Enhanced intelligent process control switch port locking
By generating a static address table and authenticating physical addresses, the process control switch locks all ports, solving the problem that traditional switches cannot effectively lock them, thus achieving protection against malicious devices and improving network security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- FISHER ROSEMOUNT SYST INC
- Filing Date
- 2018-09-29
- Publication Date
- 2026-05-08
AI Technical Summary
Existing process control switches cannot effectively lock ports with more than two connected devices and/or ports connected to a second switch, making the network vulnerable to attacks. Traditional locking mechanisms cannot prevent malicious devices from accessing the network.
The process control switch locks and maps ports by generating a static address table, locking all ports, authenticating the physical and network addresses of each device, limiting traffic thresholds, detecting and handshaking with a second switch to determine its lockability.
It effectively prevents malicious devices from accessing the network, protects the network from attacks, ensures that only known devices can communicate, and improves network security and management efficiency.
Smart Images

Figure CN116015757B_ABST
Abstract
Description
[0001] This application is a divisional application of the invention patent application filed on September 29, 2018, with application number 201811148322.5, entitled "Enhanced Intelligent Process Control Switch Port Locking". Technical Field
[0002] This disclosure generally relates to process control systems, and more specifically, to techniques for locking ports of intelligent process control switches. Background Technology
[0003] Process control systems, such as those used in power generation, chemical, petroleum, or other processes (e.g., distributed or scalable process control systems), typically include one or more process controllers that are communicatively coupled to each other, coupled to at least one host or operator workstation via a process control network, and coupled to one or more field devices via analog, digital, or combined analog / digital buses.
[0004] Field devices can be, for example, valves, valve positioners, switches, and transmitters (e.g., temperature, pressure, and flow rate sensors) that perform functions within a process or plant, such as opening or closing valves, switching devices, and measuring process parameters.
[0005] Typically located within a process plant environment, process controllers receive signals indicating process measurements or process variables generated or associated with field devices and / or other information related to the field devices, and execute controller applications or routines. Each controller uses the received information to implement control routines and generate control signals sent via a bus to the field devices to control the operation of the process or plant. One or more controller routines implement control modules that make process control decisions, generate control signals based on the received information, and cooperate with control modules or blocks in field devices (such as HART® and fieldbus field devices). Control modules in the process controller send control signals to field devices via communication lines or signal paths to control the operation of the process.
[0006] Information from field devices and process controllers is typically made available via a process control network to one or more other hardware devices, such as operator workstations, maintenance workstations, personal computers, handheld devices, data history logs, report generators, centralized databases, etc. Information transmitted over the network enables operators or maintenance personnel to perform desired functions related to the process. For example, this information allows operators to change settings for process control routines, modify the operation of control modules within process controllers or intelligent field devices, view the current status of a specific device's process or condition within the process plant, view alarms generated by field devices and process controllers, simulate process operation for personnel training or testing of process control software, diagnose problems or hardware failures within the process plant, and so on.
[0007] Field devices typically communicate with hardware devices via a process control network, which can be a LAN configured with Ethernet. The network relays process parameters, network information, and other process control data to various entities within the process control system through various network devices. Network devices typically facilitate data flow through the network by controlling their routing, frame rates, timeouts, and other network parameters, but do not alter the process data itself. Some typical network devices include, for example, Layer 2 network switches, Layer 3 network switches, routers, and / or hubs. The layers mentioned here are related to the OSI model layers.
[0008] Generally, a Layer 2 network switch receives messages and forwards them via a port associated with the MAC address (identified by the message) of the destination device within the LAN. Layer 2 network switches typically maintain a table that establishes the relationship between MAC addresses and their corresponding switch ports. When a Layer 2 network switch receives a message, it identifies the message's destination MAC address, determines the corresponding switch port from the table, and forwards the message via that port. If the destination MAC address of a message received by the Layer 2 network switch is not stored in the table, it broadcasts the message to all ports of the switch. This can be repeated until the message reaches the destination device and the destination device replies, thus informing the switch of the appropriate port "mapped" to the destination MAC address. It's important to note that Layer 2 switches do not perform routing, do not make forwarding decisions using IP addresses, and do not track intermediate nodes between the switch and the destination device. Instead, the Layer 2 switch simply refers to the table to determine which switch port should be used to forward the message.
[0009] On the other hand, Layer 3 devices (such as routers and Layer 3 switches) frequently perform routing, identify intermediate nodes, and use IP addresses for forwarding and / or routing. This routing capability and the ability to utilize network addresses enable Layer 3 devices to route data to destinations outside the LAN to which the Layer 3 device is connected. While routers and Layer 3 network switches can sometimes route process control data within process control networks, they are significantly more expensive than Layer 2 switches, especially when designed or configured for operation in a process control environment (e.g., two to three times more expensive).
[0010] As process control networks increase in size and complexity, the number and types of network devices also increase accordingly. Due to the growth of systems and networks, security and management within these complex systems become increasingly challenging. For example, each network device may include one or more communication ports, providing access points or ports for physically interconnecting process control system components and other network devices across the network. These network device ports can become access points for network expansion by adding other devices, or they can allow malicious or non-malicious entities to access the network and initiate unwanted and potentially harmful network traffic.
[0011] To address security concerns regarding malicious entities, some control switches have a disabling mechanism for disabling ports (e.g., unused ports) to prevent devices from communicating via disabled ports. Additionally, some control switches sometimes have locking mechanisms (e.g., as disclosed in U.S. Patent No. 8,590,033) that can “lock” a port to restrict communication via the locked port to a single device connected to that port during the lockout period. However, these conventional locking mechanisms are limited. In particular, conventional locking mechanisms cannot lock (i) ports with more than two connected devices and / or (ii) ports connected to a second switch (sometimes referred to as “uplink ports”). Uplink ports are typically excluded from network security lockouts (i.e., left unlocked) to maintain uplink port functionality during lockouts and to avoid unintentionally implementing overly restrictive lockouts that interfere with factory operations. Furthermore, some switches classify ports connected to daisy-chained devices as “uplink ports” in response to identifying multiple devices connected to a port and assuming the port is connected to the switch. Therefore, while some control switches can implement traditional locking mechanisms to prevent malicious devices from connecting to the network via previously unused ports (e.g., by disabling the port) or ports that are only connected to a single end device (e.g., by locking the port), these switches remain vulnerable on any port connected to an uplink switch, more than two end devices, or a single device with multiple physical addresses (e.g., a virtual system). Summary of the Invention
[0012] The described methods and systems enable process control switches to lock all of their ports and / or identify “known pairs” of physical and network addresses of each device communicating via each port of the process control switch.
[0013] In one embodiment, a process control switch includes a plurality of ports and a set of circuits communicatively connected to the plurality of ports. The set of circuits can be configured to lock the plurality of ports, wherein the set of circuits: (A) generates a static address table (i) that maps known physical addresses of devices in the process control environment to one or more of the plurality of ports to which the devices are connected, and (ii) does not update the plurality of ports with new known physical addresses when the plurality of ports are locked, wherein the static address table maps multiple known physical addresses to a single port connected to an unlockable or unmanaged switch or daisy-chained device; and / or (B) limits traffic to each of the plurality of ports, wherein the set of circuits: (i) controls the number of messages forwarded at each port to meet a traffic threshold, and (ii) authenticates the source physical address of each message received at each port. To authenticate the source physical address, the circuit set may: (a) analyze the message to identify the source physical address included in the message; (b) forward the message via one of the plurality of ports when the static address table lists the source physical address as a known physical address mapped to the single port; and (c) discard the message when the static address table does not list the source physical address as a known physical address mapped to the single port.
[0014] In one embodiment, a process control switch includes a plurality of ports and a circuit set communicatively connected to the plurality of ports. The circuit set can be configured to implement a locking operation, wherein the circuit set: (a) detects that one of the plurality of ports is connected to a second switch; (b) analyzes a handshake with the second switch to determine whether the second switch is lockable; (c) when the circuit set determines that the second switch is lockable, forwards a message received from the second switch without authenticating the source physical address of the message; and / or (d) when the circuit set determines that the second switch is not lockable, authenticates the source physical address included in a message received at the port, in order to analyze the message received at the port to determine whether the received message identifies a source physical address included in a known list of physical addresses.
