. Such changes may be unnoticeable for analysts and OT professionals. The attackers could then wait until the right moment, such as the launch of a new product, to cause significant damage.

Thanks to the ICS module, the advanced industrial intrusion detection system (IDS), GREYCORTEX Mendel is able to detect such an attack. Mendel alerts manufacturers to potential security threats in the early stages, providing valuable time to prevent attacks. To narrow the gap between IT and OT worlds, the detection dashboard based on the MITRE ATT&CK® framework was created, which uses unified terminology understandable for both IT and OT professionals.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About GREYCORTEX
GREYCORTEX uses advanced artificial intelligence, machine learning, and data mining methods to help organizations make their IT operations secure and reliable.

MENDEL, GREYCORTEX’s network traffic analysis solution, helps corporations, governments, and the critical infrastructure sector protect their futures by detecting cyber threats to sensitive data, networks, trade secrets, and reputations, which other network security products miss.

MENDEL is based on 10 years of extensive academic research and is designed using the same technology which was successful in four US-based NIST Challenges.

GREYCORTEX Mendel 4.1 Introduces a New User Interface

[May 31, 2023] — GREYCORTEX, a leading provider of network detection and response solutions, is pleased to announce the release of GREYCORTEX Mendel 4.1, featuring an all-new visually appealing interface that enhances the user experience.
 
With a strong focus on usability, GREYCORTEX Mendel 4.1 introduces a cleaner and more modern look, offering users an intuitive environment. The new user interface has been meticulously designed to reduce visual complexity and provide seamless access to essential data, enabling users to effortlessly navigate through the system.

We understand the importance of simplicity in user interfaces,” said Radek Hloušek, Product Manager at GREYCORTEX. ​Our goal with GREYCORTEX Mendel 4.1 was to create an interface that not only looks great but also enhances the overall user experience. We wanted to make complex functionality accessible and intuitive for our users, allowing them to focus on what matters most – detecting and mitigating cyber threats.

One of the standout features of the new Mendel UI is the availability of light and dark themes, providing users with the flexibility to choose a visual style that suits their preference and working environment. Whether it’s a bright and vibrant theme or a sleek and sophisticated dark mode, GREYCORTEX Mendel 4.1 offers a personalized experience to cater to diverse user needs.

Additionally, the new version brings integration with endpoint detection and response platforms and software-defined networking solutions to enable extended detection and response capabilities. Moreover, advanced filtering helps power users extract the precise information they are looking for. For OT customers, BACnet protocol processing offers visibility into building management systems.

GREYCORTEX Mendel 4.1 represents the company’s commitment to continuously innovating and improving its offerings, ensuring customers have access to cutting-edge solutions that enhance their cybersecurity.

More about GREYCORTEX Mendel 4.1.
 

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About GREYCORTEX
GREYCORTEX uses advanced artificial intelligence, machine learning, and data mining methods to help organizations make their IT operations secure and reliable.

MENDEL, GREYCORTEX’s network traffic analysis solution, helps corporations, governments, and the critical infrastructure sector protect their futures by detecting cyber threats to sensitive data, networks, trade secrets, and reputations, which other network security products miss.

MENDEL is based on 10 years of extensive academic research and is designed using the same technology which was successful in four US-based NIST Challenges.

How to Secure Building Management Systems

As infrastructure modernizes, building management systems (BMS) are becoming increasingly sophisticated. They provide automation, control and management of the physical environment of buildings, and to operate reliably, you need to ensure their security. This can be crucial in some buildings, such as hospitals. What can you do to make buildings safer?

An Introduction to BMS

BMS stands for Building Management System. It is a computer-based system that controls and monitors a building’s mechanical and electrical equipment, such as heating, ventilation, and air conditioning (HVAC), lighting, and other building systems. There are several common BMSs used in buildings today, each with their own specific features and capabilities, these include:
  • Siemens Desigo
  • Johnson Controls Metasys
  • Honeywell WEBs
  • Schneider Electric Andover Continuum
  • Trane Tracer
  • Delta Controls
There are many more systems and the choice of BMS depends on the specific requirements of the building and the needs of the building owner or operator. However, they have one thing in common – the BACnet protocol is frequently used between these systems and HVAC-endpoints.

