1 of 40

Elevating Cybersecurity Visibility with Network Access Modeling: �A Real-World Case Study

Robin Berthier • Network Perception

SANS ICS Summit • May 2, 2023

2 of 40

Robin Berthier

Co-founder & CEO, Network Perception

robin@network-perception.com

3 of 40

AGENDA

  • Biggest Challenges in Securing OT
  • CISA Cybersecurity Performance Goals
  • Network Access Modeling
  • Case Study
  • Next Steps

4 of 40

Biggest Challenges in Securing OT

Technical integration of legacy and aging OT technology with modern IT systems

Traditional IT security technologies are not designed for control systems and cause disruption in OT environments

IT staff does not understand OT operational requirements.

Source: SANS 2022 OT Cybersecurity Survey. 332 respondents

54%

52%

48%

5 of 40

Those challenges are leaving a significant volume of �geographically-dispersed OT devices vulnerable to cyber risks.

90%

of organizations lack �OT network visibility

88%

of organizations have improper network segmentation

Data source: Industrial Control System Cybersecurity Year in Review 2020, Dragos

6 of 40

CISA Cybersecurity Performance Goals (CPGs)

  1. Many organizations have not adopted fundamental security protections.
  2. Small- and medium-sized organizations are left behind.
  3. Lack of consistent standards and cyber maturity across CI sectors.
  4. OT cybersecurity often remains overlooked and under-resourced.

“Essential cybersecurity best practices are not sufficiently applied”

7 of 40

CISA Cybersecurity Performance Goals (CPGs)

Account Security

  • 1.1 Detection of Unsuccessful (Automated) Login Attempts
  • 1.2 Changing Default Passwords
  • 1.3 Multi-Factor Authentication (MFA)
  • 1.4 Minimum Password Strength
  • 1.5 Separating User and Privileged Accounts
  • 1.6 Unique Credentials
  • 1.7 Revoking Credentials for Departing Employees

Device Security

  • 2.1 Hardware and Software Approval Process
  • 2.2 Disable Macros by Default
  • 2.3 Asset Inventory
  • 2.4 Prohibit Connection of Unauthorized Devices
  • 2.5 Document Device Configurations

Data Security

  • 3.1 Log Collection
  • 3.2 Secure Log Storage
  • 3.3 Strong and Agile Encryption
  • 3.4 Secure Sensitive Data

Governance & Training

  • 4.1 Organizational Cybersecurity Leadership
  • 4.2 OT Cybersecurity Leadership
  • 4.3 Basic Cybersecurity Training
  • 4.4 OT Cybersecurity Training
  • 4.5 Improving IT and OT Cybersecurity Relationships

Vulnerability Management

  • 5.1 Mitigating Known Vulnerabilities
  • 5.2 Vulnerability Disclosure/Reporting
  • 5.3 Deploy Security.txt Files
  • 5.4 No Exploitable Services on the Internet
  • 5.5 Limit OT Connections to Public Internet
  • 5.6 Third-Party Validation of Cybersecurity Control Effectiveness

Supply Chain / Third Party

  • 6.1 Vendor/Supplier Cybersecurity Requirements
  • 6.2 Supply Chain Incident Reporting
  • 6.3 Supply Chain Vulnerability Disclosure

Response & Recovery

  • 7.1 Incident Reporting
  • 7.2 Incident Response (IR) Plans
  • 7.3 System Back Ups
  • 7.4 Document Network Topology

Other

  • 8.1 Network Segmentation
  • 8.2 Detecting Relevant Threats and TTPs
  • 8.3 Email Security

8 of 40

CISA Cybersecurity Performance Goals (CPGs)

Account Security

  • 1.1 Detection of Unsuccessful (Automated) Login Attempts
  • 1.2 Changing Default Passwords
  • 1.3 Multi-Factor Authentication (MFA)
  • 1.4 Minimum Password Strength
  • 1.5 Separating User and Privileged Accounts
  • 1.6 Unique Credentials
  • 1.7 Revoking Credentials for Departing Employees

Device Security

  • 2.1 Hardware and Software Approval Process
  • 2.2 Disable Macros by Default
  • 2.3 Asset Inventory
  • 2.4 Prohibit Connection of Unauthorized Devices
  • 2.5 Document Device Configurations

Data Security

  • 3.1 Log Collection
  • 3.2 Secure Log Storage
  • 3.3 Strong and Agile Encryption
  • 3.4 Secure Sensitive Data

