Three Unique Security Vulnerabilities of Industrial Networks

Industrial automation devices control extremely critical and valuable assets, but all too often security is an afterthought in industrial networks. In the past, industrial operators trusted in their isolation, or “air gap,” from the broader network, the relative obscurity of their communications protocols, and the physical security of their facilities to protect the integrity of their networks. Now, in a changing, more connected world, automation network operators are realizing they must confront their unique security vulnerabilities. In a recent report prepared for the US Department of Homeland Security, security consultants InfraCritical found 500,000 exposed SCADA devices just by using a search engine, with 7,200 of those devices found to be controlling critical infrastructure assets such as water, energy, and other utilities. It’s not surprising, then, that security researchers characterize the state of ICS security as “laughable.”

Many industrial operators are not even aware the extent that their systems are exposed on the internet. The critical first step to closing the security gaps, then, is to acknowledge the existence of a vulnerability. But the next step is just as critical: the vulnerabilities must be completely addressed—and automation networks have three major unique vulnerabilities.

It Is Difficult to Secure Industrial Modbus TCP Protocol Packets

Even industrial networks that have moved to modern TCP/IP and Ethernet infrastructure for the transport, internet, and link layer of their communications are often still running industrial application layer protocols. The most popular of these, Modbus TCP, is also extremely vulnerable despite being widely used in industrial communications, with no built-in security systems at all.

This means that a packet that appears to be entirely legitimate when inspected as a TCP/IP packet—such as by checking its source IP address—may in fact contain malicious Modbus TCP communications that would be evident if the system were able to filter packets by Modbus source device ID, function codes, or other Modbus command type. Since industrial devices rarely have much in the way of application layer security, it’s up to the cyber security devices, such as hardware firewalls, to provide this critical missing protection. Unfortunately, conventional firewall solutions rarely include the technology to scan industrial protocols such as Modbus TCP.

Industrial Applications are Time-Critical and Can Not Tolerate Transmission Delay

SCADA and industrial control devices directly manage real-world machinery in a way that is highly time-critical. For example, on an assembly line, all of the different machinery needs to operate in perfect coordination in order for the line to keep moving. Electric substation operations are even more time-sensitive, as a delay in triggering a circuit switch could create a power fluctuation or even a blackout.

The highly time-critical nature of industrial operations means that industrial networks can not tolerate significant latency issues. However, a common assault vector used by malicious attackers is to overwhelm a network with requests, which can affect the network latency even if a firewall is able to block the unauthorized requests. Insufficient bandwidth during critical moments will also expose the network to latency issues if the firewall is struggling to process packets quickly enough to maintain timely communications.

The latency and network demands on industrial security will only grow as industrial networks become more advanced and begin to integrate more systems ,such as video, voice, and data. IP cameras generate a lot of bandwidth, and the network security devices need to have the bandwidth and throughput to support advanced applications without compromising the security of the network or the latency of other industrial operations.

Demanding Physical Environments can Overwhelm Security Devices

Industrial machinery and industrial control devices are deployed in more extreme conditions than most conventional IT network equipment. This presents a potential mismatch in the performance of industrial control devices and the network security devices that are intended to protect them—the network security devices might struggle to hold up in the sort of intense industrial conditions that industrial automation systems must operate in. Harsh environmental hazards such as extreme temperature, EMC, and EMI, can be even more damaging to network equipment than a malicious attacker. If the network security hardware is not able to shrug off these hazards, the network will remain exposed and vulnerable to attackers.

Three Unique Security Vulnerabilities of Industrial Networks
Moxa’s Gigabit-Performance Cyber Security Solution for Automation Networks

Moxa has combined its background in industrial automation with its expertise in networking to create a cyber security solution that was designed with the unique needs and requirements of automation networks in mind. The Moxa EDR-810 is an industrial multi-port secure router that includes security functionality and is specifically optimized to address the security vulnerabilities of industrial networks. In addition to a VPN that encrypts data tunnels for remote access, a NAT to hides local IPs, and a firewall that filters packets, the EDR-810 adds automation-friendly functions such as:

Deep Modbus TCP inspection: PacketGuard™, is the world’s first built-in Modbus TCP packet inspector. With PacketGuard, the EDR-810 will inspect network packets all the way up to the Modbus application level, deeper than the transport-layer scanning that conventional network firewalls can achieve.

moxa_EDR-810
moxa_EDR-810

Low latency gigabit performance: The EDR-810 can aggregate its many ports into a Gigabit uplink, for extremely low latency performance that will not interrupt industrial operations, even when used in extremely bandwidth-hungry applications such as IP video.

Highly integrated multi-port secure router with switch functions: The EDR-810 combines security, routing, and layer 2 switch functionality into a single device, making it a highly convenient and cost-effective solution that connects and protects many devices.

