• No results found

SIMPLIFYING THE PATCH MANAGEMENT PROCESS

N/A
N/A
Protected

Academic year: 2021

Share "SIMPLIFYING THE PATCH MANAGEMENT PROCESS"

Copied!
26
0
0

Loading.... (view fulltext now)

Full text

(1)

Cyber Security | Compliance | Industrial Computing

SIMPLIFYING THE

PATCH MANAGEMENT PROCESS

www.icsupdate.com

Monta Elkins | Security Architect | FoxGuard Solutions [email protected]

(2)

Cyber Security | Compliance | Industrial Computing 2 www.foxguardsolutions.com

SIMPLIFYING

THE

(3)

Cyber Security | Compliance | Industrial Computing

SIMPLIFYING THE PATCH MANAGEMENT PROCESS

Why Patch?

Because You Need To

3 www.foxguardsolutions.com

(4)

Cyber Security | Compliance | Industrial Computing

SIMPLIFYING THE PATCH MANAGEMENT PROCESS

What Needs Patching?

EVERYTHING

(a lot more than you think)

4 www.foxguardsolutions.com

(5)

Cyber Security | Compliance | Industrial Computing

SIMPLIFYING THE PATCH MANAGEMENT PROCESS

How Can You Discover

All Patch Releases?

With Great Difficulty

5 www.foxguardsolutions.com

(6)

Cyber Security | Compliance | Industrial Computing

SIMPLIFYING THE PATCH MANAGEMENT PROCESS

How Hard Is It To Keep Up?

Hard

6 www.foxguardsolutions.com

(7)

Cyber Security | Compliance | Industrial Computing

SIMPLIFYING THE PATCH MANAGEMENT PROCESS

What Does The DOE Sponsored

Patch & Update Management

Program (

PUMP

) Do?

7 www.foxguardsolutions.com

(8)

Cyber Security | Compliance | Industrial Computing

SIMPLIFYING THE

PATCH MANAGEMENT PROCESS

Monta Elkins | Security Architect | FoxGuard Solutions [email protected]

8 www.foxguardsolutions.com

(9)

Cyber Security | Compliance | Industrial Computing

SIMPLIFYING THE PATCH MANAGEMENT PROCESS

How (

You Might Ask

)?

With Great Care

9 www.foxguardsolutions.com

(10)

Cyber Security | Compliance | Industrial Computing

PATCH AND UPDATE MANAGEMENT PROGRAM

In 2013, the Department of Energy (DOE) selected FoxGuard Solutions’ Patch and Update Management Program in response to a DOE request for proposals

FoxGuard Solutions was selected in part based upon our background in patch validation and automated patch

deployment for GE, Toshiba, and others

10 www.foxguardsolutions.com

We have also partnered with Critical Intelligence for development, recently acquired by iSight Partners

(11)

Cyber Security | Compliance | Industrial Computing

FOXGUARD PATCHING AROUND THE WORLD

11 www.foxguardsolutions.com

FOXGUARD’S PATCHING SOLUTIONS ARE USED IN 167 ICS SITES, IN 36 STATES AND 15 COUNTRIES

(12)

Cyber Security | Compliance | Industrial Computing

OBLIGATORY DEFINITION SLIDE

A patch is a software update comprised code inserted (or patched) into the code of an executable program.

Typically, a patch is installed into an existing software program.

Patches are often temporary fixes between full releases of a

software package.

-Techopedia

What does “

Patch

” Mean?

12 www.foxguardsolutions.com

(13)

Cyber Security | Compliance | Industrial Computing

PATCH FUNCTIONS

Patches may do any of the following: Upgrade the software features

Fix a software problem

Address software stability issues

Address security vulnerabilities

NERC CIP Requirements Hard for you to know

13 www.foxguardsolutions.com

“Updates” and “Firmware” also perform these required functions, so consider them as well whenever I say “patch”

(14)

Cyber Security | Compliance | Industrial Computing

PATCH CREATOR SOURCES

Patches Come From Different Creators

Patch Creator Sources Include: OS Vendor

SCADA Vendor

Equipment Vendor

Other Software Vendor A/V IDS Vendor

14 www.foxguardsolutions.com

(15)

Cyber Security | Compliance | Industrial Computing

PATCH APPROVAL SOURCES

The Same Patch Can Have Various Approvals

Depending On Patch Approval Source

Patch Approval Sources Include OS Vendor SCADA Vendor Equipment Vendor Integrator Company 15 www.foxguardsolutions.com

(16)

Cyber Security | Compliance | Industrial Computing

DESTINATION

The Same Patch Can Have Various Approval Statuses And Dates Depending On Both The Source And The Destination

16 www.foxguardsolutions.com

OS VENDOR VENDOR SCADA

CORPORATE

COMPUTER COMPUTER PLANT COMPUTER PLANT COMPUTER PLANT

OS

PA

TC

H OS PATCH & APPLICATION PATCH

SC AD A PA TC H IN TE G R AT IO N PA TC H INTEGRATION VENDOR Site Approval

(17)

Cyber Security | Compliance | Industrial Computing Programmable Electronic Devices (In NERC CIP Speak)

Virtually Everything That Plugs Into Power, Or Has Batteries (Monta Speak)

– Computers (HMIs, Workstations, Laptops, Thin Clients)

– Operating system (Windows, Linux, VxWorks)

– Other software (Acrobat Reader, Excel, Flash, Java) – SCADA packages

– BIOS

– USB Controller

– Video Card Firmware – Network Cards

– Raid Controller – Printers

– USB Thumb drives

17 www.foxguardsolutions.com

(18)

Cyber Security | Compliance | Industrial Computing

WHAT NEEDS SECURITY UPDATES/PATCHING?