[0015] Note that the present invention has been provided to introduce a series of concepts further described below in the detailed description. As explained in the embodiments, some embodiments may include features and advantages not described in the present invention, and some embodiments may omit one or more features and / or advantages described in the present invention. Attached Figure Description
[0016] According to embodiments, each of the figures described below illustrates one or more aspects of the disclosed system and / or method. Detailed description references are included in the reference numerals in the following figures.
[0017] Figure 1A This is a schematic diagram of a process control system within a process plant, in which intelligent process control switches can be implemented to enhance network security and facilitate network management and maintenance.
[0018] Figure 1B This is a second schematic diagram of a process control system within a process plant, which can achieve... Figure 1A The intelligent process control switch shown is designed to enhance network security and facilitate network management and maintenance.
[0019] Figure 1C This illustrates the basic data units or frames that can typically be transmitted through a process control system using the Ethernet protocol.
[0020] Figure 2A This is a network diagram of an exemplary process control network, in which a set of intelligent process control switches is implemented (each intelligent process control switch is similar to...) Figure 1A and 1B (Those shown) are used to improve locking performance and enhance network security.
[0021] Figure 2B This is a network diagram of a second exemplary process control network, in which an intelligent process control switch set is implemented to improve locking performance and enhance network security.
[0022] Figure 2C yes Figure 1A , 1B The block diagram of the intelligent process control switch shown in Figure 2A.
[0023] Figure 3A Demonstrates methods for locking and unlocking. Figure 1A-2C An exemplary method for using one or more ports of a smart process control switch as shown.
[0024] Figure 3B A method for locking after receiving a lock command is shown. Figure 1A-2C An exemplary method for the port of the intelligent process control switch shown.
[0025] Figure 3C Showing the method for unlocking Figure 1A , 1B Exemplary methods of the intelligent process control switch shown in 2A and 2B.
[0026] Figure 4A It shows that it can be provided to facilitate locking and unlocking. Figure 1A-2CAn exemplary user interface for the intelligent process control switch shown.
[0027] Figure 4B The image shows a set of unlocked switches. Figure 4A The exemplary user interface shown is shown below.
[0028] Figure 4C The diagram shows a set of lockable switches. Figure 4A and 4B The exemplary user interface shown is shown below.
[0029] Figure 4D The image shows a set of switches filled with switches in a "locked pending" state. Figure 4A , 4B And the exemplary user interface shown in 4C.
[0030] Figure 5 It shows Figure 2C An example of an address matching table is shown.
[0031] Figure 6 Implementation shown Figure 2C and 5 The diagram shows an exemplary method for improving the security of process control systems within a process plant using an address matching table.
[0032] Figure 7 The detection and Figure 1A-2C A block diagram illustrating an exemplary method for addressing security issues associated with the intelligent process control switch shown. Detailed Implementation
[0033] This disclosure describes process control switch 146 (in... Figure 1A , 1B As shown in 2C and sometimes referred to as “switch 146”, it is capable of (i) implementing locking operations or routines to lock its communication ports dedicated to devices with known physical addresses, and / or (ii) implementing address mapping operations or routines to identify “known pairs” of physical and network addresses of each device communicating via switch 146.
[0034] Generally, switches can be divided into two categories: configurable switches and non-configurable switches. Configurable switches (sometimes called "managed switches") can have various network settings that can be configured by the user (e.g., port speed, virtual LAN, redundancy, port mirroring, and Quality of Service (QoS) for traffic prioritization), making the switch suitable for a specific implementation. Non-configurable switches (sometimes called "unmanaged switches") are typically configured by the manufacturer according to OEM specifications, and their network settings cannot be easily modified by the end user. While configurable switches are often found in environments that require input and control of traffic (e.g., industrial environments), non-configurable switches are typically designed for environments requiring less complex operation (e.g., homes or small offices).
[0035] Generally, as used herein, the phrase "managed switch" is not synonymous with the phrase "configurable switch" as described above, and the phrase "unmanaged switch" is not synonymous with the phrase "non-configurable switch" as described above. Rather, the terms "managed" and "unmanaged" refer to the lockability of the switch. That is, as used herein, "managed switch" refers to a switch with the locking functionality described herein, and "unmanaged switch" refers to a switch lacking the locking functionality described herein. Because switch 146 is configured to implement the described locking operation, switch 146 can be referred to as a "managed switch".
[0036] The locking operation enables switch 146 to lock its port, making any device connected to that port a "known" device authorized to continue using the port during the locking period, while preventing any "new" device from communicating through that port. That is, after locking switch 146, switch 146 "discards" communication received from any "new" device connected to switch 146, thereby protecting its port from malicious newly connected devices. Generally, the term "connection," when used with the reference device and the port of switch 146, refers to the physical connection between the port and the physical medium (e.g., an Ethernet cable such as a CAT5 or CAT6 cable) that enables communication between switch 146 and the device. The physical medium can be connected to the device directly or indirectly via one or more intermediate devices that facilitate communication with the device.
[0037] When a locking operation is implemented, switch 146 can generate a record (e.g., a static address table) of physical addresses (e.g., MAC addresses) for all known devices connected (directly or indirectly) to each port of switch 146. Unlike conventional control switches, switch 146 can generate records of more than two physical devices connected to a single port. For example, when three, four, five, or more devices are daisy-chained to a single port, switch 146 can generate a record of the physical address for each of the multiple devices daisy-chained to the single port. Therefore, switch 146 can "lock" each port, and communication is only enabled via switch 146 for those devices with known physical addresses (e.g., the source physical address that matches the physical address in the record at the time of locking). In this case, when a malicious device physically connects to a port of switch 146 after locking, switch 146 will not forward messages from the malicious device (assuming its physical address does not match the physical address of the device connected to that port at the time of locking). Therefore, switch 146 can prevent malicious devices from joining the control network, thereby preventing malicious devices from collecting sensitive information from the control network or exercising unauthorized control over devices connected to the control network.
[0038] In response to receiving a lockout command transmitted based on a security threat detected by a device on the network to which switch 146 is connected, the lockout operation can be implemented by switch 146. For example, the lockout command can be transmitted by a device (e.g., a computer such as a server, workstation, or controller) in a control system (e.g., a Delta V control system) implemented in a factory associated with switch 146. As another example, the lockout command can be transmitted by a security system that monitors network activity (e.g., specially designed hardware such as an ASIC or a collection of computers executing security software). Security systems can include one or more systems for monitoring network activity, such as: access control systems, anti-keylogging systems, anti-malware systems, anti-spyware systems, anti-subversion systems, antivirus systems, encryption systems, firewall systems, intrusion detection systems (IDS), intrusion prevention systems (IPS), security information management systems, or security information and event management (SIEM) systems. One or more of these security systems can work together to generate the lockout command. For example, a firewall system can detect a security threat and notify the SIEM (which can be configured to aggregate security threats from multiple sources), and the SIEM can respond by transmitting a lockout command. Exemplary security threats can be detected in any of a variety of ways. For example, a security system can utilize signature-based detection (e.g., identifying known network signatures of known threats such as malware) and / or anomaly-based detection (e.g., detecting biases, such as opening new logical ports on nodes that are expected to only open and utilize certain logical ports (such as logical ports associated with specific protocols associated with the node).
[0039] Lockout routines can be used in conjunction with flow control routines that limit traffic at each port to a predetermined threshold. Each threshold for each port can be determined based on the type of device connected to the port. For example, if a controller is connected to a port, the controller's traffic utilization is not expected to exceed a certain amount of ingress / egress traffic per port (e.g., 512kbps ingress, or 1500 packets per second egress, etc.), and the traffic threshold for that port can be set accordingly. Field devices may consume more or less traffic, so ports connected to field devices can have different traffic thresholds. In some cases, flow control is an important feature of process control switches. For example, a process control switch without flow control can allow any amount of traffic to be exchanged between any type of device, and therefore cannot prevent basic denial-of-service attacks that are easily detected if specific communication requirements of a given process control system are observed—process control systems tend to be very predictable, so setting thresholds based on the protocols and device types used in these specific use cases is not difficult.
