Sony Pixel Power calrec Sony

Belden Research Shows at Patching for Industrial Cyber Security is a Broken Model

14/03/2013

ST. LOUIS--(BUSINESS WIRE)--Belden Inc. (NYSE: BDC), a global leader in signal transmission solutions for mission-critical applications, announces that its Tofino Security brand has published new research showing that patching is often ineffective in providing protection from the multitude of vulnerability disclosures and malware targeting critical infrastructure systems today. While patching such systems is important as part of an overall Defense in Depth strategy, the difficulties of patching for industrial systems mean that compensating controls such as Tofino Security Profiles are often a better method of providing immediate protection.

My research highlights the multiple challenges with patching for SCADA and ICS systems

Since the discovery of the Stuxnet malware in 2010, industrial infrastructure has become a key target for security researchers, hackers, and government agents. Designed years ago with a focus on reliability and safety, rather than security, Supervisory Control and Data Acquisition (SCADA) and Industrial Control Systems (ICS) products are often easy to exploit. As a result, there has been exponential growth in government security alerts for these systems in the past two years. In addition, they have attracted some of the most sophisticated (Stuxnet, Night Dragon, Flame) and damaging (Shamoon) cyberattacks on record.

Eric Byres, CTO and vice president of engineering at Tofino Security, investigated the effectiveness of patching for protecting control systems from vulnerability exploits and malware. His work revealed that:

The number of vulnerabilities existing in SCADA/ICS applications is high, with as many as 1,805 yet to be discovered vulnerabilities existing on some control system computers.

The frequency of patching needed to address future SCADA/ICS vulnerabilities in both controllers and computers likely exceeds the tolerance of most SCADA/ICS operators for system shutdowns. Unlike IT systems, most industrial processes operate 24x7 and demand high uptime. Weekly shutdowns for patching are unacceptable.

Even when patches can be installed, they can be problematic. There is a 1 in 12 chance that any patch will affect the safety or reliability of a control system, and there is a 60% failure rate in patches fixing the reported vulnerability in control system products. In addition, patches often require staff with special skills to be present. In many cases, such experts are often not certified for access to safety regulated industrial sites.

Patches are available for less than 50% of publically disclosed vulnerabilities.

Many critical infrastructure operators are reluctant to patch as it may degrade service and increase downtime.

When patching is not possible, or while waiting for a semi-annual or annual shutdown to install patches, an alternative is to deploy a workaround, also known as a compensating control'. Compensating controls do not correct the underlying vulnerability; instead, they help block known attack vectors. Examples of compensating controls include product reconfigurations, applying suggested firewall rules, or installing signatures that recognize and block malware.

Another compensating control is Tofino Security Profiles, available in Belden's Tofino Security product line. Tofino Security Profiles are rule and protocol definitions that address newly disclosed vulnerabilities. They provide a simple way for automation system vendors to create and securely distribute malware protection. Operators benefit from a single, easy-to-deploy package of tailored rules that can be installed without impacting operations. The result is that critical industrial infrastructure facilities can quickly and effectively defend themselves against new threats.

My research highlights the multiple challenges with patching for SCADA and ICS systems, remarked Eric Byres. To secure facilities, critical infrastructure operators should pursue a Defense in Depth strategy that includes patching when possible, and use compensating controls for protection when patching is not possible.

Starting today, Belden is publishing a series of blog articles on its patching research and is accompanying them with useful documents. These documents include:

Patching for Control System Security - A Broken Model?; a presentation that summarizes its patching research,

Patching for Control System Security - A Broken Model? a peer reviewed published paper,

and Solving the SCADA/ICS Security Patch Problem, a White Paper.

Visit: http://www.tofinosecurity.com/blog/scada-security-welcome-patching-treadmill for the first blog article.

