Elevating Cybersecurity Visibility with Network Access Modeling: �A Real-World Case Study
Robin Berthier • Network Perception
SANS ICS Summit • May 2, 2023
Robin Berthier
Co-founder & CEO, Network Perception
robin@network-perception.com
AGENDA
Biggest Challenges in Securing OT
Technical integration of legacy and aging OT technology with modern IT systems
Traditional IT security technologies are not designed for control systems and cause disruption in OT environments
IT staff does not understand OT operational requirements.
Source: SANS 2022 OT Cybersecurity Survey. 332 respondents
54%
52%
48%
Those challenges are leaving a significant volume of �geographically-dispersed OT devices vulnerable to cyber risks.
90%
of organizations lack �OT network visibility
88%
of organizations have improper network segmentation
Data source: Industrial Control System Cybersecurity Year in Review 2020, Dragos
CISA Cybersecurity Performance Goals (CPGs)
“Essential cybersecurity best practices are not sufficiently applied”
CISA Cybersecurity Performance Goals (CPGs)
Account Security
Device Security
Data Security
Governance & Training
Vulnerability Management
Supply Chain / Third Party
Response & Recovery
Other
CISA Cybersecurity Performance Goals (CPGs)
Account Security
Device Security
Data Security
Governance & Training
Vulnerability Management
Supply Chain / Third Party
Response & Recovery
Other
Understanding The Two Sides of Network Visibility
Network Traffic Monitoring
Network Access Modeling
Which assets can connect to which services
Which assets are connecting to which services
Asset
Service
TAP / SPAN
Asset
Service
Firewall
Requires network instrumentation with sensors
No sensor approach: only firewall config needed
Accelerating Network Visibility & Access Verification
Switches
Configuration File Management System
Network Modeling
Access policy baseline
Rule justifications
Topology diagrams
Compliance reports
Network Team
Security Team
Compliance Team
Auditors
Routers
Firewalls
CISA CPG 7.4 Document Network Topology
Network Topology Automatically Generated Offline From Firewall & Router Configuration Files
CISA CPG 8.1 Network Segmentation
Network Segmentation Documented with Visual Zones
Documented Access Rules Review
CISA CPG 5.5 Limit OT Connections to Public Internet
Instantly Verify External Connections with Path Analysis
CISA CPG 5.4 No Exploitable Services on the Internet
Verify Asset Exposure with Stepping Stone Analysis
CISA CPG 5.1 Mitigating Known Vulnerabilities
Prioritize Patching by Combining Vulnerability Scan with Path Analysis
Next Steps
Continue the conversation: �robin@network-perception.com � kb.network-perception.com
Q&A
Continue the conversation: �robin@network-perception.com � kb.network-perception.com
Critical Dependencies on Connected Cyber Systems
Key questions to ask ourselves:
Critical Operations
Cyber Systems
Dependencies
Cyber attacks
Why Investing in Cyber Resiliency
Risk-based multi-layer protection of critical assets
Keeping systems 100% secure is unrealistic
Problem
Solution
Continuous
Verification &
Visualization
Keep Operating Despite Adverse Cyber Events
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-160v2r1.pdf
Cyber Resiliency Building Blocks
Visibility and understanding | |
Analytic Monitoring | Monitor and detect adverse actions and conditions in a timely and actionable manner. |
Dynamic Representation | Keep representation of the network current. Enhance understanding of dependencies. |
Substantiated Integrity | Ascertain whether critical system elements have been corrupted. |
Defense-in-depth | |
Coordinated Protection | Implement a defense-in-depth strategy, so that adversaries must overcome multiple obstacles. |
Redundancy | Provide multiple protected instances of critical resources. |
Diversity | Use heterogeneity to minimize common mode failures, particularly attacks exploiting common vuln. |
Least privilege principle | |
Segmentation | Define and separate system elements based on criticality and trustworthiness. |
Privilege Restriction | Restrict privileges based on attributes of users and system elements as well as on environmental factors. |
Realignment | Minimize the connections between mission-critical and noncritical services. |
Non-Persistence | Generate and retain resources as needed or for a limited time. Reduce exposure to compromise. |
Agile recovery capabilities | |
Adaptive Response | Optimize the ability to respond in a timely and appropriate manner. |
Dynamic Positioning | Increase the ability to rapidly recover by distributing and diversifying the network distribution. |
Deception | Mislead, confuse, hide critical assets from, or expose covertly tainted assets to, the adversary. |
Unpredictability | Make changes randomly and unexpectedly. Increase an adversary's uncertainty regarding protections. |
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-160v2.pdf
The Path to Cyber Resiliency
Compliance Verification �Establish baseline and validate risk assessment framework
Cybersecurity Visibility �Gain accurate visibility of risk exposure and network access paths
Operational
Velocity �Visibility and verification at speed to achieve greater cyber resiliency
+
+
STEP 1
STEP 2
STEP 3
Step 1: Verification to Ensure Least Privilege Principle
Step 2: Visibility to Eliminate Blind Spots
Step 3: Velocity to Support a Dynamic Environment
Frequent Network Vulnerabilities
Rank | Risk | Recommendation |
#1 | Lack of egress access control | Verify that outbound communications are controlled |
#2 | Insecure remote access | Analyze connectivity paths and verify remote access security |
#3 | Incorrect segmentation | Clean up overly permissive access rules |
#4 | Exposed vulnerabilities | Identify vulnerabilities and verify exposure through path analysis |
#5 | Lack of change review process | Adopt a change review and firewall rule justification workflow |
Frequent Network Vulnerabilities
Rank | Risk | Recommendation |
#1 | Lack of egress access control | Verify that outbound communications are controlled |
#2 | Insecure remote access | Analyze connectivity paths and verify remote access security |
#3 | Incorrect segmentation | Clean up overly permissive access rules |
#4 | Exposed vulnerabilities | Identify vulnerabilities and verify exposure through path analysis |
#5 | Lack of change review process | Adopt a change review and firewall rule justification workflow |
Independent Change Review Process
Network Access Policy Hardening
Network Access Policy Hardening
#1 Identify your mission-critical assets & services
#2 Deny all access by default
#3 Grant network on a need-to-know basis (principle of least-privilege + Purdue model)
Zero Trust Independent Change Review Process
Switches
Device Configuration Management System
Read-only
Network Modeling
Access policy
Rule justifications
Network diagrams
Reports
Network Team
Security Team
Compliance Team
Managers
& Auditors
Routers
Firewalls
Network segmentation
Critical asset exposure
Continuous monitoring
Management
Monitoring
Case Study: Manufacturing Plant Network
Topology Visualization
#1 Identify Critical Assets & Services
Asset Tagging
#2 Deny all access by default
Network Zones
#3 Grant access on a need-to-know basis
Path Analysis
Independent Change Review Process
1. Request >
2. Design >
3. Approval >
4. Deploy.
config change
business reason
decision
5. Verify
Switches
Device Configuration Management System
Read-only
Network Modeling
Routers
Firewalls
Management
Monitoring
Access policy
Rule justifications
Network diagrams
Validate change format
Check business justification
Ensure network segmentation
Change deployed matches change approved