The EDR-810 is the latest in Moxa’s EDR family of network security devices tailored for industrial operators. Wide operating temperature range, hardened metal housings, and strong EMI/EMS resistance give Moxa’s EDR security devices the resilience to stand up to harsh operating conditions and keep up with robust industrial networks. For all the details about this entire line of advanced network security hardware, visit http://www.moxa.com/product/Industrial_Secure_Routers.htm

[ICNweb www.icnweb.kr]

TSN 국제 표준 발표

뉴스레터 구독하기

아이씨엔매거진은 AIoT, IIoT 및 피지컬 AI, 디지털트윈을 통한 제조업 디지털전환 애널리틱스를 제공합니다.
테크리포트: 자율제조, 전력전자, 모빌리티, 로보틱스, 스마트농업

AW2026 expo
ACHEMA 2027
전시회 세미나 선물 준비는 기프트랩스
오윤경 기자
오윤경 기자http://icnweb.co.kr
아이씨엔매거진 온라인 뉴스 에디터입니다. 오토메이션과 클라우드, 모빌리티, 공유경제, 엔지니어 인문학을 공부하고 있습니다. 보도자료는 아래 이메일로 주세요. => news@icnweb.co.kr
fastech EtherCAT
as-interface
GiftLabs

Related Articles

Stay Connected

440FansLike
407FollowersFollow
224FollowersFollow
120FollowersFollow
372FollowersFollow
152SubscribersSubscribe
기프트랩스
spot_img
실시간 제어 TSN 표준
InterPACK
spot_img
SPS 2026
automotion
Power Electronics Mag

Latest Articles

Related Articles

PENGUIN Solutions
[이슈] 스마트 공장 통신 표준 완성… IEC/IEEE 60802 TSN 통합 표준 발표

[이슈] 스마트 공장 통신 표준 완성… IEC/IEEE 60802 TSN 통합 표준...

0
국제 표준화 기구인 IEC와 IEEE가 스마트 공장의 복잡한 통신망을 하나로 통합할 수 있는 'IEC/IEEE 60802' TSN 프로필 표준을 제정하고, 글로벌 주요 자동화 협회 및 반도체 기업들이 대거 동참했다.
WindEnergy
InterPACK

Related Articles

fastech EtherCAT
as-interface
벡터, 충전 케이블 한계 100m로 늘린 DC 통신 컨트롤러 ‘vSECC.InPlug’ 공개

벡터, 충전 케이블 한계 100m로 늘린 DC 통신 컨트롤러 ‘vSECC.InPlug’ 공개

0
벡터가 DC 충전 커넥터 내부에 통신 모듈을 탑재하여 충전기 케이블 길이를 100m까지 늘려주는 'vSECC.InPlug'와 버스 차고지 통합 관리 시스템 'vCharM.DMS'를 발표했다.
ABB, AI 데이터센터용 통합 직류 솔루션 ‘인피니투스’ 출시

ABB, AI 데이터센터용 통합 직류 솔루션 ‘인피니투스’ 출시

0
ABB가 급증하는 AI 데이터센터 전력 수요에 대응하기 위해 전력 공급원에서 랙까지 연결되는 최초의 통합 직류(DC) 솔루션 ‘인피니투스’를 출시하고 800V DC 고효율 전력망 구축에 나섰다.
에티나, 엔비디아 젯슨 토르 기반 플래그십 에지 AI 시스템 ‘AIE-KT78·AIE-KT68’ 출시

에티나, 엔비디아 젯슨 토르 기반 플래그십 에지 AI 시스템 ‘AIE-KT78·AIE-KT68’ 출시

0
에지 AI 전문 기업 에티나가 엔비디아의 최신 차세대 인공지능 칩을 탑재해 협동로봇과 휴머노이드 로봇이 주변 환경을 스스로 인식하고 즉각 움직일 수 있도록 돕는 초고성능 로봇용 제어 반도체 시스템을 선보였다.
인피니언, 300A 피크 전류 구현한 AI 가속기용 초고밀도 전력 반도체 출시

인피니언, 300A 피크 전류 구현한 AI 가속기용 초고밀도 전력 반도체 출시

0
인피니언이 손톱보다 작은 단일 칩으로 최대 300A의 전류를 안전하게 공급하고 최신 액체 냉각 시스템과 연동하여 AI 데이터센터의 전력 부족과 과열 문제를 해결하는 초고밀도 전력 반도체 신제품을 선보였다.
노르딕 세미컨덕터, 초소형·초저전력 멀티 프로토콜 SoC ‘nRF54LC10A’ 출시

노르딕 세미컨덕터, 초소형·초저전력 멀티 프로토콜 SoC ‘nRF54LC10A’ 출시

0
노르딕 세미컨덕터가 초소형 1.9x2.3mm 크기에 블루투스, 스레드, 매터 통신과 첨단 보안 기능을 통합한 저전력 반도체 nRF54LC10A를 출시하여 소형 IoT 기기 개발을 간소화했다.
래티스 반도체, 양자 내성 암호 탑재 FPGA ‘Mach-N2’ 및 AI 설계 툴 ‘Lattice Prompt’ 공개

래티스 반도체, 양자 내성 암호 탑재 FPGA ‘Mach-N2’ 및 AI 설계...

0
래티스가 양자 컴퓨터 해킹 공격을 방어하는 차세대 보안 칩과 함께 복잡한 회로를 자연어로 입력하면 AI가 자동으로 설계해 개발 기간을 획기적으로 줄여주는 기술을 발표했다
- Our Youtube Channel -Engineers Youtube Channel

Latest Articles