Tofino Security provides practical and effective industrial network security and SCADA security products that are simple to implement and that do not require plant shutdowns. Its products include configurable security appliances with a range of loadable security modules plus fixed function security appliances made for specific automation vendor applications. Tofino Security products protect zones of equipment on the plant floor, and are complementary to Belden's Hirschmann brand, which leads industrial networking solutions. Both groups service and secure industrial networks in the oil and gas, utilities, transportation and automation industries. www.tofinosecurity.com

About Belden

St. Louis-based Belden Inc. designs, manufactures, and sells connectivity solutions for markets including industrial, enterprise, and broadcast. It has approximately 6,700 employees, and has manufacturing capabilities in North America, South America, Europe, and Asia, and a market presence in nearly every region of the world. Belden was founded in 1902, and today is a leader with some of the strongest brands in the signal transmission industry. For more information, visit www.belden.co
LINK: http://us.vocuspr.com/Newsroom/ViewAttachment.aspx?SiteName=belden&Ent...
See more stories from belden

Most recent headlines

13/03/2025

TAG Video Systems and Harmonic Partner to Deliver Enhanced Real-Time Monitoring for VOS360 Streaming Workflows at the 2025 NAB Show

TAG Video Systems and Harmonic Partner to Deliver Enhanced Real-Time Monitoring ...

13/03/2025

DigitalGlue Invites NAB Visitors to Experience New Features in Managed Storage Platform that Empowers Video Teams to Scale Effortlessly

DigitalGlue Invites NAB Visitors to Experience New Features in Managed Storage P...

13/03/2025

FOR-A America Theme - Connecting the Present, Building the Future - Comes to Life at NAB 2025 Exhibition

FOR-A America Theme - Connecting the Present, Building the Future - Comes to Lif...

13/03/2025

Ajit Pai Appointed President of CTIA

CTIA, the wireless industry association, has named former FCC Chairman Aji Pai as its President and Chief Executive Officer, effective April 1. He replaces Mere...

13/03/2025

NAB: FCC's 60 Minutes Investigation Is Unconstitutional, Invalid

he National Association of Broadcasters is urging the FCC to end its investigation of that controversial CBS interview with Kamala Harris stating there is no ...

13/03/2025

CBS Miami to Launch AR Coverage of Weather and Sports for March Madness

MIAMI CBS News & Stations continues to expand its use of augmented and virtual reality technologies with the planned launch of an augmented reality/virtual real...

13/03/2025

Meet the co-founder and chief customer success & innovation officer

Srividhya Srinivasan, co-founder and chief customer success & innovation Officer at Amagi, tells TVBEurope how staying ahead of the latest trends is essential f...

13/03/2025

FCC Chairman Carr Launches Massive Deregulation Initiative

WASHINGTON FCC Chairman Brendan Carr announced that the agency has launched a massive, new deregulatory initiative that could potentially subject virtually all ...

13/03/2025

SDVI Integrates Rally With Spectra Vail

SUNNYVALE, Calif. SDVI has announced that it has integrated its Rally media supply chain management platform with the Spectra Vail multi-cloud data management s...

13/03/2025

FCC Approves Gray's Acquisition of KXLT

ATLANTA Gray Media has announced that the Federal Communications Commission (FCC) has granted a waiver of its local ownership rules to permit Gray Media to acqu...

13/03/2025

NAB Show 2025 Exhibitor Insight: Blackmagic Design

TV Tech: What do you anticipate will be the most significant technology trends at the 2025 NAB Show?...

13/03/2025

Watch Student Naomi Soleils Folk Pop Performance on The Voice

Watch Student Naomi Soleils Folk Pop Performance on The Voice The songwriting major sang Stars by Grace Potter and the Nocturnals during the blind auditions. ...

13/03/2025

Italia 90 Republic of Ireland Squad, Riverdance, Cian Ducrot & B*Witched on Friday's Late Late Show

Here is your host, Patrick Kielty! Shake your Shamrocks, Patrick Kielty will be...

13/03/2025

RT Celebrating all things Irish this St. Patrick's Weekend

This St. Patrick's weekend, RT invites you to celebrate all things Irish, showcasing the very best of Irish sport, entertainment and live coverage from the...

