Cyber security has become an urgent issue in many industries where advanced automation and communications networks play a crucial role in mission critical applications and where high reliability is of paramount importance. The electric utility, transportation, military, and industrial markets have special needs not found in a typical “commercial” or “office” environment.
RuggedCom has been monitoring the developments of the various industry specific security standards including NERC CIP, ISA S99, AGA 12, IEC 62443, ISO 17799:2005 and PCSRF SPP-ICS, to ensure all RuggedCom products contain features necessary to comply with the identified requirements.
RuggedCom is committed to providing a complete Cyber Security solution. By combining the security features the RuggedSwitch™ products with that of the RuggedRouter™ SCADA cyber security appliance, RuggedCom customers are able to establish an electronic security perimeter around their critical infrastructure in order to prevent the disruption of mission critical applications by accidental or malicious acts.
The RuggedRouter™, an industrially hardened, cyber security appliance has been specifically developed to provide an Electronic Security Perimeter for the protection of critical cyber assets. The RuggedRouter™ is the main point of entry between the local area network (plant floor or substation) and the outside world. The RuggedRouter™ combines a layer 3 router, a firewall,
and a VPN in one device.
Key RuggedRouter™ Cyber Security features include:
Firewall – Statefull firewall to control traffic between different zones of trust within a network. Includes Network Address Translation (NAT) to prevent unauthorized or malicious activity, initiated by outside hosts, from reaching the internal LAN.
Virtual Private Networking (VPN) – Provides secure communication links over
networks. Ensures confidentiality, sender authentication, message integrity, and
uses IPSec (IP Security) for encryption and authentication of all IP packets at the
network layer.
Strong Encryption – Utilizes various encryption algorithms (DES, 3DES, AES) to obscure information and make it unreadable without special knowledge
Intrusion Detection System (coming soon) – To detect various types of malicious or abnormal network traffic and computer usage that can not be detected by a conventional firewall. Used specifically to detect various type of network “attacks” (eg. worms, viruses) and unauthorized activities (eg. unauthorized logins, files access).
The RuggedSwitch™ family of substation hardened Ethernet switches provides security at the local area network level. The key cyber security features of these switches include:
Passwords – Multi-level user passwords secures switch against unauthorized configuration
SSH / SSL – Extends capability of password protection to add encryption of passwords and data as they cross the network
Enable / Disable ports – Capability to disable ports so that traffic can not pass
802.1Q VLAN – Provides the ability to logically segregate traffic between predefined ports on switches
MAC based Port security – The ability to secure ports on a switch so only specific Devices / MAC addresses can communicate via that port
802.1x Port Based Network Access Control – The ability to lock down ports on a switch so that only authorized clients can communicate via this port
Radius - Provides centralized password management
SNMPv3 - encrypted authentication and access security
Typical Cyber Security Network Architecture
Click on /images to view larger diagrams
RuggedCom Gauntlet
For utilities that access their substation devices via IP, RuggedCom is introducing RuggedCom Gauntlet. RuggedCom Gauntlet is a 100% NERC-CIP compliant solution that provides an electronic security perimeter for effective cyber attack protection. All communication to substation devices are authenticated, controlled, and logged to prevent and detect unauthorized entry attempts. Also included are extensive reporting tools and the unique “Auto-Audit” feature that provides an easy “one-click” function that compiles all NERC-CIP required documents
into a single report.
RuggedCom is ready to assist our customers in designing a secure network environment. If you would like to learn more about RuggedCom’s cyber security offerings and how we can help, email us at RuggedInfo.
The RuggedRated symbol identifies communications products that have been specifically designed and tested to withstand the demands of harsh industrial environments.
High EMI Immunity (IEC61850-3, IEEE 1613 Class 2 )
-40C to +85C
IntegratedPower Supply (optional dual redundancy)
Zero Packet Loss
<5ms Network Fault Recovery
Rugged Construction
RuggedCom Inc.
30 Whitmore Road, Woodbridge, Ontario, Canada, L4L 7Z4
Tel: +1 (905) 856-5288 I Fax: +1 (905) 856-1995 I Toll Free: +1 (888) 264-0006