POWER February 2015 - 40

ICS CYBERSECURITY
2. Secure connections for distributed equipment and diverse systems.
Tempered Networks' HIPswitch security appliances are transport and topology agnostic, supporting
any mix of cellular, Wi-Fi, wired Ethernet, or satellite communications networks. Courtesy:
Tempered Networks
HIPswitch Conductorâ„¢
SCADA &
Historian
HIPSwitchâ„¢
Corporate
Network
orchestration is based on the Trusted Computing
Group's IF-MAP protocol and follows
a specification purpose-built for secure networking
of industrial control systems.
The orchestration follows a concept from
Cellular
Network
Segment Process Control and SCADA
Networks to Isolate and Cloak Connectivity.
The industry's best practice for
protecting critical infrastructure and DCS
networks within power facilities is to segment
networks. The Tempered Networks
solution enables organizations to segment
and isolate connectivity to and between production
facilities, following the ISA-99/IEC
62443 zones and conduits model.
However, unlike traditional firewalls or
virtual private networks (VPNs), the Tempered
Networks solution goes beyond simple
inspection, adding authorization, confidentiality,
integrity, and availability protection to
the data as it traverses the control systems
network. It essentially provides a " VPN as a
service, " where you can provision individually
managed private overlay networks-at
unlimited scale.
Another difference is that the solution is
designed to be deployed and managed by OT
teams, whereas firewalls and VPNs require
advanced security skills and are resource intensive,
especially on a large scale.
Additionally, the solution is transport and
topology agnostic, which is crucial for many
of these remote facilities where there may be
any mix of cellular, WiFi, wired Ethernet, or
satellite communications networks.
The Tempered Networks solution provides
an overlay network to segment and
isolate critical production systems and devices.
It " cloaks " all devices within the
overlay network, leaving no configuration
footprint from outside the Tempered Networks
private network. This approach leverages
existing infrastructure to connect
plants, without exposing device communications,
and without the brittleness of complex
configurations.
Securely Connect and Monitor Remote,
Distributed Equipment. Customers
40
require an independent layer of connectivity,
security, and trust management that allows
management of devices-even across
a third-party's network infrastructure. They
also require easy connectivity and monitoring
of production equipment with centralized
supervisory control and data acquisition
(SCADA) and historian systems. As noted
earlier Tempered Networks' HIPswitch security
appliances are transport and topology agnostic,
supporting any mix of cellular, Wi-Fi,
wired Ethernet, or satellite communications
networks (Figure 2).
Manage Third-Party (Contractor and
Vendor) Connections. Most facilities have
vendors or contractors that need access to
their networks, but this creates yet another
security vulnerability. Tempered Networks
facilitates authorized third-party access to
SCADA networks, which can be granted
and revoked in minutes, and monitored and
logged. Once granted, access can be constrained
to a single isolated device or a group
of devices, for a specific period of time, using
only specific applications.
When no longer required, access can
be revoked quickly, without modifying
the shared network. The solution can be
configured to require user authentication
prior to enabling access, thus adding integrated
authentication services to automation
environments.
Overview of Orchestration/Control
Compliance with industry standards was
a key element when the solution was engineered,
and it continues to be a valued aspect
by customers. Tempered Networks provides
a purpose-built solution for ICS and critical
infrastructures, based on Trusted Computing
Group (TCG), the Internet Engineering
Task Force (IETF), and the International
Society of Automation (ISA) standards. The
www.powermag.com
networking called the control plane and is
used only for control and monitoring of the
deployed HIPswitches. This is a powerful
approach because it avoids making the Tempered
Networks Conductor a bottleneck in
the system. The HIPswitches handle the data
plane independently of orchestration and,
therefore, can continue to operate with their
current configuration if orchestration becomes
unavailable. Even with a highly available orchestration
service, this independence is vital
for a highly resilient network.
There are no silver bullets in security;
however, Tempered Networks believes its
new approach raises the bar very high.
The HIPswitches are transparent on the
ICS side, meaning that protected devices
cannot communicate with the HIPswitch.
On the shared network or uplink side,
the HIPswitch has only one listening service,
and that is for connections from peer
HIPswitches. And, unless the incoming
HIPswitch connection presents a trusted
cryptographic identity in the first packet,
the connection is ignored.