13/03/2025

GTC 2025 - Announcements and Live Updates

What's next in AI is at GTC 2025. Not only the technology, but the people and ideas that are pushing AI forward - creating new opportunities, novel solution...

13/03/2025

T-Mobile, Thales and SIMPL ease IoT deployments with a flexible and secure connectivity solution

Facebook Twitter LinkedIn By combining T-Mobile's robust network, Thal...

13/03/2025

Relive the Magic as GeForce NOW Brings More Blizzard Gaming to the Cloud

Bundle up - GeForce NOW is bringing a flurry of Blizzard titles to its ever-expanding library. Prepare to weather epic gameplay in the cloud, tackling the genr...

13/03/2025

Gaming Goodness: NVIDIA Reveals Latest Neural Rendering and AI Advancements Supercharging Game Development at GDC 2025

AI is leveling up the world's most beloved games, as the latest advancements...

13/03/2025

Drop It Like It's Mod: Breathing New Life Into Classic Games With AI in NVIDIA RTX Remix

PC game modding is massive, with over 5 billion mods downloaded annually. Mods p...

12/03/2025

Como o Impacto Cultural e Financeiro da Indstria Musical Define Seu Sucesso em 2025

O Spotify acaba de lan ar o relat rio Loud & Clear deste ano, uma vis o transpar...

12/03/2025

Cmo el impacto cultural y financiero de la industria musical define su xito en 2025

Spotify acaba de presentar el informe Loud & Clear de este a o, una mirada trans...

12/03/2025

Nourish Mind, Body, and Soul This Ramadan With Spotify

Ramadan, a period of profound spiritual significance for Muslims worldwide, is a time for fasting, prayer, reflection, and community. Enrich your experience thi...

12/03/2025

How the Music Industry's Cultural and Financial Impact Define Its Success in 2025

Spotify has just unveiled this year's Loud & Clear report, a transparent loo...

12/03/2025

FAST now transcends back catalog content

More than 70% of FAST programming has been produced since 2010, according to new Gracenote report NEW YORK March 12, 2025 Gracenote, the content data busin...

12/03/2025

Viamedia Adopts ShowSeeker Pilot To Streamline Ad Workflows

GEONA, Nev. Independent digital and linear advertising rep firm Viamedia will adopt cloud-based ShowSeeker Pilot as its primary ad campaign and order management...

12/03/2025

Mediagenix Appoints Wael Yasin as Sales Director Central Europe

BRUSSELS Mediagenix has announced that Wael Yasin has joined the company as sales director Central Europe....

12/03/2025

Omdia: Global Online Consumer Expenditure to Hit $6.6 Trillion by 2029

LONDON A new study highlights opportunities for shoppable TV and the massive impact online consumer spending is having on the economy, with Omdia predicting tha...

12/03/2025

Comcast Technology Solutions Upgrades to Interra Systems BATON Version 9

CUPERTINO, Calif. Interra Systems has announced that Comcast Technology Solutions has integrated recent updates to BATON Version 9 into its operations....

12/03/2025

Nevion announces new 400G addition to its eMerge SDN media fabric offering

Nevion announces new 400G addition to its eMerge SDN media fabric offering Brie Clayton March 12, 2025 0 Comments High-capacity switch enhances existi...

12/03/2025

DaVinci Resolve Studio Delivers Cinematic Sound for Adam Bol

DaVinci Resolve Studio Delivers Cinematic Sound for Adam Bol Brie Clayton March 12, 2025 0 Comments Feature film relies on DaVinci Resolve Studio for ...

12/03/2025

SVT Leverages Ateliere Live to Pioneer 100% Software-Defined Production at Rally Sweden 2025

SVT Leverages Ateliere Live to Pioneer 100% Software-Defined Production at Rally...

12/03/2025

Berklee Awards Fenway Neighborhood Improvement Grant to Four Organizations

Berklee Awards Fenway Neighborhood Improvement Grant to Four Organizations A total of $17,000 will be distributed among the Boston-based nonprofits. By Madd...

12/03/2025

Offering a broad umbrella for IP standards

TVBEuropes Jenny Priestley sits down with new SMPTE president Richard Welsh to discuss his aims for the organisation going forward, its efforts to attract a you...

12/03/2025

Warner Bros Belgium takes a new approach to its post production workflows

The new process has significantly enhanced operational efficiencies, with automation freeing up creators to concentrate on higher value tasks By Matthew Corrig...

12/03/2025

Another VFX company suspends operations

Jellyfish Pictures, which has offices in London and Sheffield, said it has been battling hard in the face of strong headwinds over the last 12 months By Jenny ...

12/03/2025

Bitcentral to Showcase AI-Powered Innovations for Smarter...

Visit Booth #W2213 to Experience the Latest in AI-Driven Content Discovery and Workflow Automation Bitcentral, a leader in media workflow solutions, is set to ...

12/03/2025

Jeff Lilly Named WGN-TV Director Of Technology

CHICAGO Jeff Lilly has been named WGN-TV director of technology effective March 17, 2025, according to Ric Harris, WGN-TV vice president and general manager....

12/03/2025

Survey: Consumers Want More Shoppable TV Experiences

MOUNTAIN VIEW, Calif. A new study from LG Ad Solutions indicates that consumers want more features that would allow them to shop for products on the connected T...

12/03/2025

IP Showcase To Focus On IP, Broadcast Tech Convergence at 2025 NAB Show

BOTHELL, Wash. The Alliance for IP Media Solutions (AIMS), Advanced Media Workflow Association (AMWA) and the Video Services Forum (VSF) will once again present...

12/03/2025

Comcast Boosts Internet Speeds for More Than 20 Million Customers

PHILADELPHIA Comcast announced that it has upgraded Xfinity Internet speeds for more than 20 million customers for no additional cost....

12/03/2025

Create with Maxon: Cinema 4D Fundamentals Workshop - March 12-14

Create with Maxon: Cinema 4D Fundamentals Workshop - March 12-14 Brie Clayton March 11, 2025 0 Comments Makin' Waffles with Elly Wade During Marc...

12/03/2025

Ross Video Strengthens Cloud Leadership with Appointment of Aaron Tunnell

Ottawa, Canada - March 12, 2025 - Ross Video is pleased to announce the appointment of Aaron Tunnell as Business Development Director, Cloud Solutions, reinforc...

12/03/2025

VEON to release 4Q 2024 trading update on 20 March 2025

12 Mar 2025 VEON to release 4Q 2024 trading update on 20 March 2025 Dubai, 12 March 2025 - VEON Ltd. (NASDAQ: VEON), a global digital operator, today confirms ...

12/03/2025

Getting Set for the Winter Olympics: Inside SVT's Ongoing Software-Based Production Evolution

Getting set for the Winter Olympics: Inside SVT's ongoing software-based pro...

12/03/2025

Seamless SMPTE 2110: A Discussion on Making the Move to IP Less Painful

Seamless SMPTE 2110: A Discussion on Making the Move to IP Less Painful Leaders from Netflix, Monumental Sports & Entertainment, LinkedI, and Megapixel address ...

12/03/2025

Opening Doors of Perception: Meta's Ajit Ninan on Rethinking AR/MR Perceptual Displays

Opening Doors of Perception: Meta's Ajit Ninan on Rethinking AR/MR Perceptua...

12/03/2025

Sky Sports Unveils Exciting Plans for 2025 Formula 1 Coverage

With the 2025 Formula 1 season set to begin in Melbourne on March 16, Sky Sports is gearing up to deliver its most comprehensive F1 coverage yet. Following a th...

12/03/2025

Unicanal and Trece TV revolutionize Digital TV in Paraguay with Rohde & Schwarz transmission solutions

Unicanal and Trece TV revolutionize Digital TV in Paraguay with Rohde & Schwarz ...

12/03/2025

Honoring Service, Celebrating Sport: Rohde & Schwarz UK Sponsors NavyFit Rugby Double-Header

Honoring Service, Celebrating Sport: Rohde & Schwarz UK Sponsors NavyFit Rugby D...