[0040] Further referring to the locking operation, switch 146 can determine when a port is connected to the second switch (e.g., using a Bridging Protocol Bridge Unit (BPDU) frame) and can perform a handshake with the second switch to determine whether the second switch is switch 146 or an "unmanaged switch" (e.g., a switch without the publicly disclosed locking capability). If the second switch is an unlockable or "unmanaged" switch, switch 146 can identify and record the physical address of each end device connected to a port of switch 146 via the unlockable or "unmanaged" switch.
[0041] If necessary, switch 146 can leave certain unlocked ports during a lockout period. For example, switch 146 can determine when a port is connected to a second switch (such a port may be referred to as an "uplink port") and can perform a handshake with the second switch to determine whether the second switch is "managed" (i.e., "lockable" like switch 146) or "unmanaged" (i.e., not "lockable" like switch 146). If the second switch is "managed," switch 146 can keep the uplink port unlocked (and therefore can not check the source physical address of messages received via the uplink port, and / or can check the source physical address of messages but not discard messages with unknown source physical addresses). Such an uplink port may be referred to as a "managed uplink port." If the second switch is "unmanaged," switch 146 can identify and record the physical address of each end device connected to the uplink port via the "unmanaged switch," and the uplink port may be referred to as an "unmanaged uplink port." Switch 146 can subsequently lock the uplink port, causing it to discard messages originating from unknown devices connected to the unmanaged switch, thereby preventing unknown devices (e.g., potentially malicious devices) from accessing the wider network connected to switch 146. It should be noted that the locked port of switch 146 can continue to transmit broadcast and multicast messages from known devices, and in this case, unknown or unauthorized devices (i.e., devices without a known physical address for a given port) can listen to these transmitted broadcast and multicast messages. However, in this situation, unauthorized devices will not be able to respond to those messages or otherwise transmit any messages through the locked port of switch 146.
[0042] The address mapping operation enables switch 146 to verify that a device with a known physical address is a known device after locking, by confirming that the device is not simply spoofing a known physical address. Switch 146 performs this verification by tracking the network address (e.g., IP address) of each known physical address. Therefore, each known device for a given port should have a known address pair (i.e., physical and network address) tracked by switch 146. Thus, even if a malicious device connects to a locked port of switch 146 and successfully spoofs the physical address of a known device targeting that locked port, switch 146 will detect that the malicious device's network address does not match the network address recorded on the physical address pair. Therefore, switch 146 generates an alarm and / or discards communication received from the malicious device.
[0043] If needed, switch 146 can implement port mirroring. For example, switch 146 can copy packets entering or leaving a specific port and can send the copied packets to an analyzer (e.g., via an assigned port associated with the analyzer). The analyzer can be any machine configured (e.g., via software) to analyze the copied packets. Port mirroring enables diagnostics and / or debugging of the copied packets without significantly affecting the devices sending and / or receiving the original packets.
[0044] Figure 1A and 1B This is a schematic diagram of a process control system 100 within a process plant, where a switch 146 may be implemented to enhance network security and facilitate network management and maintenance. The process control system 100 includes a process control network 150, which is a collection of nodes (e.g., devices or systems capable of sending, receiving, and / or forwarding information) and communication links connected to enable communication between the nodes. Nodes in network 150 include one or more switches 146; one or more process controllers 110; one or more host workstations or computers 120-122 (e.g., authorized workstations and / or servers), at least one of which includes a display screen; one or more input / output (I / O) cards 140; one or more field devices 130, 133, and / or 142; a gateway 143; and / or a data history repository 145. Some embodiments do not include field devices 142 and gateway 143.
[0045] Network 150 is a Local Area Network (LAN). In some cases, a Wide Area Network (WAN) and / or telecommunications network may be part of the factory network, but in other cases it may not be part of Network 150. Network 150 can be configured for Ethernet communication and / or for any suitable communication protocol (e.g., TCP / IP, proprietary protocols, etc.), and can be implemented using hardwired (preferred) or wireless technologies. Additional aspects of Network 150 are described in more detail at the end of the detailed implementation.
[0046] One or more process controllers 110 (each of which may be, for example, DeltaV sold by Fisher Rosemount Systems, Inc.) TM The controllers 110 are communicatively connected to network 150 and one or more host workstations or computers 120-122 via one or more switches 146. Each controller 110 may include one or more network interface cards (sometimes referred to as "communication interfaces") and may be connected to field devices 130 via I / O cards 140, each I / O card 140 being communicatively connected to one of the controllers 110 via a backplane. The field devices 130 may be communicatively coupled to network 150 (e.g., using DeltaV electronic grouping technology). Network 150 may also be used to connect Ethernet-based I / O nodes, such as DeltaV CHARMI / O cards (CIOC), wireless I / O cards (WIOC), Ethernet I / O cards (EIOC), etc., which connect to field devices using open protocols and transmit data back to one or more process controllers 110. In this case, the communication between the controllers 110 and the I / O nodes may be explicitly proprietary.
[0047] I / O network 155, which may be a subnet of network 150, facilitates communication between controller 110 (e.g., via I / O card 140) and field devices 130, 133, and 142. I / O network 155 may include... Figure 1A Intermediate nodes not shown, such as additional switch 146 (see [reference]). Figure 1B I / O network 155 can be configured for Ethernet communication and / or for any suitable communication protocol (e.g., TCP / IP, Modbus IP, etc.) and can be implemented using hardwired or wireless technologies depending on the implementation. Some embodiments do not include I / O network 155, or include modified versions of I / O network 155 (e.g., some embodiments do not include a switch between controller 110 and field devices).
[0048] I / O card 140 is communicatively connected to field device 130 using any desired hardware and software associated with, for example, a standard 4-20mA device, a standard Ethernet protocol, and / or any intelligent communication protocol such as the Foundation Fieldbus Protocol (Fieldbus), HART protocol, or any other desired communication or controller protocol.
[0049] Field device 130 can be any type of device, such as sensors, valves, transmitters, positioners, etc. Figure 1A In the illustrated embodiment, field device 130 is a HART device that communicates with a HART modem via a standard analog 4-20mA line 131, while field device 133 is a smart device, such as a fieldbus field device, that communicates with an I / O card 140 using a fieldbus protocol via a digital bus 135 or an I / O network 155. Of course, field devices 130 and 133 can conform to any other desired standard or protocol, including any standards or protocols developed in the future.
[0050] Field device 142 can be connected to digital bus 135 via a dedicated network device such as gateway 143. For example, field device 142 may only understand PROFIBUS-PA commands, and I / O network 155 may implement the PROFIBUS-DP protocol. For this purpose, gateway 143 can provide bidirectional PROFIBUS-DP / PA conversion. Switch 146 may also be located at or near gateway 143.
[0051] Controller 110 may be one of many distributed controllers within a plant, each having one or more processors, implementing or monitoring one or more process control routines. Routines may include one or more control loops stored in or associated with the controller. Controller 110 also communicates with devices 130 or 133, host computers 120-122, and a data history repository 145 via network 150 and associated network devices to control the process in any desired manner. It should be noted that any control routine or element described herein may have portions implemented or executed by different controllers or other devices, if desired. Similarly, the control routines or elements described herein that will be implemented within process control system 100 may take any form, including software, firmware, hardware, etc. For the purposes of this discussion, a process control element may be any component or part of the process control system, including, for example, routines, blocks, or modules stored on any computer-readable medium. Control routines, which can be modules or any parts of the control process (such as subroutines, portions of subroutines such as lines of code), can be implemented in any desired software format, such as using ladder logic, sequential function charts, function block diagrams, object-oriented programming, or any other software programming language or design paradigm. Similarly, control routines can be hard-coded into, for example, one or more EPROMs, EEPROMs, application-specific integrated circuits (ASICs), or any other hardware or firmware element. Furthermore, any design tool can be used to design control routines, including graphical design tools or any other type of software / hardware / firmware programming or design tool. Therefore, controller 110 can be configured to implement control strategies or control routines in any desired manner.
