MTL Instruments is launching a security module designed specifically for managing Modbus TCP. Byres Security and MTL Instruments, a division of Cooper Crouse-Hinds, are introducing the Tofino Modbus TCP Enforcer Loadable Security Module (LSM), which performs detailed analysis and filtering of all Modbus TCP messages and is certified by Modbus-IDA. It enables owners of control and SCADA systems to regulate Modbus network traffic to a level of detail that the companies say has never before been possible, thereby increasing network security, reliability and performance of critical systems.
Daniel Lacroix, Corporate Information Security Officer for The Saint Lawrence Seaway Management Corporation (SLSMC), states: "The ability to filter individual Modbus commands has tremendous potential to improve the security of our control networks." The SLSMC operates over 30 locks and bridges on the Canadian side of the Saint Lawrence Seaway, a major marine transportation system that carried over 43million tonnes of cargo in 2007.
'Deep packet' or 'content' inspection for web email or traffic has been offered in IT firewalls for several years but, according to MTL, nothing has been available for the process control or SCADA world. Modbus traffic could either be allowed or blocked by a standard firewall, but fine-grained control was impossible. And since the smooth flow of Modbus TCP traffic is critical to the average industrial facility, engineers usually opted to let everything pass and take their chances with security.
Industry experts have been urgently calling for better control of SCADA protocols. Earlier in 2008, a major American government agency warned major energy companies: "A vulnerability has been identified and verified within the firmware upgrade process used in control systems deployed in Critical Infrastructure and Key Resources (CIKR)... development of a mitigation plan is required to protect the installed customer base and the CIKR of the nation. Firmware Vulnerability Mitigation Steps [includes] blocking network firmware upgrades with appropriate firewall rules."
Two global energy companies and a major transportation company have trialled the Tofino ModbusTCP Enforcer LSM and have been impressed with how it enables them to follow the government's guidance and enhance both the security and stability of their systems. They have been able to restrict Modbus functions in numerous ways, by:
Eric Byres, CTO at Byres Security, notes: "The Modbus TCP Enforcer is another key step in our Tofino Zone Level Security strategy. Tofino provides tailored protection for groups of PLCs, DCSs, RTUs and HMIs and does it in a way that is simple to implement for control engineers. Security is taken care of, and focus can be maintained on keeping processes running safely and efficiently."
The Tofino Modbus TCP Enforcer LSM is now available world wide from MTL Instruments.
The complete Tofino industrial security product consists of three core components: