Cybersecurity and Neural Networks – Pete Lund, OPSWAT
Pete Lund, vice president of product for OT security at OPSWAT, explains how neural networks will improve cybersecurity by detecting anomalies using algorithms.
Transcript
This is Textron TV. Hey guys. Thanks for the throw.
We're here with Pete Lund who is vice president of product for OT security at SWAT and they are provider of a platform. That is applying. I guess for lack of a better phrase neural networks also known as deep learning algorithms to securing these OT networks, Pete.
Welcome the show. Thanks. Mike.
Glad to be here. Walk us through if you would what you guys are up to because we've been talking about various forms of AI and security with mixed success for years now. Is there something about OT security that lends itself more to this approach and what exactly are you guys doing?
Sure. So look the touch on that so neuralizer, you know our newest, you know OT cyber security offering complementing, you know much of the other comprehensive things. We do in OT really kind of what makes in our lives are different is our approach is not only you know, leveraging machine learning like others out there, but it's very very easy.
So we present, you know, use some of those machine learning strategies to present users the events and anomalies that really matter the ones that really stand out based on our neural approach which you know kind of mirrors the human learning process. So as you interact with the tool give us more tips and tricks on you know, was that something of Interest learns and kind of get smarter right along with you? How do I Implement that is it a service that you're logging into?
You're pulling data from my network. You're dropping an agents. How do you figure out what I'm up to and what's an anomal?
Sure. Yeah, so we deploy in a very safe way for OT because certainly OT can be very sensitive when it comes to. Things like traditional it tools, you know heavy intrusive scanning or agents often are not acceptable.
So we're a very unique Appliance. We're deployed very much like an HMI would be in the environment. So a single kind of all-in-one piece of Hardware form factor that has active and scanning capabilities built into it and we leave it up for the customer to choose whatever is best fit for their environment.
So if it's a very sensitive Network we can do simply just passive monitoring only so looking at you know, spam tap mirror style traffic if you if you're more comfortable a little bit more advanced or have devices that are friendly for you know, an active polling mechanism. We have that built into the appliance as well. It's just as simple as turning it on and giving us, you know connected routed connections to devices where we'll Do things like Poll for Enoch zip or you know Siemens S7 profinet some of those traditional protocols that are safe to pull as long as you're doing it in the the way the industrial OEM designed which of course we are.
What is the current state of the security maturity for OT folks out there? They're kind of a different animal than your average it community. And of course, there's always been issues between security folks and it folks that go on for decades now, but what is the state of the relationship between security and OT folks these days?
here I'd say it's a slow and steady trust building that is kind of getting somewhat forced by, you know, recent events, you know things like Russia other, you know more recent attacks like Colonial pipeline old smart water and we're now seeing Folks at the very least getting to let's at least share data, you know share the right data at the right time. It is never going to fully understand OT and vice versa, but they've at least agreed that we've got to have good visibility good commonality. We need to kind of bond together to ultimately fight and beat that adversary right because they're they're not gonna stop and with them leveraging machine learning and other Technologies, we have to get smarter in our defenses.
You've got, you know, the kind of Market breaks up into a few different ways. You've got the folks who aren't very mature at all. They haven't really started that visibility Journey which is the first kind of Step In, you know, understanding the size of the problem.
How do I how do I eat the elephant as you say one bite at the time and it's really start with visibility that gives you a good picture of what is my network look like who am I normally communicating with? Oh my God, I didn't realize I had, you know vendor remote access enabled there. That's kind of that foundational.
What am I assets look like what are my networks look like and the nice thing about neuralizer, you know, it's a good starting point and certainly there are other Solutions out there, but Big thing with opswat is once you get that visibility, we have a whole Suite of products that brings you up that maturity curve. So once you've kind of established visibility, we've got an industrial firewall product that you can put into, you know, actually secure those last mile devices. We've got a data diode technology where you can actually help segment it from OT and do some safe one way data sharing.
We've got our own secure remote access platform that was designed around OT and then we get all into kind of the file scanning and transient asset protection. So the great thing about neuralizer it is that starting point that most organizations either have done or considering and the great thing about Apple spot as we help you kind of graduate into, you know, fully mature. Full-time stock staff or outsourced stock really kind of covering the gamut of that maturity curve.
We've seen a couple of high-profile attacks recently that of course got some attention to the folks in Washington and other governments. Do you think that we're going to see a lot of regulations coming down the pike that are going to force some of this old security conversation? Yeah, we certainly do see you know happenings in the regulation space I'd say the results so far have been mixed.
One thing about regulation is it's certainly does Drive maturity to happen. Maybe not the most efficient way or the best way but we saw utilities, you know, adopt and accept a number of years ago and you know security and compliance are certainly not the same thing, but they do interact we I would say some of the latest regulations from you know TSA. We're a little bit rushed and they kind of pulled back on those and kind of revise them, but I would say kind of advice to folks is we have really good standards like the new cyber security framework the next security framework, you know is today IEC all of those are kind of core and fundamental to securement if you simply just get proactive and follow them you will start to get yourself out of Harm's Way so as much as the government Can help with kind of revise standards and what to focus on we've we've done a ton of investment in the standards and they are really world-class.
