Select Page

Non-invasive Network Intrusion and Anomaly Detection Systems and BlackEnergy 3

As mentioned on numerous occasions, to increase the security of operating environments, it is not enough to incorporate prevention countermeasures; specific systems must be deployed to facilitate dete...

As mentioned on numerous occasions, to increase the security of operating environments, it is not enough to incorporate prevention countermeasures; specific systems must be deployed to facilitate detection, response, information, and recovery.

Among the systems that help detect, respond to, and report potential threats early are non-invasive network intrusion and anomaly detection systems, specifically for OT environments.

These are solutions that are deployed in an appliance (HW + SW) that allow the detection of intrusions in the OT network in a non-invasive way (i.e., no hosts/agents are installed in real-time systems), the discovery of attack vectors based on malware, and the existence of anomalies in industrial protocols and operation activities.

The system performs these activities intelligently. This last feature is key. The system learns from the operation of the operating network (sniffing traffic by activating a port on a switch in “mirroring” mode) and establishes a series of valid patterns. If the system detects any behavior on the network that does not correspond to what has been learned, it immediately launches an alert informing of said anomaly.

What do these systems have to do with BlackEnergy3? And by the way, what is BlackEnergy3?
As we mentioned a few years ago in this post, BlackEnergy was the malware associated with the APT Sandworm, which infected the SCADA Web servers of the Cimplicity from General Electric solution. The ICS –CERT then published the alert ICS-ALERT-14-281-01A. If the systems have not been updated, it is very likely that since 2012, many of them are still infected.

Currently, those systems that are compromised may be affected by the behavior described below.

Normally, organizations have carried out network segmentation projects, incorporating firewalls between the operation/critical networks and the transactional (IT) networks. Additionally, if it is necessary to incorporate SCADA Web to perform remote access, it is normal to create a demilitarized zone with access to the Internet. The following figure shows, in a very schematic way, an architecture in which the IT network has been omitted and the OT/critical network and a network in which SCADA Web servers converge are represented.

graphic

Team B is infected by BlackEnergy. Taking advantage of this situation, the attacker wants to access team A, located in the OT network. To do this, it uses the SMB protocol (usually authorized in firewalls that segment LAN networks to allow file exchange and sharing). RPCs over SMB are exchanged between the two machines. This type of exchange allows BlackEnergy 3, using RPCs, to access the equipment that is in the critical network and from there take control of the process, extract confidential information, etc.

As can be inferred, this type of behavior of the SMB protocol and RPC exchange should not be considered normal. If an organization had deployed a system that would allow detecting these traffic and communication anomalies between devices and/or protocols, it could take appropriate measures to isolate the equipment, reconfigure the firewalls, and update the SCADA Web system if possible.

From Logitek, we prescribe the LK CyberSense solution as a non-invasive network intrusion and anomaly detection system. If you want to know its benefits, please contact us.