[0052] Data history repository 145 may be any desired type of data collection unit having any desired type of storage and any desired or known software, hardware, or firmware for storing data, and may be separate from or part of one of workstations 120-122. Data history repository 145 may be communicatively coupled to network 150 and / or workstations 120 and 122 via switch 146.
[0053] Figure 1CAn example of a basic data unit or frame 175 is illustrated, which can typically communicate via process control system 100 and via process control network 150 using the Ethernet protocol. Ethernet frame 175 includes seven fields, each transmitting information between devices such as switch 146 or other components of process control system 100. These fields can include multiple bytes of data 178 interpreted and processed by the receiving device. For example, the destination MAC address field 180 can include the physical address of an intermediate or destination node of process control network 100, while the source MAC address field 182 can include the physical address of the sending or intermediate node of process control system 100. The destination MAC address 180 and source MAC address 182 fields can be used in conjunction with data from switch 146 to process data transmitted via process control network 150. In some embodiments, when a device is in a “locked” state, fields 180, 182 can be compared with one or more tables stored within the receiving network device. The result of the comparison can be used to reject or otherwise deny received data or other physical or logical connections to the locked network device.
[0054] Figure 2A This is a network diagram of an exemplary process control network 200A, in which switch sets 146A-D are implemented (each switch represents...) Figure 2C (Example of switch 146 shown) to improve locking performance and enhance network security. Solid lines represent communication links connected to locked ports, and dashed lines represent communication links connected to unlocked ports. Advantageously, each port of switches 146A-D can be locked. Therefore, even if a malicious device connects to a process control device, hub, or unmanaged switch connected to a port of one of the switches 146A-D, the malicious device cannot communicate through that port when the corresponding switch 146A-D is locked.
[0055] In addition to switches 146A-D, network 200A also includes devices 111A-111L (collectively referred to as “Device 111”), devices 113A-113D (collectively referred to as “Device 113”), and hub 112. Device 111 is a process control device specifically configured to operate in a process control plant and communicate via a process control network. Each device 111 has one or two physical addresses (e.g., for redundancy). Typically, the physical address of device 111 is a specially configured MAC address that allows device 111 to be recognized by other process control devices on process control network 100D. For example, the physical address of each device 111 may begin or end with a specific, recognizable character pattern (e.g., F9-C3-XX-XX-XX-XX) that allows each device to be identified as a device specifically configured for implementation in a process control environment. Exemplary device 111 includes process controllers, I / O cards, workstations, data history repositories, and specially configured network devices.
[0056] Device 113 includes (i) devices not specifically configured for process control networks (sometimes referred to as “off-the-shelf devices” or “general-purpose devices”) and / or (ii) devices with more than two physical addresses (which may include both specially configured process control devices and “general-purpose” devices). Hub 112 is a general-purpose network hub.
[0057] Regardless of the type or number of devices connected to the ports, the 146A-D switch can lock all ports, thus preventing attacks from malicious devices (directly or indirectly) connected to any port of any 146A-D switch. Figure 2A Several examples of how the 146A-D improves upon current process control switches are illustrated. Below, four specific examples demonstrate the advantages of the 146A-D: (i) locking ports connected to “general-purpose devices” or devices with more than two physical addresses (process control or “general-purpose”); (ii) locking ports connected to unmanaged switches; (iii) locking ports connected to daisy-chained sets of devices; and (iv) locking ports connected to unmanaged network devices (e.g., hubs) that are connected to multiple devices.
[0058] The first example involves a switch 146A, which includes port 201, which can be locked when connected to device 113A, which can be (i) a "general-purpose device" with any number of physical addresses or (ii) a process control device with more than two physical addresses. In operation, switch 146A implements a locking routine to lock port 201. After locking, switch 146A does not allow any device with a physical address different from that of device 113A to communicate via port 201. In other words, switch 146A will analyze any messages received at port 201 to identify the source physical address included in the message. If the message does not contain a source physical address that matches the physical address of device 113A known to switch 146A at the time of locking, switch 146A "discards" the message instead of forwarding it via one of its other ports, and switch 146A generates a port violation alarm. In contrast, a typical process control switch may not lock the port connected to device 113A because device 113A is a "general purpose" device or a device with more than two physical addresses, and process control switches typically do not lock such ports, even if a locking process is initiated.
[0059] Switch 146A also includes port 211 connected to switch 146B. Port 211 is locked, as indicated by the solid line connected to it. Therefore, switch 146A can store the physical addresses of all devices communicating via port 211 during the lockout, including any physical addresses of devices connected to any of switches 146B-D. In some cases, each of switches 146B-D can receive notification that it is connected to an upstream switch 146 (e.g., switch 146A), and therefore, based on the assumption that the upstream switch 146 will authenticate the physical addresses listed in the authentication message to ensure that the listed physical addresses are known addresses, physical address authentication may not be required during the lockout. In other cases, one or more of switches 146B-D authenticate physical addresses together with switch 146A during the lockout.
[0060] The second example relates to switch 146B, which includes port 203, which can be locked when connected to an unmanaged switch (i.e., a switch lacking the described locking capability or unable to transmit BPDU frames). Port 203 and any other ports connected to the second switch (e.g., ports 211 and 213, 215, and 217 of switch 146A) can be referred to as "uplink ports." Note that in some cases, switch 146 can be configured to recognize only managed uplink ports when identifying uplink ports, so switch port 203 may not be classified as an uplink port by switch 146B (e.g., switch 146 can be configured to classify only those ports connected to other switches 146 as uplink ports). Device 111G-I is connected to unmanaged switch 109, which is physically connected to port 203. It is worth noting that because unmanaged switch 109 cannot lock its ports (as shown by the dashed line connecting switch 109 to device 111G-I), a malicious device can connect to switch 109 to communicate with other devices connected to switch 109 (e.g., device 111G-111I). In other words, even if someone attempts to lock all lockable switches in network 200A (e.g., switches 146A-146D), a new device with an unknown physical address can connect to switch 109, and switch 109 will forward messages from the malicious device to a port on switch 109 that has been mapped to the destination address contained in the message from the malicious device.
[0061] However, because port 203 is locked by switch 146B (as shown by the solid line connecting switches 146B and 109), any messages received at port 203 from new, unknown devices will be discarded by switch 146B. This message will be discarded because when switch 146B is locked, it creates a record of the known physical addresses of all known devices communicating via port 203, even if these known devices are communicating via an unmanaged uplink switch such as switch 109 (switch 146B can create this record by monitoring and recording the source and destination addresses of messages sent and received via port 203). Therefore, in the example shown, switch 146B "locks" the record of known physical addresses, so that only the physical address of device 111G-I is associated with port 203. Therefore, any device connected (e.g., via a wired or wireless connection) to switch 109 cannot communicate with other devices on network 200A via port 203 of switch 146B (if a new device has a physical address that matches the physical address of a device in device 111G-I, switch 146 can use address mapping table 222 to detect that the new device is not a device in device 111G-I). In short, even if port 203 is connected to an unmanaged switch (i.e., switch 109) that does not lock its port, switch 146B can lock port 203, so that only devices connected to switch 109 can communicate via switch 146B when locked.
