The Cyber Security Review | Saturday, November 26, 2022
With the rampant spread of cybercrime, a tremendous amount of work is being done to protect their computer networks from securing bits and bytes.
FREMONT, CA: Due to the widespread prevalence of cybercrime, much effort is being put forth to safeguard computer networks and secure bits and bytes. But at the same time, more must be done to protect our atoms, specifically the physical infrastructure that underpins the global economy.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Nations are awash in operational technology (OT) platforms that have virtually automated every aspect of their physical infrastructure, including buildings, bridges, trains, cars, and the machinery and production lines that keep their economies humming. But it's still a novel idea to think that a bridge, a jet, or a hospital bed might all be compromised. Such threats must be taken seriously since they could result in catastrophic damage.
For example, a major power plant is attacked, and the Northeast United States is left without heat during a particularly severe cold wave. Take into account the extreme suffering, and possibly even death, that such an attack would bring about as houses would go dark, businesses would be cut off from consumers, hospitals would struggle to function, and airports would close.
The Stuxnet virus was the first sign that physical infrastructure would be a significant target for cyber threats, which initially surfaced more than ten years ago. Including a uranium enrichment plant, Stuxnet was a harmful worm that infiltrated the software of at least 14 industrial locations in Iran.
Since then, the Stuxnet virus has evolved and spread to other industrial and energy-generating sites throughout the globe. The truth is that Stuxnet-like assaults are now possible against critical infrastructure worldwide. Vital systems used in the most significant sectors of the global economy, such as manufacturing, power, water, transportation, and finance, have security weaknesses.
Built-in Vulnerability
The issue is that makers of operational technology need to put security into the design of their goods. As a result, trillions of dollars worth of OT assets are currently highly susceptible. Most of these items are constructed using microcontrollers that connect via the unreliable CAN system. Everything from passenger cars and farm machinery to medical devices and home automation uses the CAN system. However, it doesn't directly support secure communications. Additionally, it lacks the necessary permission and authentication. For instance, neither the sender's nor the receiver's addresses are disclosed in a CAN frame.
As a result, CAN bus networks are becoming more open to hostile intrusions, especially with the growth of the cyberattack landscape. New strategies and solutions are required to properly secure CAN buses and safeguard crucial infrastructure.
A CAN bus works as a shared communication path for numerous microprocessors. For example, the CAN bus enables seamless communication between the engine system, combustion system, braking system, and lighting system through a common channel in an automobile.
Hackers, however, can obstruct that communication and begin sending arbitrary messages that nonetheless adhere to the protocol because the CAN bus is fundamentally insecure. Imagine the chaos resulting from even a little hack of automated vehicles, turning them into a swarm of potentially dangerous things.
Designing a security mechanism for CAN with robust, embedded protection, high fault tolerance, and low cost represents a problem for the automobile sector, in fact, for all significant industries. Because of this, there is a vast market potential for firms that can tackle this problem and ultimately protect our physical assets from cyberattacks, including every aeroplane, train, manufacturing system, etc.
How OT Security Would Work
Well, it might address the security issue by adding a layer of authentication and intelligence to an older CAN bus. This solution might deconstruct the protocol and intercept CAN data to augment communications passing across OT data buses and alert users to unusual activity. After installing such a solution, operators of highly valuable physical equipment would get real-time, actionable intelligence about anomalies and incursions in their systems, making them better prepared to fend off any cyberattack.
This kind of business will probably originate in the defence sector. It will be able to assess different machine protocols and have fundamental solid technology in the embedded data plane.
This is a business opportunity with a USD 10 billion plus potential with the right team and support. Few duties are more crucial than safeguarding our physical infrastructure. Because of this, there is a significant need for fresh approaches that are laser-focused on fortifying vital assets against cyberattacks.
Decision-maker for Data
Experts working with data, including technical employees, can contribute their thoughts and breakthroughs on DataDecisionMakers. To learn about cutting-edge concepts, current information, best practices, and data and technology's future.
More in News