Insider attacks within the network are
mitigated with this approach because it is
easy to microsegment the customer's network.
If a compromise (whether human or
malware) occurs, the ability for that threat
to propagate to other parts of the network
is very limited, and log messages will be
generated to indicate these attempts. Furthermore,
authentication services can be
layered into network access for human users
to provide additional levels of security
control, awareness, and logging.
Human factors at the administrative
level will always be an important consideration
in any organization, and this issue
is present when using an orchestration service
to manage security and connectivity.
Tempered Networks has incorporated approaches
for managing this risk, including
role-based authorization, granular logging,
and increased visibility through an emphasis
on collaboration.
Works Well with Other IT Security
Systems
Customers often have invested in other IT
security solutions, such as firewalls, deep
packet inspection (DPI), security incident
and event management (SIEM) systems, data
diodes, and network intrusion detection systems
(NIDS). The Tempered Networks solution
works with any of these existing systems
and preserves the customer's investment.
POWER | February 2015
http://www.powermag.com

POWER February 2015

Table of Contents for the Digital Edition of POWER February 2015

Contents
POWER February 2015 - Cover1
POWER February 2015 - Cover2
POWER February 2015 - Contents
POWER February 2015 - 2
POWER February 2015 - 3
POWER February 2015 - 4
POWER February 2015 - 5
POWER February 2015 - 6
POWER February 2015 - 7
POWER February 2015 - 8
POWER February 2015 - 9
POWER February 2015 - 10
POWER February 2015 - 11
POWER February 2015 - 12
POWER February 2015 - 13
POWER February 2015 - 14
POWER February 2015 - 15
POWER February 2015 - 16
POWER February 2015 - 17
POWER February 2015 - 18
POWER February 2015 - 19
POWER February 2015 - 20
POWER February 2015 - 21
POWER February 2015 - 22
POWER February 2015 - 23
POWER February 2015 - 24
POWER February 2015 - 25
POWER February 2015 - 26
POWER February 2015 - 27
POWER February 2015 - 28
POWER February 2015 - 29
POWER February 2015 - 30
POWER February 2015 - 31
POWER February 2015 - 32
POWER February 2015 - 33
POWER February 2015 - 34
POWER February 2015 - 35
POWER February 2015 - 36
POWER February 2015 - 37
POWER February 2015 - 38
POWER February 2015 - 39
POWER February 2015 - 40
POWER February 2015 - 41
POWER February 2015 - 42
POWER February 2015 - 43
POWER February 2015 - 44
POWER February 2015 - 45
POWER February 2015 - 46
POWER February 2015 - 47
POWER February 2015 - 48
POWER February 2015 - 49
POWER February 2015 - 50
POWER February 2015 - 51
POWER February 2015 - 52
POWER February 2015 - 53
POWER February 2015 - 54
POWER February 2015 - 55
POWER February 2015 - 56
POWER February 2015 - 57
POWER February 2015 - 58
POWER February 2015 - 59
POWER February 2015 - 60
POWER February 2015 - 61
POWER February 2015 - 62
POWER February 2015 - 63
POWER February 2015 - 64
POWER February 2015 - 65
POWER February 2015 - 66
POWER February 2015 - 67
POWER February 2015 - 68
POWER February 2015 - 69
POWER February 2015 - 70
POWER February 2015 - 71
POWER February 2015 - 72
POWER February 2015 - 73
POWER February 2015 - 74
POWER February 2015 - 75
POWER February 2015 - 76
POWER February 2015 - Cover3
POWER February 2015 - Cover4
https://www.nxtbook.com/accessintelligence/POWER/pwr_may-2024
https://www.nxtbook.com/accessintelligence/POWER/pwr_april-2024
https://www.nxtbook.com/accessintelligence/POWER/pwr_march-2024
https://www.nxtbook.com/accessintelligence/POWER/pwr_february-2024
https://www.nxtbook.com/accessintelligence/POWER/pwr_january-2024
https://www.nxtbook.com/accessintelligence/POWER/pwr_december-2023
https://www.nxtbook.com/accessintelligence/POWER/pwr_november-2023
https://www.nxtbook.com/accessintelligence/POWER/power-october-2023
https://www.nxtbook.com/accessintelligence/POWER/re-tech-supp-to-power-september-2023
https://www.nxtbook.com/accessintelligence/POWER/power-september-2023
https://www.nxtbook.com/accessintelligence/POWER/power-and-re-tech-supp-september-2023
https://www.nxtbook.com/accessintelligence/POWER/power-august-2023
https://www.nxtbook.com/accessintelligence/POWER/power-july-2023
https://www.nxtbook.com/accessintelligence/POWER/power-june-2023
https://www.nxtbook.com/accessintelligence/POWER/power-may-2023
https://www.nxtbook.com/accessintelligence/POWER/power-april-2023
https://www.nxtbook.com/accessintelligence/POWER/power-march-2023
https://www.nxtbook.com/accessintelligence/POWER/power-february-2023
https://www.nxtbook.com/accessintelligence/POWER/power-january-2023
https://www.nxtbook.com/accessintelligence/POWER/power-december-2022
https://www.nxtbook.com/accessintelligence/POWER/power-november-2022
https://www.nxtbook.com/accessintelligence/POWER/Power-October-2022-140th-Anniversary-Supp
https://www.nxtbook.com/accessintelligence/POWER/Power-October-2022-and-Anniversary-Supp
https://www.nxtbook.com/accessintelligence/POWER/power-and-re-tech-supp-september-2022
https://www.nxtbook.com/accessintelligence/POWER/power-september-2022
https://www.nxtbook.com/accessintelligence/POWER/power-august-2022
https://www.nxtbook.com/accessintelligence/POWER/Power-July-2022-Intl
https://www.nxtbook.com/accessintelligence/POWER/power-july-2022
https://www.nxtbook.com/accessintelligence/POWER/power-june-2022-intl
https://www.nxtbook.com/accessintelligence/POWER/power-june-2022
https://www.nxtbook.com/accessintelligence/POWER/power-may-2022
https://www.nxtbook.com/accessintelligence/POWER/power-may-2022-intl
https://www.nxtbook.com/accessintelligence/POWER/power-april-2022
https://www.nxtbook.com/accessintelligence/POWER/Power-April-2022-Intl
https://www.nxtbook.com/accessintelligence/POWER/power-march-2022
https://www.nxtbook.com/accessintelligence/POWER/power-february-2022
https://www.nxtbook.com/accessintelligence/POWER/power-january-2022
https://www.nxtbook.com/accessintelligence/POWER/power-december-2021
https://www.nxtbook.com/accessintelligence/POWER/power-top-plants-supp-december-2021
https://www.nxtbook.com/accessintelligence/POWER/power-november-2021
https://www.nxtbook.com/accessintelligence/POWER/power-october-2021
https://www.nxtbook.com/accessintelligence/POWER/power-september-2021
https://www.nxtbook.com/accessintelligence/POWER/power-august-2021
https://www.nxtbook.com/accessintelligence/POWER/power-july-2021
https://www.nxtbook.com/accessintelligence/POWER/power-june-2021
https://www.nxtbook.com/accessintelligence/POWER/power-may-2021
https://www.nxtbook.com/accessintelligence/POWER/power-april-2021
https://www.nxtbook.com/accessintelligence/POWER/power-march-2021
https://www.nxtbook.com/accessintelligence/POWER/power-february-2021
https://www.nxtbook.com/accessintelligence/POWER/power-january-2021
https://www.nxtbook.com/accessintelligence/POWER/power-december-2020
https://www.nxtbook.com/accessintelligence/POWER/power-november-2020
https://www.nxtbook.com/accessintelligence/POWER/power-october-2020
https://www.nxtbook.com/accessintelligence/POWER/power-september-2020
https://www.nxtbook.com/accessintelligence/POWER/power-august-2020
https://www.nxtbook.com/accessintelligence/POWER/power-july-2020
https://www.nxtbook.com/accessintelligence/POWER/power-june-2020
https://www.nxtbook.com/accessintelligence/POWER/power-may-2020
https://www.nxtbook.com/accessintelligence/POWER/power-april-2020
https://www.nxtbook.com/accessintelligence/POWER/power-march-2020
https://www.nxtbook.com/accessintelligence/POWER/power-february-2020
https://www.nxtbook.com/accessintelligence/POWER/power-january-2020
https://www.nxtbook.com/accessintelligence/POWER/power-december-2019
https://www.nxtbook.com/accessintelligence/POWER/power-november-2019
https://www.nxtbook.com/accessintelligence/POWER/power-october-2019
https://www.nxtbook.com/accessintelligence/POWER/power-september-2019
https://www.nxtbook.com/accessintelligence/POWER/power-august-2019
https://www.nxtbook.com/accessintelligence/POWER/power-july-2019
https://www.nxtbook.com/accessintelligence/POWER/power-june-2019
https://www.nxtbook.com/accessintelligence/POWER/power-may-2019
https://www.nxtbook.com/accessintelligence/POWER/power-april-2019
https://www.nxtbook.com/accessintelligence/POWER/power-march-2019
https://www.nxtbook.com/accessintelligence/POWER/power-february-2019
https://www.nxtbook.com/accessintelligence/POWER/power-january-2019
https://www.nxtbook.com/accessintelligence/POWER/power-december-2018
https://www.nxtbook.com/accessintelligence/POWER/power-november-2018
https://www.nxtbook.com/accessintelligence/POWER/power-october-2018
https://www.nxtbook.com/accessintelligence/POWER/power-september-2018
https://www.nxtbook.com/accessintelligence/POWER/power-august-2018
https://www.nxtbook.com/accessintelligence/POWER/power-july-2018
https://www.nxtbook.com/accessintelligence/POWER/power-june-2018
https://www.nxtbook.com/accessintelligence/POWER/power-may-2018
https://www.nxtbook.com/accessintelligence/POWER/power-april-2018
https://www.nxtbook.com/accessintelligence/POWER/power-march-2018
https://www.nxtbook.com/accessintelligence/POWER/power-february-2018
https://www.nxtbook.com/accessintelligence/POWER/power-january-2018
https://www.nxtbook.com/accessintelligence/POWER/power-december-2017
https://www.nxtbook.com/accessintelligence/POWER/power-november-2017
https://www.nxtbook.com/accessintelligence/POWER/power-october-2017
https://www.nxtbook.com/accessintelligence/POWER/power-september-2017
https://www.nxtbook.com/accessintelligence/POWER/power-august-2017
https://www.nxtbook.com/accessintelligence/POWER/power-july-2017
https://www.nxtbook.com/accessintelligence/POWER/power-june-2017
https://www.nxtbook.com/accessintelligence/POWER/power-may-2017
https://www.nxtbook.com/accessintelligence/POWER/power-april-2017
https://www.nxtbook.com/accessintelligence/POWER/power-march-2017
https://www.nxtbook.com/accessintelligence/POWER/power-february-2017
https://www.nxtbook.com/accessintelligence/POWER/power-january-2017
https://www.nxtbook.com/accessintelligence/POWER/power-december-2016
https://www.nxtbook.com/accessintelligence/POWER/power-november-2016
https://www.nxtbook.com/accessintelligence/POWER/power-october-2016
https://www.nxtbook.com/accessintelligence/POWER/power-september-2016
https://www.nxtbook.com/accessintelligence/POWER/power-august-2016
https://www.nxtbook.com/accessintelligence/POWER/power-july-2016
https://www.nxtbook.com/accessintelligence/POWER/power-june-2016
https://www.nxtbook.com/accessintelligence/POWER/power-may-2016
https://www.nxtbook.com/accessintelligence/POWER/power-april-2016
https://www.nxtbook.com/accessintelligence/POWER/power-march-2016
https://www.nxtbook.com/accessintelligence/POWER/power-february-2016
https://www.nxtbook.com/accessintelligence/POWER/power-january-2016
https://www.nxtbook.com/accessintelligence/POWER/power-december-2015
https://www.nxtbook.com/accessintelligence/POWER/power-november-2015
https://www.nxtbook.com/accessintelligence/POWER/power-october-2015
https://www.nxtbook.com/accessintelligence/POWER/power-september-2015
https://www.nxtbook.com/accessintelligence/POWER/power-august-2015
https://www.nxtbook.com/accessintelligence/POWER/power-july-2015
https://www.nxtbook.com/accessintelligence/POWER/power-june-2015
https://www.nxtbook.com/accessintelligence/POWER/power-may-2015
https://www.nxtbook.com/accessintelligence/POWER/power-april-2015
https://www.nxtbook.com/accessintelligence/POWER/power-march-2015