[0062] Turn to the third example, Figure 2AA switch 146C including port 205 is shown. Port 205 can be locked when daisy-chained devices 111E and 111F are connected to it. Device 111E is physically connected to port 205, and device 111F is daisy-chained to device 111E, enabling device 111F to communicate with other devices on network 200A via its connection to device 111E and port 205. Generally, the daisy-chain connection is a pass-through connection, giving all daisy-chained devices (i.e., 111E and 111F) direct access to port 205. Notably, device 111E does not lock its access point connected to device 111F, as shown by the dashed line between devices 111E and 111F. Therefore, a malicious device could connect to either device 111E or 111F, either of which could forward messages received from the malicious device. However, if a new device connects to the same daisy chain (which is connected to port 205), or if a device in the daisy chain is replaced by a new device, switch 146C marks port 205 as a port violation and may not allow communication from any device connected to the daisy chain. In some cases, switch 146C may simply discard messages from the new device during the lockout. These messages are discarded because when port 205 is locked, switch 146C creates a record of known physical addresses for all known devices communicating via port 205 (e.g., devices 111E and 111F) and discards messages identifying source physical addresses different from the known physical addresses (e.g., the physical address of a malicious device). Therefore, when a malicious device might connect to device 111E or 111F, any messages from the malicious device will be discarded by switch 146C (i.e., not forwarded via other ports of switch 146C).
[0063] Finally, as a fourth example, Figure 2A A switch 146D is shown, including port 207, which can be locked when connected to a lockable hub 112, which is connected to multiple devices. In short, switch 146D treats hub 112 similarly to how switch 146B treats unmanaged switch 109. Devices 113D, 111K, and 111L are connected to hub 112, which is physically connected to port 207. Because hub 112 cannot lock its port (as shown by the dashed lines connecting hub 112 to devices 113D, 111K, and 111L), a malicious device could connect to hub 112 to communicate with other devices connected to hub 112. However, because port 207 is locked by switch 146D, any messages received at port 207 from new, unknown devices will be discarded by switch 146D.
[0064] It is worth noting that devices 113D, 111K, and 111L can communicate via network 200 because their physical addresses are registered in the memory of switches 146D and / or 146B. In some cases, for ease of use and convenience, the uplink ports of switches 146A-D (e.g., ports 213 and 215) are not locked, but all physical addresses mapped to the uplink ports are registered (e.g., at switches 146B and / or 146D), and changes to the address table are flagged and alarms are generated by the switches. For example, if someone attempts to disconnect switch 146D from switch 146B and connect a new hub to port 215, switch 146B detects any unknown addresses of devices attempting to communicate with switch 146B via the new hub. If someone attempts to insert a new hub as an intermediary device between switches 146B and 146D, both switches 146B and 146D can detect the new hub (and / or any new address of the new device connected to the hub), and one or both can generate an alarm about the new physical address now connected to switches 146B and 146D. This uplink port detection mechanism allows users to identify when such physical access intervention is implemented.
[0065] Figure 2B This is a network diagram of an exemplary process control network 200B that implements a set of switches 146A-D. Network 200B is similar to network 200A. Each switch 146A-D in network 200B is configured to detect when one of its ports is connected to a second switch (i.e., an uplink port) and lock the uplink port only if the second switch is unmanaged. Each switch 146A-D can analyze the handshake with the second switch to determine whether the second switch is managed (e.g., to determine whether the second switch is switch 146). During locking, each switch 146A-D can process messages received via the uplink port differently depending on whether the connected second switch is lockable. In other words, depending on whether the second switch is lockable, each switch 146A-D can lock or keep the uplink port unlocked.
[0066] For example, switch 146A includes uplink port 211 connected to switch 146B. Because switch 146B is lockable, switch 146A keeps uplink port 211 unlocked. Similarly, switch 146B keeps uplink ports 213 and 215 unlocked because they are connected to lockable switches 146C and 146D. Switch 146A can forward messages received from switch 146B without authenticating the source physical address included in the message. It can be said that switch 146A “assumes” switch 146B is handling the locking of its ports, and therefore may not lock uplink port 211 even during locking. Switch 146B can similarly keep ports 213 and 215 unlocked. In some cases, switches 146A and 146B continue to monitor the source physical addresses of messages received via uplink ports 211-215 and can compare the source physical addresses with known physical addresses. When monitoring reveals that the source physical address is unknown, switches 146A and 146B can generate a port violation alarm.
[0067] When the second switch is not lockable (e.g., a generic or "off-the-shelf" switch), switch 146A-D can be used in conjunction with reference... Figure 2A The same method is used to lock up the uplink port. For example, switch 146B can lock up uplink port 203 (which is connected to an unmanaged or unlockable switch 109), as described in the reference. Figure 2A As described above. In some cases, when the uplink port is locked, the switch 146A-D discards messages with unknown source physical addresses. In other cases, when the uplink port is locked, the switch 146A-D continues to forward messages with unknown physical addresses, while generating port violation alerts or alarms.
[0068] Figure 2C This is a block diagram of switch 146. Switch 146 can be used for DeltaV. TMDeltaV intelligent switches in process control networks (with different series available to address different use cases). Switch 146 is a Layer 2 switch, meaning it operates at Layer 2 of the OSI model – the data link layer. In operation, switch 146 selects the forwarding port for a message by (i) identifying the destination physical address included in the message and (ii) referring to the switching table to identify the forwarding port associated with the destination physical address. Switch 146 does not keep track of intermediate nodes. For example, if switch 146 receives messages intended for use by terminal devices connecting to switch 146 via four intermediate nodes, switch 146 does not have a record of the "next node" or any other intermediate nodes. Instead, it refers to the switching table to determine which port should be used to forward the message. Furthermore, switch 146 does not keep track of network addresses for message forwarding purposes, and it does not use IP routing tables.
[0069] Conversely, Layer 3 network devices such as routers operate at Layer 3 of the OSI model—the Network Layer—and typically utilize routing tables. When a router receives a message, it identifies the destination network address contained within the message. The router then consults its routing table to determine the best route to the destination network address, identifies the "next-hop" network address listed as the best route, and forwards the message to the device with the "next-hop" network address. Layer 3 switches typically possess network routing intelligence similar to routers. In some cases, switch 146 may be a Layer 3 switch. That is, in some embodiments, switch 146 may utilize network addresses for routing and / or forwarding.
[0070] As previously mentioned, switch 146 is an "intelligent process control switch," meaning it is specifically configured for process control environments and for communicating with process control system-specific devices such as process controllers, field devices, I / O cards, process control workstations, process control history libraries, etc. Switch 146 firmware may include specific configurations to address DeltaV communication requirements, such as storm control (restricting data transmission for specific communications) and / or loop prevention. By downloading firmware specifically designed for process control system 100 to switch 146, switch 146 can be configured for process control operations. This dedicated firmware addresses use cases specific to process control system 100 and is generally inaccessible to the user for modification. Generally, the firmware used is designed to prevent network loops, prevent network storms, and lock unused switch ports.
[0071] Switch 146 includes one or more communication ports 202, a console access port 204, and status lights 206. Communication ports 202 are used to interconnect various other network devices and process control system components for communication over network 150, while status lights 206 indicate the current operation of network devices and can be used for diagnostic purposes. Generally, port 202 is configured to receive wired physical connections, such as Ethernet connections (e.g., using CAT5 ScTP or CAT6 cables) or fiber optic connections.
[0072] Switch 146 also includes circuitry 230, which is a dedicated application-specific integrated circuit (ASIC) configured to perform the operations and functions performed by switch 146. At higher levels, circuitry 230 controls port 202. Specifically, circuitry 230 enables and disables port 202, locks and unlocks port 202, and processes messages received at port 202. Figure 2B While circuit 230 is shown as a single circuit, in some embodiments, switch 146 may include multiple circuits that perform the functions described in reference circuit 230.
[0073] In addition, switch 146 may include memory 208 (which may include volatile memory 210 and / or non-volatile memory 212) storing the following: (i) one or more standard and proprietary management information bases (MIBs) 214; (ii) a switching table 216 (sometimes referred to as a "forwarding database table" or "FDB table"); (iii) a dynamic address table 218; (iv) a static address table 220; and (v) an address matching table 222. In some cases, memory 208 may include content-addressable memory (CAM), and one or more of tables 214-222 may be stored in the CAM.
