Instead of relying on signatures, these solutions use known patterns of attacks (IOCs) that have been seen before in other customer environments.
However, the challenge for the OT organization was that the solution required the OT devices to be continuously connected to the Internet for monitoring and to receive updates from the vendor’s cloud.
Also, updates could be queued and tested on lab devices, but couldn’t be loaded to production devices until the annual maintenance window. And, the solutions didn’t run on the older windows OS, which would leave critical devices unprotected.
The Red Team could use standard techniques to bypass the protections, similar to those techniques used in the SolarWinds and other supply chain attacks.
Artificial Intelligence-Driven Defense
The manufacturer then analyzed and decided to use a comprehensive AI-driven defense system designed to protect all OT endpoints from all cybersecurity threats. This solution, AZT PROTECT from Rockwell Automation Technology Partner ARIA Cybersecurity, can lock down applications and the OS, preventing malware and ransomware from running.
It also continuously monitors how applications execute in memory, to provide continuous protection from any form of attempted adulteration to the running applications. In addition, it provides additional measures that stop the common techniques used by sophisticated attacks, including misuse of OS processes, shellcode, injections and privilege escalations.
The combination was intended to stop sophisticated attacks, such as those coming in via supply chains that commonly have access to OT environments.
Results
The AI-driven defense system met the manufacturer’s requirements with positive results. The solution was able to learn the applications on the device and prevent new unapproved applications from running — out of the box. It blocked all ransomware and malware, including fileless malware attacks launched by the Red Team. It also defended against the Red Team attempts to misuse OS processes, shellcode, injections and privilege escalations as seen in sophisticated supply-chain attacks.
It prevented code adulteration attacks on the applications with unpatched vulnerabilities while running. The solution defended all attacks while being fully air gapped, and it didn’t need updates to stop new attacks.
The cyber defense system supported all legacy operating systems and didn’t negatively impact production application performance.
And, it provided reporting required for SEC and other compliance in addition to exporting syslog formatted alert data into IT’s SIEM for further analysis.
Additional benefits included:
- A complete inventory of all applications and versions running and their status on each device and in each device group.
- Stopping unknown vulnerabilities — such as the Pool Party novel process thread attacks discovered in December of 2023.
- The ability to be loaded on running devices without reboot.
- Ease of use for OT staff to deploy and operate with minimal training.
ARIA Cybersecurity Solutions, based in Lowell, Massachusetts, is a Rockwell Automation Technology Partner that offers complete network and data security solutions. Its ARIA Zero Trust PROTECT (AZT PROTECT™) AI-driven defense system is designed to protect OT endpoints from all cybersecurity threats.
Like this article? Sign up for the digital magazine (4X/year) and e-newsletter from The Journal From Rockwell Automation and Our PartnerNetwork and get articles like this delivered to your inbox.
The Journal From Rockwell Automation and Our PartnerNetwork™ is published by Endeavor Business Media.