
ST. LOUIS--(BUSINESS WIRE)--Belden Inc. (NYSE: BDC), a global leader in signal transmission solutions for mission-critical applications, announces that its Tofino Security brand has published new research showing that patching is often ineffective in providing protection from the multitude of vulnerability disclosures and malware targeting critical infrastructure systems today. While patching such systems is important as part of an overall Defense in Depth strategy, the difficulties of patching for industrial systems mean that compensating controls such as Tofino Security Profiles are often a better method of providing immediate protection.
My research highlights the multiple challenges with patching for SCADA and ICS systems
Since the discovery of the Stuxnet malware in 2010, industrial infrastructure has become a key target for security researchers, hackers, and government agents. Designed years ago with a focus on reliability and safety, rather than security, Supervisory Control and Data Acquisition (SCADA) and Industrial Control Systems (ICS) products are often easy to exploit. As a result, there has been exponential growth in government security alerts for these systems in the past two years. In addition, they have attracted some of the most sophisticated (Stuxnet, Night Dragon, Flame) and damaging (Shamoon) cyberattacks on record.
Eric Byres, CTO and vice president of engineering at Tofino Security, investigated the effectiveness of patching for protecting control systems from vulnerability exploits and malware. His work revealed that:
The number of vulnerabilities existing in SCADA/ICS applications is high, with as many as 1,805 yet to be discovered vulnerabilities existing on some control system computers.
The frequency of patching needed to address future SCADA/ICS vulnerabilities in both controllers and computers likely exceeds the tolerance of most SCADA/ICS operators for system shutdowns. Unlike IT systems, most industrial processes operate 24x7 and demand high uptime. Weekly shutdowns for patching are unacceptable.
Even when patches can be installed, they can be problematic. There is a 1 in 12 chance that any patch will affect the safety or reliability of a control system, and there is a 60% failure rate in patches fixing the reported vulnerability in control system products. In addition, patches often require staff with special skills to be present. In many cases, such experts are often not certified for access to safety regulated industrial sites.
Patches are available for less than 50% of publically disclosed vulnerabilities.
Many critical infrastructure operators are reluctant to patch as it may degrade service and increase downtime.
When patching is not possible, or while waiting for a semi-annual or annual shutdown to install patches, an alternative is to deploy a workaround, also known as a compensating control'. Compensating controls do not correct the underlying vulnerability; instead, they help block known attack vectors. Examples of compensating controls include product reconfigurations, applying suggested firewall rules, or installing signatures that recognize and block malware.
Another compensating control is Tofino Security Profiles, available in Belden's Tofino Security product line. Tofino Security Profiles are rule and protocol definitions that address newly disclosed vulnerabilities. They provide a simple way for automation system vendors to create and securely distribute malware protection. Operators benefit from a single, easy-to-deploy package of tailored rules that can be installed without impacting operations. The result is that critical industrial infrastructure facilities can quickly and effectively defend themselves against new threats.
My research highlights the multiple challenges with patching for SCADA and ICS systems, remarked Eric Byres. To secure facilities, critical infrastructure operators should pursue a Defense in Depth strategy that includes patching when possible, and use compensating controls for protection when patching is not possible.
Starting today, Belden is publishing a series of blog articles on its patching research and is accompanying them with useful documents. These documents include:
Patching for Control System Security - A Broken Model?; a presentation that summarizes its patching research,
Patching for Control System Security - A Broken Model? a peer reviewed published paper,
and Solving the SCADA/ICS Security Patch Problem, a White Paper.
Visit: http://www.tofinosecurity.com/blog/scada-security-welcome-patching-treadmill for the first blog article.
