The storage of petroleum products (crude and processed oil) is a complex industrial process. Oil storage tanks are tasked with maintaining precise environmental conditions (e.g. temperature, pressure and electromagnetic insulation), deviations from which may lead to horrendous environmental results.
When one of the largest petroleum distribution firms in Southeast Asia sought a solution for protecting one of its storage terminal facilities (and meet governmental cyber-security regulations), the project’s specifications included, in addition to mere intrusion detection, also monitoring and management of multiple disparate intrusion detection systems, as well as tight control over access authorization management during maintenance operations.
The oil storage terminal security project encompassed a large number of tanks, divided into three units. Each unit was to be connected to a Radiflow iSID intrusion detection system, for detecting anomalies, which may indicate an insider attack (e.g. installing malicious logic on a PLC or introducing an unauthorized device into the network).
iSID’s multiple security engines offer capabilities pertaining to specific type of network activity: modeling and visibility of OT and IT devices, protocols and sessions; detection of threats and attacks; policy monitoring and validation of operational parameters; rules-based maintenance management; and networked device management.
The three instances of iSID were to be monitored and managed remotely from a central Security Operations Center (SOC).
To allow the remote management of multiple iSID systems, Radiflow’s iCEN Central Monitoring System was used to display aggregated data from all iSID instances in an organization. This included full asset information, alerts (prioritized by severity and originating iSID detection engine) and network protocols used.
iCEN displays a status snapshot of all iSID instances across the organization, including their total risk and activity status, with easy drill-down and remote connection to each iSID instance.
Users are able to switch between geographical map and tabular display modes, both featuring color-coding for quick cross-site prioritization. iCEN provides a quick summary status, detailed properties and health monitoring status (CPU, RAM) for each monitored instance of iSID.
In addition, a number of Radiflow’s iSEG 3180 DPI Firewall/Ruggedized Secure Gateways were installed at each tank. The iSEG gateway provides DPI firewall capabilities for analyzing SCADA traffic.
Upon detecting an anomaly the 3180 will automatically generate alerts, block the abnormal activity and isolate any affected sub-networks. To facilitate compliance with local regulations, the iSEG RF-3180 includes an APA (Authentication Proxy Access) which allows remote access to authorized personal at predefined time slots.
To maximize efficiency, each RF-3180 Firewall/Gateway also hosted in its chassis an instance of Radiflow’s iSAP Smart Collector.
iSAP provides a cost effective, non-intrusive method for sending large volumes of data traffic from the gateways (using a mirrored stream) without over-taxing the local network (as is the case with typical data traffic collectors). This is done using Radiflow’s proprietary compression and filtering (removal of IT protocol data) algorithm. The use of iSAP allowed installing only a handful of instances of iSID, thus reducing the overall cost of the project.
Multiple instances of the iSID Industrial Threat Detection System were installed at the oil terminal, all managed remotely through the Radiflow iCEN Remote Management System.
After weighing all vendors’ proposals, the client chose Radiflow for the project based on a number of factors:
At present, the Radiflow system is fully-functional, and has been regularly detecting anomalies and issuing recommendations for remediation since it began operations.
Strengthening OT Resilience: Protecting Critical Systems in a Rapidly Evolving Threat Environment
Quarterly ICS Security Report 2024 Q3
Cybersecurity e Safety: le sfide della Transizione 5.0 | 15 novembre 2024