BACnet Protocol: Essential for Building Management Systems Security

The Building Automation and Control Network (BACnet) protocol is a communication protocol that is widely used in building automation and control systems for HVAC, lighting, and other building systems. BACnet was designed to provide a standard way for different building systems to communicate and share data, and is now used in thousands of buildings worldwide. One of the key features of BACnet is its support for security. BACnet includes several security features to protect against unauthorized access, tampering, and other types of attacks. These features include:
  • Authentication: BACnet supports the use of passwords and other forms of authentication to ensure that only authorized users can access the building automation and control systems.
  • Encryption: BACnet supports the use of encryption to protect the confidentiality and integrity of data as it is transmitted between different devices and systems.
  • Access control: BACnet includes features to restrict access to specific objects and properties within the building automation and control systems. This allows building operators to control who can access and control different systems within the building.
  • Auditing: BACnet includes the capability to record and log all access to the building automation and control systems. This allows building operators to detect and investigate any unauthorized access or tampering.
Despite these security features, the BACnet protocol has some security weaknesses. For example, some security experts have raised concerns about the use of static passwords for authentication, which can be easily guessed or cracked by attackers. Additionally, BACnet does not include support for security certificates or other forms of digital authentication, which can make it more difficult to ensure that devices are communicating with the correct systems. Another concern with BACnet security is that its security feature is not widely implemented. Many building automation and control systems using BACnet do not have security features enabled or are configured in an insecure way. This leaves them vulnerable to attacks and can make it easy for unauthorized users to gain access to sensitive systems and data.
BACnet is a communication protocol that is widely used in building automation and control systems, and provides several security features to protect against unauthorized access and tampering. However, there are some concerns about the security of the protocol, particularly regarding the use of static passwords and the lack of wide implementation of security features. It is important for building operators to be aware of these security risks and to take steps to secure their building automation and control systems, such as regularly changing passwords, enabling encryption, and monitoring for suspicious activities.

Risk Mitigation in BMS Security

One of the most important aspects of risk mitigation is the visualization of the flows from and to a BMS, whether it is executed via BACnet or a different OT-protocol. This allows a user to optimize their network configuration, mitigating the risks of:
  • Static passwords
  • Lack of certificates
  • Disabled security features on various BACnet-enabled assets
One tool you can use for the flow visualization is GREYCORTEX Mendel, which has protocol parsers and BMS-asset identification built into its core.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About GREYCORTEX
GREYCORTEX uses advanced artificial intelligence, machine learning, and data mining methods to help organizations make their IT operations secure and reliable.

MENDEL, GREYCORTEX’s network traffic analysis solution, helps corporations, governments, and the critical infrastructure sector protect their futures by detecting cyber threats to sensitive data, networks, trade secrets, and reputations, which other network security products miss.

MENDEL is based on 10 years of extensive academic research and is designed using the same technology which was successful in four US-based NIST Challenges.

GREYCORTEX Mendel 4.0 Now Available

December 15, 2022 – We have released a new version of GREYCORTEX Mendel. Version brings a new view of security and risks that individual subnets and hosts bring, advanced NetFlow processing and integration with other tools and security platforms.

The new version is already available for new installations and will also be gradually released on December 19 for an online upgrade.

More about GREYCORTEX Mendel 4.0

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About GREYCORTEX
GREYCORTEX uses advanced artificial intelligence, machine learning, and data mining methods to help organizations make their IT operations secure and reliable.

MENDEL, GREYCORTEX’s network traffic analysis solution, helps corporations, governments, and the critical infrastructure sector protect their futures by detecting cyber threats to sensitive data, networks, trade secrets, and reputations, which other network security products miss.

MENDEL is based on 10 years of extensive academic research and is designed using the same technology which was successful in four US-based NIST Challenges.

GREYCORTEX Mendel 3.9.1. Now Available

September 20, 2022 – We have released GREYCORTEX Mendel 3.9.1 which brings minor improvements and bug fixes.

Enhancements

Event visibility level store its configuration on the user level (keep the last state before logout)

Improved performance and reliability for Failsafe mode

Improved subnet filtering by substring search in filter

Fixed issues with

  • Performance in the network capture module
  • Invalid license during Sensor&Collector upgrade
  • Default firewall configuration for an asset discovery tool
  • Checkpoint firewall rule policies
  • Detecting TOR traffic by IDS signatures
  • Resizing LVM storage on AWS
  • Two or more DNS servers on the management interface
  • Empty subnet graph for subnets filtered by tag(s)
  • User permissions
  • SSL configuration for Fortigate firewall plugin
  • Invalid CSV header in subnet import
  • Malformed input for network parsers
     

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About GREYCORTEX
GREYCORTEX uses advanced artificial intelligence, machine learning, and data mining methods to help organizations make their IT operations secure and reliable.

MENDEL, GREYCORTEX’s network traffic analysis solution, helps corporations, governments, and the critical infrastructure sector protect their futures by detecting cyber threats to sensitive data, networks, trade secrets, and reputations, which other network security products miss.

MENDEL is based on 10 years of extensive academic research and is designed using the same technology which was successful in four US-based NIST Challenges.

×

Hello!

Click one of our contacts below to chat on WhatsApp

×