Security module analyses and filters Modbus TCP messages
Posted to News on 23rd Oct 2008, 12:19

Security module analyses and filters Modbus TCP messages

MTL Instruments is launching a security module designed specifically for managing Modbus TCP. Byres Security and MTL Instruments, a division of Cooper Crouse-Hinds, are introducing the Tofino Modbus TCP Enforcer Loadable Security Module (LSM), which performs detailed analysis and filtering of all Modbus TCP messages and is certified by Modbus-IDA. It enables owners of control and SCADA systems to regulate Modbus network traffic to a level of detail that the companies say has never before been possible, thereby increasing network security, reliability and performance of critical systems.

Security module analyses and filters Modbus TCP messages

Daniel Lacroix, Corporate Information Security Officer for The Saint Lawrence Seaway Management Corporation (SLSMC), states: "The ability to filter individual Modbus commands has tremendous potential to improve the security of our control networks." The SLSMC operates over 30 locks and bridges on the Canadian side of the Saint Lawrence Seaway, a major marine transportation system that carried over 43million tonnes of cargo in 2007.

'Deep packet' or 'content' inspection for web email or traffic has been offered in IT firewalls for several years but, according to MTL, nothing has been available for the process control or SCADA world. Modbus traffic could either be allowed or blocked by a standard firewall, but fine-grained control was impossible. And since the smooth flow of Modbus TCP traffic is critical to the average industrial facility, engineers usually opted to let everything pass and take their chances with security.

Government warning

Industry experts have been urgently calling for better control of SCADA protocols. Earlier in 2008, a major American government agency warned major energy companies: "A vulnerability has been identified and verified within the firmware upgrade process used in control systems deployed in Critical Infrastructure and Key Resources (CIKR)... development of a mitigation plan is required to protect the installed customer base and the CIKR of the nation. Firmware Vulnerability Mitigation Steps [includes] blocking network firmware upgrades with appropriate firewall rules."

Two global energy companies and a major transportation company have trialled the Tofino ModbusTCP Enforcer LSM and have been impressed with how it enables them to follow the government's guidance and enhance both the security and stability of their systems. They have been able to restrict Modbus functions in numerous ways, by:

  • Blocking all firmware upgrades while allowing normal HMI traffic
  • Tailoring appropriate Modbus access permissions to PLCs for different stations such as read-only for monitoring panels, read/write for HMIs and full programming and diagnostics access for PLC engineering workstations
  • Restricting Modbus access permissions to specific memory locations in a controller
  • Providing enhanced security and protection for any Modbus TCP device including filtering of invalid traffic that could cause denial of service or system failures
  • Enforcing read-only access to safety-instrumented systems for enhanced isolation and safety

Eric Byres, CTO at Byres Security, notes: "The Modbus TCP Enforcer is another key step in our Tofino Zone Level Security strategy. Tofino provides tailored protection for groups of PLCs, DCSs, RTUs and HMIs and does it in a way that is simple to implement for control engineers. Security is taken care of, and focus can be maintained on keeping processes running safely and efficiently."

The Tofino Modbus TCP Enforcer LSM is now available world wide from MTL Instruments.

About the Tofino industrial security device

The complete Tofino industrial security product consists of three core components:

  • Tofino Security Appliance - an industrially hardened and certified appliance that is installed in front of individual and/or zones of HMI, DCS, PLC or RTU control devices that require protection. Retail price: $1000.
  • Tofino Loadable Security Modules (LSM) - a variety of software plug-ins providing security services such as firewall, secure asset management and VPN encryption. Each LSM is downloaded into the security appliances to enable them to offer customisable security functions, depending on the requirements of the control system. Retail price: varies according to LSM, between $200 and $500.
  • Tofino Central Management Platform (CMP) - a centralised management system and database for monitoring, supervision and configuration of each security appliance, regardless of its physical location. Retail price: $3500. One Tofino central management platform can manage several Tofino security appliances and LSMs.


MTL Instruments

Power Court
LU1 3JJ
UNITED KINGDOM

+44 (0)1582 723633

Bosch Rexroth Pilz Automation Ltd ABSSAC Ltd Procter Machine Safety SICK (UK) LTD Mechan Controls Ltd Euchner (UK) Rittal Ltd Murrelektronik Ltd Spelsberg Els UK Ltd HARTING Ltd Leuze electronic Ltd Kawasaki Robotics (UK) Ltd WEG (UK) Ltd Phoenix Contact Ltd Micro Epsilon UK Limited AutomateUK Machinesafe Compliance Ltd STOBER Drives Ltd Dold Industries Ltd Smartscan Ltd Aerotech Ltd FATH Components Ltd Heidenhain (GB) Ltd AutomateUK M Buttkereit Ltd Servo Components & Systems Ltd PI (Physik Instrumente) Ltd