[0074] Generally, each of the MIBs 214 is a database of objects or variables that can be manipulated to manage devices (e.g., switch 146) corresponding to a specific MIB 214. MIBs 214 may include a set of objects accessible via a command-line interface (CLI) for managing switch 146 and implementing process control network 150-specific functions. One or more dedicated MIBs 214 may include objects manageable by circuitry 230 for controlling the locking and unlocking functions described herein. Furthermore, circuitry 230 may utilize dedicated MIBs 214 to communicate with switch 146 via a runtime API for DeltaV. TM Network security features provide an interface. The process control network 150 can be configured as a hybrid of network devices, each including a dedicated MIB for controlling locking and unlocking functions (i.e., "locking devices") and commercial off-the-shelf network devices without locking or unlocking functions.
[0075] Switching table 216 includes one or more physical addresses (e.g., MAC addresses) and a corresponding port on switch 146 for each physical address. In operation, switch 146 receives a message at port 202. Circuit 230 analyzes the message to identify the destination physical address included in the message and refers to switching table 216 to identify the port 202 corresponding to the destination physical address. When switching table 216 does not include a destination physical address, circuit 230 may execute a flooding routine during which it causes switch 146 to transmit messages via all ports 202. Assuming a device with a destination physical address is connected (directly or indirectly) to port 202, the device will respond to the received message. After switch 146 receives the response, circuit 230 records the destination physical address and the port 202 from which circuit 230 received the response from the destination device in switching table 216.
[0076] Generally, switch 146 does not use dynamic address table 218 to make decisions about forwarding or dropping messages. Instead, dynamic address table 218 represents a record of devices connected to the ports, which can be continuously updated over time. Dynamic address table 218 lists the physical addresses of the end devices currently connected to each port 202 of switch 146. For example, switch 146 can analyze frames 175 received from devices (such as...) Figure 1C (As shown) The switch 146 dynamically learns the mapping of physical addresses to specific ports 202 by identifying the source MAC address 180 of the device. The switch 146 adds the source MAC address 180 to the dynamic address table 218 as the physical address mapped to the specific port 202. Furthermore, the switch 146 can dynamically learn the mapping of physical addresses to a second port by (i) analyzing frame 175 to identify the destination MAC address 1802 of the destination device, (ii) executing the flooding routine described with respect to the switching table 216, and (iii) identifying the port 202 that received the response message from the destination device. In some cases, the dynamic address table 218 can be periodically updated by copying information from the forwarding table 216. Additionally, in some implementations, the switch 146 uses only one of tables 216 and 218 for forwarding decisions and tracking the physical addresses of connected devices.
[0077] As nodes connect to or disconnect from switch 146 by mapping new physical addresses to port 202 to which new devices are connected and by aging up currently unused physical addresses (e.g., tracking the time or number of messages that have elapsed without successfully sending or receiving messages to or from a specific physical address), circuit 230 can update the dynamic address table 218. For example, when the aging time expires, circuit 230 can remove a physical address from the dynamic address table 218.
[0078] Similar to dynamic address table 218, static address table 220 lists the physical addresses of the terminal devices associated with each port 202. However, the physical addresses in table 220 are not dynamically learned and do not age out. Instead, they are explicitly entered by copying dynamic table 218 when switch 146 is locked. Functionality implemented in the firmware of switch 146 allows switching table 216 to be compared with tables 218 and 220 to process incoming messages. Circuit 230 can utilize static address table 220 when implementing authentication operations to authenticate the source physical address included in a message received at port 202. Specifically, if the source physical address of a received message is not identified as a known physical address mapped to the receiving port in static address table 220, circuit 230 can discard the message.
[0079] Generally, when switch 146 is in a normal or "unlocked" state, physical addresses can be added to switching table 216. For example, in the "unlocked" state, when switch 146 receives Ethernet frame 175, circuit 230 checks the destination MAC address 180 and refers to switching table 216 to identify the appropriate port 202 to which frame 175 should be forwarded. If switching table 216 does not contain information about the received destination MAC address 180, switch 146 broadcasts Ethernet frame 175 to all ports in network 150. When the broadcast MAC is identified at another network device, another frame can be sent to the broadcast switch 146, which adds the discovered MAC address to dynamic address table 218 and FDB table 216. However, in the "locked" state (discussed further below), switching table 216 can be frozen in its current configuration to prevent further changes or additions. Previously learned physical addresses and other information included in dynamic address table 218 when locked can be moved to static address table 220, and learning for switch 146 can be disabled. In the locked state, the switching table 216 cannot be modified, thereby preventing the switch 146 from accepting and forwarding frames 175 received from unknown or previously unlearned MAC addresses 182.
[0080] Address matching table 222 lists the network address of each known physical address stored in one or more tables in tables 216, 218, and 220. Switch 146 can determine the network address of a known physical address by sending an ARP request to that network address. Alternatively, in some cases, a database may store a list of network addresses of nodes on process control network 150, and switch 146 may download the network address of a known physical address from the database. While switch 146 does not utilize address matching table 222 to select forwarding ports for received messages, switch 146 can use table 222 to prevent Address Resolution Protocol (ARP) spoofing. Specifically, when switch 146 is locked, it can verify the identity of a source device that has sent a message to switch 146 by verifying that the source device has a network address that matches a known network address in address matching table 222. This verification can be helpful when a malicious device spoofs the physical address of a known device. See below for reference. Figure 5 Address matching table 222 is described in more detail.
[0081] When switch 146 has an uplink port (i.e., a port connected to the second switch), switch 146 can perform a handshake with the second switch to determine whether the second switch is a "managed" or "unmanaged" switch. Generally, a "managed" switch can lock its ports, while an "unmanaged" switch cannot. During the handshake, switch 146 can receive an indication from the second switch regarding its "lockability" or its status as managed or unmanaged. In some cases, switch 146 can send a query to the second switch, and the second switch can respond with an indication that it is managed. The second switch can also respond with an indication that it is unmanaged, or it can simply not respond. Failure to receive a response within a specific time period (e.g., 1 second, 5 seconds, 30 seconds, etc.) can be used to indicate to switch 146 that the second switch is unmanaged.
[0082] When switch 146 receives an indication that the second switch is managed, switch 146 can bypass locking the second switch, assuming the second switch will handle port locking. Accordingly, switch 146 can monitor the source physical addresses of devices communicating through the second switch and compare these monitored source physical addresses with records of known physical addresses. When switch 146 detects a monitored source physical address connected to the second switch that is not a known physical address, switch 146 can generate an alarm (e.g., a port violation alarm that can be transmitted to one of workstations 120 or 122 for display via a user interface).
[0083] Figure 3AAn exemplary method 300 for locking and unlocking ports 202 of one or more switches 146 is shown. Typically, method 300 allows a user of a process control system 100 to lock switch 146, causing switch 146 to discard any messages received from “unknown” devices. For example, if a user unplugs a device from port 202 of switch 146 and plugs in a different device, switch 146 rejects any messages from the different device and alerts the user interface, monitoring services, and / or other applications running on workstations 120, 122 of system 100. In the locked state, all ports 202 of network 150 and / or 155 can be locked, thereby preventing any new device with an “unknown” physical address from communicating via port 202. While the following method generally refers to… Figure 4A The user interface 400 shown in -D is provided, but it should be understood that any suitable user interface for performing the described functions can be used.
[0084] At block 302, the user can launch a process control network security application, which displays user interface 400. Figure 4A (As shown in -D) to begin the locking process. One of workstations 120 or 122 can provide a user interface 400, which can utilize the MIB 214 at switch 146 to initiate the locking and unlocking process.
[0085] At block 304, the application can initiate switch discovery, which can be automatic (e.g., at startup) or in response to user input. User interface 400 can display a "Discover Switch" status indicator 402 or another indicator that one or more switches 146 of process control network 150 are being identified. In some embodiments, the application can disable one or more function buttons on user interface 400 when network device discovery is initiated. The user can also manually initiate network device discovery. In some cases, the application can discover any switch (managed or unmanaged) present in process control network 150. In other cases, the application can only identify those network devices, such as switch 146, that include locking functionality.