Governance & Training

  • 4.1 Organizational Cybersecurity Leadership
  • 4.2 OT Cybersecurity Leadership
  • 4.3 Basic Cybersecurity Training
  • 4.4 OT Cybersecurity Training
  • 4.5 Improving IT and OT Cybersecurity Relationships

Vulnerability Management

  • 5.1 Mitigating Known Vulnerabilities
  • 5.2 Vulnerability Disclosure/Reporting
  • 5.3 Deploy Security.txt Files
  • 5.4 No Exploitable Services on the Internet
  • 5.5 Limit OT Connections to Public Internet
  • 5.6 Third-Party Validation of Cybersecurity Control Effectiveness

Supply Chain / Third Party

  • 6.1 Vendor/Supplier Cybersecurity Requirements
  • 6.2 Supply Chain Incident Reporting
  • 6.3 Supply Chain Vulnerability Disclosure

Response & Recovery

  • 7.1 Incident Reporting
  • 7.2 Incident Response (IR) Plans
  • 7.3 System Back Ups
  • 7.4 Document Network Topology

Other

  • 8.1 Network Segmentation
  • 8.2 Detecting Relevant Threats and TTPs
  • 8.3 Email Security

9 of 40

Understanding The Two Sides of Network Visibility

Network Traffic Monitoring

Network Access Modeling

Which assets can connect to which services

Which assets are connecting to which services

Asset

Service

TAP / SPAN

Asset

Service

Firewall

Requires network instrumentation with sensors

No sensor approach: only firewall config needed

10 of 40

Accelerating Network Visibility & Access Verification

Switches

Configuration File Management System

Network Modeling

Access policy baseline

Rule justifications

Topology diagrams

Compliance reports

Network Team

Security Team

Compliance Team

Auditors

Routers

Firewalls

11 of 40

CISA CPG 7.4 Document Network Topology

12 of 40

Network Topology Automatically Generated Offline From Firewall & Router Configuration Files

13 of 40

CISA CPG 8.1 Network Segmentation

14 of 40

Network Segmentation Documented with Visual Zones

15 of 40

Documented Access Rules Review

16 of 40

CISA CPG 5.5 Limit OT Connections to Public Internet

17 of 40

Instantly Verify External Connections with Path Analysis

18 of 40

CISA CPG 5.4 No Exploitable Services on the Internet

19 of 40

Verify Asset Exposure with Stepping Stone Analysis

20 of 40

CISA CPG 5.1 Mitigating Known Vulnerabilities

21 of 40

Prioritize Patching by Combining Vulnerability Scan with Path Analysis

22 of 40

Next Steps

  • Engage in a conversation with your team about CISA Cybersecurity Performance Goals
    • Review CPG checklist and identify gaps
    • Leverage NIST CSF mapping to assess internal cybersecurity control coverage
    • Define a cybersecurity visibility action plan with roles and responsibilities

  • Strengthen your cyber hygiene procedures with Network Access Modeling
    • Automatically document network topology from firewall & router configurations
    • Verify your network segmentation and periodically review your access rules
    • Verify exposure of OT assets and vulnerable assets with path analysis

Continue the conversation: �robin@network-perception.com � kb.network-perception.com

23 of 40

Q&A

Continue the conversation: �robin@network-perception.com � kb.network-perception.com

24 of 40

Critical Dependencies on Connected Cyber Systems

Key questions to ask ourselves:

  • On which cyber systems do our critical operations depend on?
  • How are those systems connected and how are communications controlled?
  • How to increase resiliency in our environment moving forward?

Critical Operations

Cyber Systems

Dependencies

Cyber attacks

25 of 40

Why Investing in Cyber Resiliency

Risk-based multi-layer protection of critical assets

Keeping systems 100% secure is unrealistic

Problem

Solution

Continuous

Verification &

Visualization

26 of 40

Keep Operating Despite Adverse Cyber Events

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-160v2r1.pdf

27 of 40

Cyber Resiliency Building Blocks

Visibility and understanding

Analytic Monitoring

Monitor and detect adverse actions and conditions in a timely and actionable manner.

Dynamic Representation

Keep representation of the network current. Enhance understanding of dependencies.

Substantiated Integrity

Ascertain whether critical system elements have been corrupted.

Defense-in-depth

Coordinated Protection

Implement a defense-in-depth strategy, so that adversaries must overcome multiple obstacles.

Redundancy

Provide multiple protected instances of critical resources.

Diversity

Use heterogeneity to minimize common mode failures, particularly attacks exploiting common vuln.

Least privilege principle

Segmentation

Define and separate system elements based on criticality and trustworthiness.

Privilege Restriction

Restrict privileges based on attributes of users and system elements as well as on environmental factors.

