Skip to main content
Guidance

Operational Technology

Making sense of cyber security in OT environments.

Pages

Page 37 of 37

Principle 9. Adopt defence in depth

This is a key security concept; a system will be more secure if it contains many independent layers of security mechanisms. For example, encryption alone will not secure a system from all threats.

Use of TCP/IP encapsulated ICS protocols OTA will increase the difficulty of replay attacks, and has the potential to enhance security through the use of network segregation, coupled with appropriate filtering/firewalling on the network. Traffic should be limited to only allow specific data structures and protocols to reduce the ability for lateral movement within the network by a malicious actor.

Defence in depth can also be extended to the radio interface itself. Increasing the complexity of the RF modulation scheme used for communications, and maximising channel occupancy can also aid in prevention of replay attacks by creating a more challenging RF environment for an attacker to perform signal identification and capture. If permissible within the spectrum, anti-jamming techniques (such as frequency hopping) can provide resilience against both replay and jamming attacks. If the ability to change the operating frequency of RF devices is present, we recommend that operators have frequency switch plans in place in the event of interference, or in case of a suspected attack on the network.

Additional methods of securing the RF network can include physical security, such as locked enclosures, and reducing signal availability by limiting the power levels of transmitters (particularly in mesh networks) and, in broadcast networks, containing signals through proper network planning (for example using directional antenna where appropriate).

Published

Reviewed

Version

1.0