[0086] Applications can discover switch 146 by searching network 150 using one or more parameters. In some cases, applications can search network 155 alternatively. Switch 146 can be initially discovered using its physical address. Switch 146 can be configured to have a network address during the debugging process. After the debugging process, communication with switch 146 via MIB 214 is enabled (e.g., switch 146 can be identified by locating its dedicated MIB 214), and devices outside the LAN can send messages to the switch by addressing the messages to switch 146's network address. Applications can search for switch 146 by searching a specified range of physical addresses and / or network addresses. Note that while switch 146 itself can have a network address, it typically does not depend on the network addresses of other devices when selecting a forwarding port for received messages.
[0087] At block 306, one or more switches 146 were found at block 304. Figure 4B ) can be accessed via the user interface 400 through an expandable drop-down menu 406 ( Figure 4A This can be displayed for switch 146 to show parameters for selecting one of the discovered switches from the expandable drop-down menu 406. Figure 4C For example, security parameters such as lockout status, lockout timer, and password lifetime can be displayed in the window of the user interface 400. The window can also display switch alarms (e.g., communication, fault, maintenance, recommendations) and component status parameters (e.g., power status, chassis temperature, etc.). The switch ports and multiple parameters for each port can also be listed (e.g., indicating whether the port is enabled or disabled, identifying the node name of the connected end node, identifying the port lockout address, and / or indicating whether a port lockout violation exists).
[0088] Once all discoverable switches 146 are found, the user interface 400 can indicate that the search is complete. In some embodiments, when method 300 is first initiated, switches 146 may be displayed only by their physical addresses in the list of decommissioned switches on interface 400. When a discovered switch is not locked, a locked state can indicate that the discovered switch 146 is in an "unlocked" state. In the unlocked state, switch 146 is able to perform all normal functions within network 150. In some embodiments, port 202 in the unlocked state can perform basic transparent bridging functions such as learning, aging, and forwarding. The default aging time can be set to 600 seconds (ten minutes), but other default times can be set according to the configuration of switch 146 and network 150. After the search is complete, one or more function buttons 434 are available for selection by the user or an automated process.
[0089] At block 308, the user or automated process can select... Figure 4A The user interface 400 shown lists one or more "Unlock" switches. The user can make this selection by using an input device on the workstation (e.g., a mouse or touchscreen) to select one or more desired switches, which causes the user interface 400 to display a drop-down menu with optional buttons for locking the switches. Figure 4B As shown, users can also select an entire network (e.g., by right-clicking the desired network) to lock it (i.e., locking all switches 146 in the selected network). In some cases, one or more switches 146 may include hardware actuators (e.g., buttons) that can be actuated to initiate the lock. Furthermore, the automated process can select the switches to lock based on triggers, such as detecting malicious devices connected to network 150 at a certain capacity.
[0090] At block 310, the workstation responds to detecting that the user has selected a lock button (such as...). Figure 4B The locking process (such as the locking button 436 shown) is initiated. Figure 3B (Method 325 shown). A lock button provided by the user interface 400 can initiate a process to selectively lock different parts of the process control network 150. For example, a single button can provide the ability to selectively lock the entire network, the primary network, the secondary network, individual switches 146, or a specific port 202 at one or more selected switches 146. For additional security, in some cases the lock process can be initiated only from selected workstations 120, 122, and can be initiated via the Internet without using, for example, a remote workstation that is not a physical part of the process control network 150, or can be initiated only from one or more pre-approved MAC addresses or IP addresses. An authentication process can be initiated when the lock process is initiated by selecting the lock button. For example, a workstation can request a username and password or other personal identifier from the user to confirm access to the lock process. The application can utilize administrative access via MIB 214 to lock and unlock switches 146. Communication can be encrypted, and any keys or passwords used are unknown to the user but known to the switches 146 and the application.
[0091] During authentication after selecting the lock button, the workstation can send a lock command to the selected switch 146 (e.g., by setting one or more variables in the selected switch 146's dedicated MIB 214). In response to receiving the lock command, switch 146 can lock all of its ports 202. Generally, locking port 202 includes refusing to accept any messages or frames 175 with a source MAC address 182 that was not included in switch 146's switching table 216 when the lock state is activated. In some embodiments, disallowed physical addresses can be recorded in switch 146's memory 208 (e.g., known, malicious MAC addresses, a series of MAC addresses belonging to unauthorized devices, etc.), and switch 146 can discard any received messages containing a disallowed physical address.
[0092] At block 311, after performing locking procedure 325 on one or more switches 146, it may be necessary to unlock one or more of the switches 146, for example, during troubleshooting operations, routine maintenance, diagnostics, network reconfiguration, etc.
[0093] At block 312, the user or automated process can select one or more switches 146 that are in a "locked" state, and at block 314, in response to the user's selection such as Figure 4D The unlock button shown allows the user's workstation to initiate the unlocking process (such as...). Figure 3C (Method 350 shown). Similar to the lock button, the unlock button can initiate an unlocking process for a different portion of the process control network 150 previously locked using one or more dedicated MIBs 214. For additional security, the unlocking process can be configured with a lock timer that automatically relocks one or more previously locked ports 220. The lock timer can be configured with a default setting whereby, after a period of time following the completion of the unlocking process (block 316), one or more unlocked switches 146 can be relocked (block 310). In one embodiment, the lock timer is configured with a default setting of 60 minutes (i.e., thirty-six hundred seconds). The unlocking process can be initiated from selected workstations 120, 122, and can be initiated via the Internet without using, for example, a remote workstation that is not a physical part of the process control network 150, or can be initiated from one or more pre-approved MAC addresses only.
[0094] The unlocking process may also include an authentication process. For example, workstation 120 or 122 and / or user interface 400 may request a username and password or other personal identification from the user to confirm access to the lockout process. If the user is properly authenticated, the user may access the dedicated MIB 214 of one or more selected lockout switches 146 and / or port 202 to initiate the unlocking process.
[0095] Figure 3B An exemplary method 325 for locking port 202 of switch 146 is shown. The blocks described below can be implemented by switch 146 and / or workstation 120 or 122.
[0096] At block 326, switch 146 generates static tables, such as static address table 220. Generally, a static table is a record of the known physical addresses of each port connected to switch 146 at the time of lockout initiation. Port states and / or physical address mappings may be stored automatically or explicitly by the user (e.g., stored in non-volatile memory 212). If needed, switch 146 may use the record of known physical addresses during power cycles or restarts to prevent forced opening of locked ports.
[0097] In some embodiments, a static table is generated by copying a list of physical addresses mapped to each port 202 from the dynamic address table 218. In some cases, known physical addresses and other data can be completely removed from the dynamic address table 218 and moved to the static address table 220. In some embodiments, if the current number of learned addresses in the dynamic address table 218 is greater than the maximum number, only a subset of addresses can be locked. The remaining addresses can then be removed from the swap table 216, potentially leading to connection errors. If a connection problem occurs, an error message can be sent to the user interface to indicate a failure in the locking process.
[0098] At block 328, switch 146 can analyze each message received at each port to identify the source physical address included in each message (e.g., Figure 1C The source MAC address shown is 182. Then, switch 146 can determine whether the source physical address is included in the static table (block 330). If not, the source physical address is an unknown address, and the message is discarded (block 332).
[0099] If the source address from the message is included in a static table, switch 146 analyzes the traffic at the port corresponding to the destination address included in the message (block 334). If the traffic at the forwarding port is below a traffic threshold stored in memory (e.g., input by a user or program during switch configuration), the message is forwarded (block 306). Otherwise, the message is held until the traffic falls below the threshold, at which point the message is forwarded. In some implementations, the message may be discarded after a predetermined time, or it may be discarded immediately. In some embodiments, switch 146 additionally or alternatively analyzes the traffic at the receiving port and only analyzes the source address of the message when the traffic falls below a predetermined traffic threshold (block 328).
