Critical infrastructures in the detection of real-time threats


Ediz Öztürk, founder of edZconsult, discusses the importance of security layers in industrial control systems (OT) and the measures required for real-time threat detection.

We need to establish a distinct security layer within industrial systems, particularly for the detection of real-time threats. We often observe a separation here—both in terms of human resources and system interoperability. Specialization is essential because industrial control systems carry their own unique risks, and we require appropriate risk management methodologies to accurately identify them. Naturally, there are various risk methodologies and frameworks available for this purpose. When risks associated with these frameworks are identified, we see that many of them exist at various points across different layers—human, machine, and network. Physical risks, for instance, are often overlooked in this context. We observe this clearly; while factories and similar industrial facilities do implement various measures—such as occupational safety protocols—the adequacy of these measures, the system’s preparedness against external interference, and the implementation of correct policies by the relevant organizations are critical factors. Just as we apply risk management and governance approaches in information security, data is constantly exchanged via various protocols in these systems. It is crucial to analyze this data—leveraging artificial intelligence—to verify whether the data being transmitted is legitimate and expected. However, can every company implement this correctly? I cannot say that they do, as we conduct numerous audits in this sector and observe the reality on the ground. Actually, I prefer to avoid the term “audit”; instead, we call it “assessment.” Based on this assessment, we examine whether various industrial systems are correctly utilizing the appropriate OT protocols. We also specifically require them to employ risk management and real-time threat modeling frameworks. Naturally, this involves both known and unknown threats. As you know, just like with antivirus software, there are specific signatures involved. By comparing these signatures, we attempt to determine the presence or activity of malware, or whether a piece of software has become infected. Similar systems must certainly be in operation here; these are signature-based processes. However, hackers are constantly devising new attack methods. So, how do we address these? We need specialized systems capable of real-time monitoring—using what we call “heuristic scanning” (a form of anomaly detection)—that alert you to potential threats within the traffic, even if no specific signature exists for them. We generally recognize these as IDS and IPS—Intrusion Detection Systems and Intrusion Prevention Systems. However, using prevention systems—specifically those that block traffic—carries risks in industrial environments. Why? Because in an industrial setting, you might be manufacturing thousands or even millions of parts daily, and the process must remain continuous. There is a significant financial value attached to this output, and the production facility cannot afford to stop. If a threat prevention system operates based on suspicion—and if that sensitivity threshold is set too high—it might mistake a non-existent threat for a real one and disrupt the industrial facility, resulting in financial loss. That is precisely why companies are taking a very conservative approach to this. Our argument is that, just as our systems are monitored 24/7—practices that have been in place for years, with ongoing collaborative discussions on effective management since the 1980s—these same systems and approaches absolutely need to be applied to OT as well. I believe it is crucial to develop specific methodologies in this area and, naturally, for the academic community to establish various risk frameworks in this context.

The Importance of Establishing a Security Layer in Industrial Systems

Industrial systems stand as the complex structures forming the backbone of the modern world. These systems undertake critical tasks across numerous sectors, ranging from manufacturing and energy to transportation and communication. However, the security of these systems is of vital importance to both businesses and society. Detecting real-time threats and taking preventive measures against them has become essential for the sustainability of industrial systems. In this context, establishing a distinct security layer within industrial systems plays a critical role in ensuring the harmonious operation of both human resources and the systems themselves. This article explores why establishing a security layer in industrial systems is so important and examines the challenges encountered during this process.

Risk Management in Industrial Systems

Industrial control systems face unique risks. Accurately identifying and managing these risks is crucial for system security. Risk management methodologies play a significant role in this process. Implementing the right methodologies enables the early identification and effective management of potential threats.

Managing Physical and Cyber ​​Risks

Industrial systems are subject to both physical and cyber risks. While physical risks are generally managed through occupational safety measures, cyber risks are more complex in nature. Managing these risks requires protecting systems against both internal and external threats. Cybersecurity protocols and AI-driven analyses emerge as key tools in this process. Real-Time Threat Detection

Real-time threat detection is a vital component of industrial system security. It enables the rapid identification of both known and unknown threats. Signature-based systems and heuristic scanning are the primary methods employed in this process. By identifying potential threats in advance, these systems play a crucial role in ensuring system security.

The Role of IDS and IPS Systems

Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) play a critical role in maintaining security within industrial systems. These systems detect potential threats and take measures against them. However, false alarms generated by these systems can adversely affect production processes; therefore, careful configuration and management are essential.

Security Policies in Industrial Systems

Establishing security policies is of great importance for the sustainability of industrial systems. These policies provide effective protection against both internal and external threats. The formulation of security policies must be supported by continuous monitoring and updating of the systems.

Academic Studies and Methodologies

Establishing a security layer in industrial systems should be supported by academic studies and methodologies. Such studies facilitate the development of new methods and approaches to enhance system security. Contributions from the academic community will play a significant role in ensuring the security of industrial systems.

Summary

Establishing a security layer in industrial systems has become a critical necessity in the modern world. The security of these systems is of great importance for the sustainability of both businesses and society. Risk management, real-time threat detection, and the establishment of security policies stand out as key steps in this process. Technological tools, such as IDS and IPS systems, play a critical role in this regard. Academic studies and methodologies enable the development of new approaches to enhance the security of industrial systems. Therefore, establishing a security layer within industrial systems provides effective protection against both current and future threats.

Share:

About the Wise