Tofino Security provides practical and effective industrial network security and SCADA security products that are simple to implement and that do not require plant shutdowns. Its products include configurable security appliances with a range of loadable security modules plus fixed function security appliances made for specific automation vendor applications. Tofino Security products protect zones of equipment on the plant floor, and are complementary to Belden's Hirschmann brand, which leads industrial networking solutions. Both groups service and secure industrial networks in the oil and gas, utilities, transportation and automation industries. www.tofinosecurity.com
About Belden
St. Louis-based Belden Inc. designs, manufactures, and sells connectivity solutions for markets including industrial, enterprise, and broadcast. It has approximately 6,700 employees, and has manufacturing capabilities in North America, South America, Europe, and Asia, and a market presence in nearly every region of the world. Belden was founded in 1902, and today is a leader with some of the strongest brands in the signal transmission industry. For more information, visit www.belden.co
Most recent headlines
13/03/2025
TAG Video Systems and Harmonic Partner to Deliver Enhanced Real-Time Monitoring ...
13/03/2025
DigitalGlue Invites NAB Visitors to Experience New Features in Managed Storage P...
13/03/2025
FOR-A America Theme - Connecting the Present, Building the Future - Comes to Lif...
13/03/2025
CTIA, the wireless industry association, has named former FCC Chairman Aji Pai as its President and Chief Executive Officer, effective April 1. He replaces Mere...
13/03/2025
he National Association of Broadcasters is urging the FCC to end its investigation of that controversial CBS interview with Kamala Harris stating there is no ...
13/03/2025
MIAMI CBS News & Stations continues to expand its use of augmented and virtual reality technologies with the planned launch of an augmented reality/virtual real...
13/03/2025
Srividhya Srinivasan, co-founder and chief customer success & innovation Officer at Amagi, tells TVBEurope how staying ahead of the latest trends is essential f...
13/03/2025
WASHINGTON FCC Chairman Brendan Carr announced that the agency has launched a massive, new deregulatory initiative that could potentially subject virtually all ...
13/03/2025
SUNNYVALE, Calif. SDVI has announced that it has integrated its Rally media supply chain management platform with the Spectra Vail multi-cloud data management s...
13/03/2025
ATLANTA Gray Media has announced that the Federal Communications Commission (FCC) has granted a waiver of its local ownership rules to permit Gray Media to acqu...
13/03/2025
TV Tech: What do you anticipate will be the most significant technology trends at the 2025 NAB Show?...
13/03/2025
Watch Student Naomi Soleils Folk Pop Performance on The Voice The songwriting major sang Stars by Grace Potter and the Nocturnals during the blind auditions.
...
13/03/2025
Here is your host, Patrick Kielty!
Shake your Shamrocks, Patrick Kielty will be...
13/03/2025
This St. Patrick's weekend, RT invites you to celebrate all things Irish, showcasing the very best of Irish sport, entertainment and live coverage from the...
13/03/2025
What's next in AI is at GTC 2025. Not only the technology, but the people and ideas that are pushing AI forward - creating new opportunities, novel solution...
13/03/2025
Facebook
Twitter
LinkedIn
By combining T-Mobile's robust network, Thal...
13/03/2025
Bundle up - GeForce NOW is bringing a flurry of Blizzard titles to its ever-expanding library.
Prepare to weather epic gameplay in the cloud, tackling the genr...
13/03/2025
AI is leveling up the world's most beloved games, as the latest advancements...
13/03/2025
PC game modding is massive, with over 5 billion mods downloaded annually. Mods p...
12/03/2025
O Spotify acaba de lan ar o relat rio Loud & Clear deste ano, uma vis o transpar...
12/03/2025
Spotify acaba de presentar el informe Loud & Clear de este a o, una mirada trans...
12/03/2025
Ramadan, a period of profound spiritual significance for Muslims worldwide, is a time for fasting, prayer, reflection, and community. Enrich your experience thi...
12/03/2025
Spotify has just unveiled this year's Loud & Clear report, a transparent loo...
12/03/2025
More than 70% of FAST programming has been produced since 2010, according to new Gracenote report
NEW YORK March 12, 2025 Gracenote, the content data busin...
12/03/2025
GEONA, Nev. Independent digital and linear advertising rep firm Viamedia will adopt cloud-based ShowSeeker Pilot as its primary ad campaign and order management...