ICS & Other Hardware

– PLCs – RTUs – Intelligent Sensors – Intelligent Actuators – VOIP Phones – Displays/Monitors/TV’s – Test Equipment – Scopes – Meters

– Network Gear They Attach To

– Switches

– Firewalls

– IDS (Intrusion Detection Systems)

– Security gateways

– DLP (Data Loss Prevention)

18 www.foxguardsolutions.com

(19)

Cyber Security | Compliance | Industrial Computing

COMBINATIONS

The same patch can have various approval statuses and dates depending on both the source and the destination

19 www.foxguardsolutions.com

(20)

Cyber Security | Compliance | Industrial Computing

HOW DOES PUMP HELP?

Collection And Monitoring Of Patch/Update Metadata Aggregated Patch Release Information

– OS Vendors, SCADA Vendors, Hardware Vendors, Integrators – Patch Applicability For Individual Devices

– Patch Approval Per Device, Per Vendor, Per Site

– With Links To Patch Source, (Actual Patch Only Available From Vendor)

Internal Approval Process And "Patch Gap” Reporting

Track Device Status: Patched, Out Of Date, Scheduled, Mitigation

– PUMP Can Train To Develop Approval/Validation Process

Related Discussion

– Anonymous Information Sharing With Reputation

20 www.foxguardsolutions.com

(21)

Cyber Security | Compliance | Industrial Computing

WHEN YOU ARE SERIOUS ABOUT PATCHING

 Patch Security Information

– Is This A Security Related Patch

– Are There Related CERT Notices, CVE’s

 Allow Multiple Customer Accounts With Access

Control To Support Large Organizations (e.g.)

– Compliance Manager Role – Implementation Engineer Role

 Compliance Support Documentation

– e.g. CIP Requires Documenting Patch Sources For Cyber Assets And Evaluating Available Patches Every 35 Days

 Positive Notification

– Notification For Each Device On A Regular Schedule – Notification Of “Negative Change”

21 www.foxguardsolutions.com

(22)

Cyber Security | Compliance | Industrial Computing

PUMP - MORE PATCHES AND UPDATES

Vendors

– If You Are A Vendor And Would Like Patch And Update Information Included About Your Products, Please Contact Us.

– Vendor Involvement Available, Contact Us – Use BY Vendors – (How Do You Keep Up

With All Of Your Patch Sources?)

A Single Source To Check For All / Most Vendor Patch Information

– Links Provided

– Contracts With Your Vendor To GET Patches

May Be Required

– If You Would Like To Request Specific Devices

For Priority Implementation, Contact FoxGuard

22 www.foxguardsolutions.com

(23)

Cyber Security | Compliance | Industrial Computing

AUTHENTICITY VERIFICATION TOOLSET

Patch And Update Authenticity Verification Toolset

– Verify File Hashes

– Verify Digital Signatures

– Tools, Training And Assistance For Vendors To Help Make

Signed Hash Files Available For Their Patches / Updates

23 www.foxguardsolutions.com

Where Hashes / Signatures Aren’t Available – Provide Carefully Documented Community Hash

Information To Identify Exceptions

– Provide Hash Data From Various Networks To Help Identify Man-in-the-middle Attacks

(24)

Cyber Security | Compliance | Industrial Computing

FIRMWARE VERSION QUERY

Patch And Update Version Query

– Version Data Collection Engine - Per Device

– Gap Analysis And Reporting Dashboard

– Querying / “Scanning” Is Not “Network Scanning”

– Think modbus/telnet/ssh query to identify device and firmware

24 www.foxguardsolutions.com

– Used In Combination With Patch

Data Aggregator Service For Gap Analysis

– Also Used After Updates To Verify

Firmware Installation

– Works In Conjunction With Your

(25)

Cyber Security | Compliance | Industrial Computing

PUMP DEMONSTRATION SITES

Provide Training, And Implementation, At Two Asset Owner’s Locations

25 www.foxguardsolutions.com

Training programing includes all the necessary tools and skills to setup and implement a successful patch and

update management program

– Including creating an approval/validation program Testing a full validation cycle with

patch and update deployment End-user feedback gathered to

(26)

Cyber Security | Compliance | Industrial Computing

SIMPLIFYING THE

PATCH MANAGEMENT PROCESS

www.icsupdate.com

Monta Elkins | Security Architect | FoxGuard Solutions [email protected]

References

Related documents

You’ll learn it, too, by shooting for Missouri journalism publications and by helping run one of the world’s largest and most important photo competitions, Pictures of the

Type Type of absolute rotary encoder connected accord- ing to type code in the accompanying documenta- tion for the encoder (EC: integrated bus cover for EtherCAT); for

Legal Vendor Network (Prevalent) Vendor Risk Management Cyber Metrics (BitSight) Cybersecurity Ratings Themes.. Cyber maturity and

Systems supported by vendor patches have the patch application integrated into a documented server maintenance process.. Server is configured with appropriate real-time

The authorised capital of an RRB is fixed at Rs.1 crore and its issued capital at Rs. Of the issued capital, 50 percent is to be subscribed by the Central Government, 15 percent

The Executive Board continues to expect that the global economic growth forecasted will have a positive impact on passenger develop- ment in the Fraport Group in 2014. At the

- Contrary to contract vendor didn’t have uniform security practices. - Contrary to contract vendor didn’t notify company of

• Maintain copies of current licenses, required bonds and insurance. • Have written copies of the notaries’ policies as to security of stamps and