Free Subscription Submit Product & News Releases Today's News Headlines News By Company News By Date e-Newsletter Archives
Featured Suppliers Automation Product Manufacturers Systems Integrators and Service Providers Machine and Equipment Manufacturers
Product Search Featured Products Products by Category Products by Manufacturer Request Product Catalogs Submit Products
Add Event Hannover Messe 2012 Industrial Automation North America 2012
Employer Login Search for Jobs Post a Job 30-Day Job Posting Information Annual Job Slot Information Testimonials Recruiting Services Contract Services Salary Survey Results 2011
Techie Lounge Multimedia Library White Papers Training & Seminars Application Tools Complimentary Reference Guides Complimentary Evaluation Software Industry Web Sites Free Subscriptions to Trade Publications
LinkedIn Group Facebook Group Twitter YouTube Channel
Bookstore Online Training Courses Supplier Listings Automation.com Logo Items
 


 

Today's Automation News Headlines from Automation.com

  • Feedback
  • Print Page
MTL Instruments releases Tofino Modbus SCADA security solution
 
Go to company's web site


October 27, 2008 – Byres Security and MTL Instruments are introducing the Tofino Modbus TCP Enforcer Loadable Security Module (LSM), which performs detailed analysis and filtering of all Modbus TCP messages, and is certified by Modbus-IDA. It allows owners of control and SCADA systems to regulate Modbus network traffic to a level of detail that has never before been possible, thereby increasing network security, reliability and performance of critical systems.

“Deep packet” or “content” inspection for web email or traffic has been offered in IT firewalls for several years, but nothing has been available for the process control or SCADA world. Modbus traffic could either be allowed or blocked by a standard firewall, but fine-grained control was impossible. And since the smooth flow of Modbus TCP traffic is critical to the average industrial facility, engineers usually opted to let everything pass and take their chances with security. Industry experts have been urgently calling for better control of SCADA protocols. This spring a major US Government agency warned major energy companies:

“A vulnerability has been identified and verified within the firmware upgrade process used in control systems deployed in Critical Infrastructure and Key Resources (CIKR)… development of a mitigation plan is required to protect the installed customer base and the CIKR of the nation. Firmware Vulnerability Mitigation Steps [includes] blocking network firmware upgrades with appropriate firewall rules.”

Two global energy companies and a major transportation company have trialled the Tofino ModbusTCP Enforcer LSM and have been very excited with how it allows them to follow the government’s guidance and enhance both the security and stability of their systems. They have been able to restrict Modbus functions in numerous ways:
  • Blocking all firmware upgrades, while allowing normal HMI traffic.
  • Tailoring appropriate Modbus access permissions to PLCs for different stations, such as read-only for monitoring panels, read/write for HMIs, and full programming and diagnostics access for PLC engineering workstations
  • Restricting Modbus access permissions to specific memory locations in a controller
  • Providing enhanced security and protection for any Modbus TCP device, including filtering of invalid traffic that could cause denial of service or system failures
  • Enforcing read-only access to Safety Instrumented Systems for enhanced isolation and safety


    “The ability to filter individual MODBUS commands has tremendous potential to improve the security of our control networks” stated Daniel Lacroix, Corporate Information Security Officer for The Saint Lawrence Seaway Management Corporation (SLSMC). The SLSMC operates over 30 locks and bridges on the Canadian side of the Saint Lawrence Seaway, a major marine transportation system that carried over 43 million tonnes of cargo in 2007.

    “The ModbusTCP Enforcer is another key step in our Tofino Zone Level Security strategy”, notes Eric Byres, CTO at Byres Security Inc. “Tofino provides tailored protection for groups of PLCs, DCSs RTUs and HMIs and does it in a way that is simple to implement for control engineers. Security is taken care of, and focus can be maintained on keeping processes running safely and efficiently.”

    Pricing and Availability
    The Tofino Modbus TCP Enforcer LSM is available worldwide as of Oct 14, 2008 from MTL Instruments. The retail price of the product is $500 USD.

    About MTL
    MTL Instruments, a division of Cooper Crouse-Hinds, is a world leader in the development and supply of electronic instrumentation and protection equipment for the process control and telecommunications industries. Many of the world's most critical processes are monitored, controlled or protected by MTL equipment and the Group is distinguished by the quality and reliability of its products, its global network of sales-and-support centres and its acknowledged position as a thought-leader in this high technology marketplace. With 36 dedicated sales centres in 13 countries and a further 137 MTL representatives in 64 countries, MTL's expertise in Intrinsic Safety, Industrial Networks, Surge Protection and Operator Displays/HMI is unsurpassed.
  •  
    Go to company's web site
     
    • Feedback
    • Print Page