12/03/2025
BRUSSELS Mediagenix has announced that Wael Yasin has joined the company as sales director Central Europe....
12/03/2025
LONDON A new study highlights opportunities for shoppable TV and the massive impact online consumer spending is having on the economy, with Omdia predicting tha...
12/03/2025
CUPERTINO, Calif. Interra Systems has announced that Comcast Technology Solutions has integrated recent updates to BATON Version 9 into its operations....
12/03/2025
Nevion announces new 400G addition to its eMerge SDN media fabric offering
Brie Clayton March 12, 2025
0 Comments
High-capacity switch enhances existi...
12/03/2025
DaVinci Resolve Studio Delivers Cinematic Sound for Adam Bol
Brie Clayton March 12, 2025
0 Comments
Feature film relies on DaVinci Resolve Studio for ...
12/03/2025
SVT Leverages Ateliere Live to Pioneer 100% Software-Defined Production at Rally...
12/03/2025
Berklee Awards Fenway Neighborhood Improvement Grant to Four Organizations A total of $17,000 will be distributed among the Boston-based nonprofits.
By
Madd...
12/03/2025
TVBEuropes Jenny Priestley sits down with new SMPTE president Richard Welsh to discuss his aims for the organisation going forward, its efforts to attract a you...
12/03/2025
The new process has significantly enhanced operational efficiencies, with automation freeing up creators to concentrate on higher value tasks
By Matthew Corrig...
12/03/2025
Jellyfish Pictures, which has offices in London and Sheffield, said it has been battling hard in the face of strong headwinds over the last 12 months
By Jenny ...
12/03/2025
Visit Booth #W2213 to Experience the Latest in AI-Driven Content Discovery and Workflow Automation
Bitcentral, a leader in media workflow solutions, is set to ...
12/03/2025
CHICAGO Jeff Lilly has been named WGN-TV director of technology effective March 17, 2025, according to Ric Harris, WGN-TV vice president and general manager....
12/03/2025
MOUNTAIN VIEW, Calif. A new study from LG Ad Solutions indicates that consumers want more features that would allow them to shop for products on the connected T...
12/03/2025
BOTHELL, Wash. The Alliance for IP Media Solutions (AIMS), Advanced Media Workflow Association (AMWA) and the Video Services Forum (VSF) will once again present...
12/03/2025
PHILADELPHIA Comcast announced that it has upgraded Xfinity Internet speeds for more than 20 million customers for no additional cost....
12/03/2025
Create with Maxon: Cinema 4D Fundamentals Workshop - March 12-14
Brie Clayton March 11, 2025
0 Comments
Makin' Waffles with Elly Wade
During Marc...
12/03/2025
Ottawa, Canada - March 12, 2025 - Ross Video is pleased to announce the appointment of Aaron Tunnell as Business Development Director, Cloud Solutions, reinforc...
12/03/2025
12 Mar 2025
VEON to release 4Q 2024 trading update on 20 March 2025 Dubai, 12 March 2025 - VEON Ltd. (NASDAQ: VEON), a global digital operator, today confirms ...
12/03/2025
Getting set for the Winter Olympics: Inside SVT's ongoing software-based pro...
12/03/2025
THE PLAYERS Championship 2025: AI Commentary, Shared-Reality Viewing at COSM, La...
12/03/2025
Seamless SMPTE 2110: A Discussion on Making the Move to IP Less Painful Leaders from Netflix, Monumental Sports & Entertainment, LinkedI, and Megapixel address ...
12/03/2025
Opening Doors of Perception: Meta's Ajit Ninan on Rethinking AR/MR Perceptua...
12/03/2025
With the 2025 Formula 1 season set to begin in Melbourne on March 16, Sky Sports is gearing up to deliver its most comprehensive F1 coverage yet. Following a th...
12/03/2025
Unicanal and Trece TV revolutionize Digital TV in Paraguay with Rohde & Schwarz ...
12/03/2025
Honoring Service, Celebrating Sport: Rohde & Schwarz UK Sponsors NavyFit Rugby D...