Do you that we'll see malware moving laterally from OT networks to it networks as Things become increasing more integrated and will security people have to figure out some way to kind of bridge those two policies and environments. Yeah, absolutely. So you've seen some of that kind of happen already specifically if you can consider, you know building automation part of the OT space.
So building are oftentimes, you know, HVAC controllers lighting controllers can be not as secure some what forgotten we're seeing. It attackers enter those bases and then pivoting over into corporate it networks or maybe networks that have domain trusted or maybe we're implemented in a flat non-segmented way. So that is certainly something to to watch out for but certainly it is generally the easiest way and just because you have a lot less control and place you have a lot more, you know human factors at risk generally speaking folks aren't opening, you know, those fishing emails while on the OT side of the house.
There's just kind of less General overall attack space in OT, but certainly once they get in any of you got a good you've got a good connected Network between the two that's not segmented with a data diode. For example. Then yeah, you have to worry about that and we're seeing more of OT start to connect to the cloud from an operations standpoints.
So some of those technologies that are used in historians where when you do have to make that it and OT break you're still able to get kind of production information up and out to the cloud and that's going to be another new Threat Vector, especially as we get into things like Renewables and distributed energy. Kind of as 5G also kind of plays into this. We've got more and more connectivity coming into various pieces and parts of our team.
We have to be worried about protecting it. Do you think that the people who are attacking these networks? Are they your average running the mill cybersecurity people.
Are they more like nation-state folks and their level of sophistication is a lot higher than some of the attacks. You might normally see against say your average school system or whatever. Yeah, I would say probably the latter.
So since OT is very high stakes. It's not a typical, you know Kid Next Door or a group that's looking for, you know, a quick rent somewhere style payout. These are folks that want to stay embedded in systems and strike when you know the worst possible time.
So as part of an act of war or as part of, you know, corporate earnings really hitting the company at the right time. So it is that very very Advanced nation state attack or a group style attack. Every now and again there's an attack and everybody stands up and says this time for sure is a wake-up call Everybody's gonna respond and then a lot of people kind of roll over and hit the snooze alarm and just go back to business as usual.
So are we seeing a lot more focus on OT security these days or is it kind of been yet another instance where there's a couple of attacks, but now everybody's kind of just going back to whatever they were routinely doing before. I think we are starting to get slow and steady progress and I would say slow and steady is always been the way OT adopts Technologies. Certainly.
The attacks are becoming more frequent granted. They're not always finding their way into OT. So Colonials a great example where you know, they certainly had a very good stronghold in it OT was generally not impacted but they did have to shut operations down from a precautionary standpoint.
We're also seeing things like cyber insurance come into play and that is kind of forcing folks to mature a bit from from an organizational standpoint. We're seeing a lot more assessments and Audits and people kind of get getting ready to make those bigger cybersecurity Investments. So we're seeing Audits and Pen tests on the rise and certainly lots of interest in all so all forms of kind of cyber security product and OT.
It's a very kind of strong Market to be in and Ops what kind of leads that space when it comes to that and to end visibility to you know, how Actually put protective controls in place, but that's kind of the big thing. We're kind of through the the asset visibility wave and kind of the second wave of OT security as we're seeing the market mature is getting deeper in that inventory understanding vulnerabilities looking at the secure s-bomb makeup of things that's kind of the next place as we understand, you know vulnerabilities and how they impact. But really the whole Market needs to get to putting those protective and controls in place and we're certainly getting there.
We're seeing some of the convergence or as I like to call it. You know, some Industries will never be truly converged but that data sharing aspects and good quality visibility is it's kind of like table Stakes. If you don't you don't understand your assets.
There's really no excuse anymore. There's tons of great products out there and then Services you can leverage to even do it yourself. So what is that one thing you see folks doing from an OT perspective.
That just makes you shake your head and go can't believe we're still doing that. Yeah, lots of lots of good choices there but I think the the thing that gets me the most is kind of the the trust level of of your vendors, right? So when you're you know come in from your favorite, you know, ABB yokogawa Honeywell that the trust level of the vendor is still very high.
They're not put through enough rigor on the inbound sort of whether it's bringing removal media making a network change. There's that inherent trust is good, but it needs to be a trust but verify because oftentimes we're seeing you know, The Outsiders the third parties ultimately be the reason why that industry or our company is compromised, especially when it comes to secure remote access. You can still find many many devices on the public internet, which really shouldn't be and it's often times dialing back to you someone needing that access but it hasn't been set correctly.
It's not managed. It's not logged and really no one has visibility to it. All right as they say sometimes the biggest enemy is us.
So we'll see right better at this as we go along and hopefully some AI will get us down the path a little bit faster. Hey Pete. Thanks for being on the show.
Hey Mike, thanks for having me. All right guys back to you in the studio.