https://www.nxtbook.com/accessintelligence/POWER/power-february-2015
https://www.nxtbook.com/accessintelligence/POWER/power-january-2015
https://www.nxtbook.com/accessintelligence/POWER/power-december-2014
https://www.nxtbook.com/accessintelligence/POWER/power-november-2014
https://www.nxtbook.com/accessintelligence/POWER/power-october-2014
https://www.nxtbook.com/accessintelligence/POWER/power-september-2014
https://www.nxtbook.com/accessintelligence/POWER/power-august-2014
https://www.nxtbook.com/accessintelligence/POWER/power-july-2014
https://www.nxtbook.com/accessintelligence/POWER/power-june-2014
https://www.nxtbook.com/accessintelligence/POWER/power-may-2014
https://www.nxtbook.com/accessintelligence/POWER/power-april-2014
https://www.nxtbook.com/accessintelligence/POWER/power-march-2014
https://www.nxtbook.com/accessintelligence/POWER/power-february-2014
https://www.nxtbook.com/accessintelligence/POWER/power-january-2014
https://www.nxtbook.com/accessintelligence/POWER/power-december-2013
https://www.nxtbook.com/accessintelligence/POWER/power-november-2013
https://www.nxtbook.com/accessintelligence/POWER/power-october-2013
https://www.nxtbook.com/accessintelligence/POWER/power-september-2013
https://www.nxtbook.com/accessintelligence/POWER/power-august-2013
https://www.nxtbook.com/accessintelligence/POWER/power-july-2013
https://www.nxtbook.com/accessintelligence/POWER/power-june-2013
https://www.nxtbook.com/accessintelligence/POWER/power-may-2013
https://www.nxtbook.com/accessintelligence/POWER/power-april-2013
https://www.nxtbook.com/accessintelligence/POWER/power-march-2013
https://www.nxtbook.com/accessintelligence/POWER/power-february-2013
https://www.nxtbook.com/accessintelligence/POWER/power-january-2013
https://www.nxtbook.com/accessintelligence/POWER/power-december-2012
https://www.nxtbook.com/accessintelligence/POWER/power-november-2012
https://www.nxtbook.com/accessintelligence/POWER/power-october-2012
https://www.nxtbook.com/accessintelligence/POWER/power-september-2012
https://www.nxtbook.com/accessintelligence/POWER/power-august-2012
https://www.nxtbook.com/accessintelligence/POWER/power-july-2012
https://www.nxtbook.com/accessintelligence/POWER/power-june-2012
https://www.nxtbook.com/accessintelligence/POWER/power-may-2012
https://www.nxtbook.com/accessintelligence/POWER/power-april-2012
https://www.nxtbook.com/accessintelligence/POWER/power-march-2012
https://www.nxtbook.com/accessintelligence/POWER/power-february-2012
https://www.nxtbook.com/accessintelligence/POWER/power-january-2012
https://www.nxtbook.com/accessintelligence/POWER/power-november-2011
https://www.nxtbook.com/accessintelligence/POWER/power-october-2011
https://www.nxtbook.com/accessintelligence/POWER/power-september-2011
https://www.nxtbook.com/accessintelligence/POWER/power-august-2011
https://www.nxtbook.com/accessintelligence/POWER/power-july-2011
https://www.nxtbook.com/accessintelligence/POWER/power-june-2011
https://www.nxtbook.com/accessintelligence/POWER/power-may-2011
https://www.nxtbook.com/accessintelligence/POWER/power-april-2011
https://www.nxtbook.com/accessintelligence/POWER/power-march-2011
https://www.nxtbook.com/accessintelligence/POWER/power-february-2011
https://www.nxtbook.com/accessintelligence/POWER/power-january-2011
https://www.nxtbook.com/accessintelligence/POWER/power-december-2010
https://www.nxtbook.com/accessintelligence/POWER/power-november-2010
https://www.nxtbook.com/accessintelligence/POWER/power-october-2010
https://www.nxtbook.com/accessintelligence/POWER/power-september-2010
https://www.nxtbook.com/accessintelligence/POWER/power-august-2010
https://www.nxtbook.com/accessintelligence/POWER/power-july-2010
https://www.nxtbook.com/accessintelligence/POWER/power-june-2010
https://www.nxtbook.com/accessintelligence/POWER/power-may-2010
https://www.nxtbookmedia.com