TY - GEN
T1 - Host protection strategies for industrial control systems
AU - McIntyre, Anne
AU - Lindqvist, Ulf
AU - Peterson, Brian
AU - Tudor, Zachary
PY - 2012
Y1 - 2012
N2 - Protection of ICS process control data, networks, applications, and host operating systems, particularly in multi-vendor environments, is a critical, on-going requirement for the oil and gas sector. A loss of control over a critical control process potentially could result in loss of life, personnel injury, environmental impact, facility damage, production loss, and economic cost. System maintenance and protection increasingly centers on patching vulnerable automation software and operating systems, many of which have reached end-of-life, are unsupported by the vendor, or lack economic basis for replacement. A new alternative to the classic patching approach to maintaining system security, application whitelisting (AWL) technology, was evaluated against a set of established criteria that support continuity of operations in critical system environments by providing strong cybersecurity. This report presents findings of the LOGIIC program regarding application whitelisting, key attributes to its use in an ICS environment, and general conclusions about its implementation.
AB - Protection of ICS process control data, networks, applications, and host operating systems, particularly in multi-vendor environments, is a critical, on-going requirement for the oil and gas sector. A loss of control over a critical control process potentially could result in loss of life, personnel injury, environmental impact, facility damage, production loss, and economic cost. System maintenance and protection increasingly centers on patching vulnerable automation software and operating systems, many of which have reached end-of-life, are unsupported by the vendor, or lack economic basis for replacement. A new alternative to the classic patching approach to maintaining system security, application whitelisting (AWL) technology, was evaluated against a set of established criteria that support continuity of operations in critical system environments by providing strong cybersecurity. This report presents findings of the LOGIIC program regarding application whitelisting, key attributes to its use in an ICS environment, and general conclusions about its implementation.
KW - Industrial control system security
KW - antivirus
KW - application whitelisting
KW - cyber security
KW - host protection
UR - https://www.scopus.com/pages/publications/84874576238
U2 - 10.1109/THS.2012.6459830
DO - 10.1109/THS.2012.6459830
M3 - Conference contribution
AN - SCOPUS:84874576238
SN - 9781467327084
T3 - 2012 IEEE International Conference on Technologies for Homeland Security, HST 2012
SP - 87
EP - 92
BT - 2012 IEEE International Conference on Technologies for Homeland Security, HST 2012
T2 - 2012 12th IEEE International Conference on Technologies for Homeland Security, HST 2012
Y2 - 13 November 2012 through 15 November 2012
ER -