Realignment

Minimize the connections between mission-critical and noncritical services.

Non-Persistence

Generate and retain resources as needed or for a limited time. Reduce exposure to compromise.

Agile recovery capabilities

Adaptive Response

Optimize the ability to respond in a timely and appropriate manner.

Dynamic Positioning

Increase the ability to rapidly recover by distributing and diversifying the network distribution.

Deception

Mislead, confuse, hide critical assets from, or expose covertly tainted assets to, the adversary.

Unpredictability

Make changes randomly and unexpectedly. Increase an adversary's uncertainty regarding protections.

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-160v2.pdf

28 of 40

The Path to Cyber Resiliency

Compliance Verification Establish baseline and validate risk assessment framework

Cybersecurity Visibility Gain accurate visibility of risk exposure and network access paths

Operational

Velocity Visibility and verification at speed to achieve greater cyber resiliency

+

+

STEP 1

STEP 2

STEP 3

29 of 40

Step 1: Verification to Ensure Least Privilege Principle

  • Step 1.1: Build or update your asset inventory
    • List of connected equipment, servers, endpoints
  • Step 1.2: Verify your network segmentation
    • Identify critical networks and separate from non-critical networks
  • Step 1.3: Verify your network access policy
    • Review firewall rules and remove overly permissive or non-needed accesses

30 of 40

Step 2: Visibility to Eliminate Blind Spots

  • Step 2.1: Generate or update your network topology
    • Leverage automated network modeling solutions
  • Step 2.2: Assess your vulnerability exposure
    • Combine vulnerability reports with network path analysis
  • Step 2.3: Ensure defense-in-depth strategy
    • Rely on multiple layers of security to better defend mission-critical assets

31 of 40

Step 3: Velocity to Support a Dynamic Environment

  • Step 3.1: Develop a continuous monitoring capability
    • Keep information up-to-date 24x7x365
  • Step 3.2: Automate your network change review process
    • Vet configuration changes before and after deployment
  • Step 3.3: Build and train an incident response team
    • Define visibility requirements to ensure business continuity

32 of 40

Frequent Network Vulnerabilities

Rank

Risk

Recommendation

#1

Lack of egress access control

Verify that outbound communications are controlled

#2

Insecure remote access

Analyze connectivity paths and verify remote access security

#3

Incorrect segmentation

Clean up overly permissive access rules

#4

Exposed vulnerabilities

Identify vulnerabilities and verify exposure through path analysis

#5

Lack of change review process

Adopt a change review and firewall rule justification workflow

33 of 40

Frequent Network Vulnerabilities

Rank

Risk

Recommendation

#1

Lack of egress access control

Verify that outbound communications are controlled

#2

Insecure remote access

Analyze connectivity paths and verify remote access security

#3

Incorrect segmentation

Clean up overly permissive access rules

#4

Exposed vulnerabilities

Identify vulnerabilities and verify exposure through path analysis

#5

Lack of change review process

Adopt a change review and firewall rule justification workflow

Independent Change Review Process

Network Access Policy Hardening

34 of 40

Network Access Policy Hardening

#1 Identify your mission-critical assets & services

#2 Deny all access by default

#3 Grant network on a need-to-know basis (principle of least-privilege + Purdue model)

  • Restrict scope of source and destination
  • Restrict scope of services (applications, protocols, ports)
  • Close unnecessary remote access

35 of 40

Zero Trust Independent Change Review Process

Switches

Device Configuration Management System

Read-only

Network Modeling

Access policy

Rule justifications

Network diagrams

Reports

Network Team

Security Team

Compliance Team

Managers

& Auditors

Routers

Firewalls

  • Verification

Network segmentation

  • Visibility

Critical asset exposure

  • Velocity

Continuous monitoring

Management

Monitoring

36 of 40

Case Study: Manufacturing Plant Network

Topology Visualization

37 of 40

#1 Identify Critical Assets & Services

Asset Tagging

38 of 40

#2 Deny all access by default

Network Zones

39 of 40

#3 Grant access on a need-to-know basis

Path Analysis

40 of 40

Independent Change Review Process

1. Request >

2. Design >

3. Approval >

4. Deploy.

config change

business reason

decision

5. Verify

Switches

Device Configuration Management System

Read-only

Network Modeling

Routers

Firewalls

Management

Monitoring

Access policy

Rule justifications

Network diagrams

  • Step 3: Approval in staging workspace

Validate change format

Check business justification

Ensure network segmentation

  • Step 5: Verification in prod. workspace

Change deployed matches change approved