[0100] Note that in some cases, switch 146 may disable typical functions of switch 146 during a lockout period. In one embodiment, switch 146 disables address learning and address aging functions for switch 146 or a specific port 202. For example, dynamic address table 218 may be disabled and no longer accept any entries, switch 146 may no longer flood network 150 to discover new addresses, and after the aging time expires, previously received addresses may not be removed from dynamic address table 218.
[0101] After initiating the lock, the user interface 400 can change the lock status of one or more switches 146 from "unlocked" or change the status indicator from "complete" to an indication that the selected device is locked or is in the process of locking. (Reference) Figure 4C After the locking process is completed, the user interface 400 can display the "lock status" of any locked switch as "locked".
[0102] Figure 3C An exemplary method 350 for unlocking switch 146 is shown. A user's workstation can send an unlock command to switch 146 (e.g., by changing the value of an object or variable in a dedicated MIB 214 of switch 146).
[0103] At block 354, address data in static table 220 that maps physical addresses to specific ports can be deleted. In some embodiments, static address data added by the user or other explicit procedures can be retained in static address table 220 during unlocking.
[0104] At block 356, switch 146 can enable the unlocked state of port 220. Specifically, switch 146 will stop discarding messages with source addresses that do not match static table 218.
[0105] At block 358, switch 146 can restore normal port or device functionality. For example, in the unlocked state, typical learning and aging functions that were suspended during the lockout can be restored, and switch table 216 and dynamic table 218 can be repopulated.
[0106] At block 360, switch 146 can store new switch or port configurations. For example, port states and / or physical addresses can be stored automatically or explicitly by the user, so that switch 146 can perform these operations during power cycles or restarts.
[0107] In some embodiments, after the unlocking process is initiated at block 314, the user interface 400 can change the lockout state of one or more switches from "locked" to an indication that the selected switch is in a "lock pending" state. Additionally, if the lockout timer is initialized using the unlocking process, the remaining time state can indicate the amount of time remaining before the device returns to the locked state. The remaining time can also be configured to never return to the locked state. For example, an object in dedicated MIB 214 can be accessed to configure the timer to a "never return" state or any other amount of time.
[0108] In some embodiments, switch 146 can be restored to a saved configuration upon power-up. For example, an entity may attempt to connect an unauthorized device to process control network 150 by cycling the power supply to one or more switches 146 to force open a locked port. Upon power-up, switch 146 may be configured to access its non-volatile memory 212 ( Figure 2C The configuration is stored at [location]. Therefore, regardless of whether the power cycle switch returns to the locked or unlocked state, all devices connected to network 150 before the power cycle can automatically re-establish communication with the system, while any new devices added to the port during a power outage will be rejected. If a device is powered on in the "unlocked" state and the lockout timer is greater than zero, the device can automatically enter the locked state after that time expires.
[0109] Figure 5 An example of address matching table 222 according to some embodiments is shown. Figure 5 The address matching table 222 shown may be a representation of data that can be stored on switch 146 (e.g., using content-addressable memory) and / or on another device within the process control system. Alternatively or additionally, devices (such as switch 146, workstation 120 or 122, or another device) may cause at least a portion of the information included in address matching table 222 to be presented on a user interface (e.g., user interface 400) for user access and viewing. It should be understood that address matching table 222 is merely an example and therefore includes exemplary information, and may include alternative and / or additional information.
[0110] Address matching table 222 may include a set of columns, each filled with corresponding data and information. Specifically, address matching table 222 may include port column 505, IP address column 510, MAC address column 515, lockout status column 520, and security status column 525. Port column 505 may identify the communication port set 202 of switch 146 (as shown in the figure: communication ports 1 to 6). Each communication port in this communication port set 202 may have a device or another switch connected to it. If a communication port is connected to another switch 146, the communication port may be considered an uplink port. Although... Figure 5The diagram shows a single device (or no device) connected to each port, but it should be noted that a single port can be mapped to multiple devices, each of which will include a physical address (column 510), a network address (column 515), a locked state (column 520), and a security state (column 525).
[0111] IP address column 510 can identify the set of network addresses (e.g., IP addresses) of the set of devices respectively connected to the communication port set 202, and MAC address column 515 can identify the set of physical addresses (e.g., MAC addresses) of the set of devices respectively corresponding to the communication port set. For example, a device with IP address 10.10.10.2 and MAC address 00:0C:F5:09:56:E9 is connected to communication port "1". Figure 5 As shown, there are no devices connected to communication ports "3" and "6", so their corresponding IP and MAC addresses are empty.
[0112] Lock status column 520 can identify the lock status (e.g., "locked" or "unlocked") of each of the communication port sets 202. Figure 5 As shown, each communication port 202 (communication ports "1", "2", "4", and "5") connected to a device is "locked", and each communication port (communication ports "3" and "6") not connected to a device is "unlocked". However, it should be noted that in a typical example, when switch 146 is locked, all ports of switch 146 are locked unless the switch port is identified as an uplink port or manually configured by the user via CLI to be ignored (always unlocked). In the embodiments discussed herein, switch 146 (specifically, a set of ASICs of switch 146) can obtain the IP and MAC addresses of the devices associated with initiating the locking of the occupied communication ports.
[0113] Security status column 525 can identify the security status of each communication port in the communication port set. According to an embodiment, switch 146 can automatically and continuously monitor information (e.g., as data packets) received and transmitted via the communication port set, between and among devices already connected to it and / or any other devices that can be connected to the switch after it is locked.
[0114] Switch 146 can inspect any received data packets to determine if there are any discrepancies in the information included in the data packets. Specifically, switch 146 can compare the information included in the data packets with the information included in address matching table 222 to identify discrepancies. If switch 146 does not identify any discrepancies in the data packet traffic for a particular communication port, the security status of that communication port can be "normal". Conversely, if switch 146 identifies discrepancies in the data packet traffic, the security status of that communication port 222 can change from "normal" to "alarm".
[0115] like Figure 5 As shown, the security status of communication ports "2" and "6" is "alarm," while the remaining communication ports have a "normal" security status. In an exemplary embodiment, the security status of communication port "2" may be "alarm" due to an attempted ARP spoofing attack. In this embodiment, the device initially connected to communication port "2" may be replaced by an attacking device (or the originally connected device may be compromised), which can send data packets to switch 146. Switch 146 can inspect the data packets and determine that one or both of the IP addresses and MAC addresses included in the data packets do not match the corresponding IP address and / or MAC address in address matching table 222. Therefore, switch 146 can update the security status of the corresponding communication port to "alarm."
[0116] Similarly, in an exemplary embodiment, the security status of communication port "6" can also be "alarmed" due to an attempted ARP spoofing attack. In this embodiment, communication port "6" can be unlocked because no device is connected to it when it is locked. After locking, a device (which may or may not be the attacking device) can connect to the unlocked communication port "6," and the device can send data packets to the switch. Switch 146 can examine the data packets and determine that because communication port "6" is unlocked, the device should not communicate via communication port "6." Therefore, the switch can update the security status of the communication port to "alarmed."
[0117] Switch 146 can facilitate the communication and / or display of any detected alarms. In an embodiment, switch 146 can be connected to another device in a process control system that may be equipped with a user interface. Switch 146 can transmit indications of one or more detected alarms to the device, which can be configured to display or present one or more detected alarms via a user interface. Thus, users associated with the process control plant (e.g., individuals or administrators) can access and view the information and facilitate appropriate corrective or diagnostic actions.
[0118] Figure 6A block diagram of an exemplary method 600 for implementing address matching table 222 to improve the security of a process control system (such as process control system 100) within a process plant is shown. Implementation of method 600 can be facilitated by switch 146.
[0119] Method 600 may begin when switch 146 initiates a lock on the set of communication ports of switch 146 (block 605). In an embodiment, switch 146 may initiate a lock on a portion or all of the set of communication ports of switch 146.
[0120] In connection with initiating a lock on the communication port set, switch 146 may obtain a set of network addresses (e.g., a set of IP addresses) of a set of devices connected to at least a portion of the communication port set (block 610). It should be understood that the switch may obtain the set of network addresses before, simultaneously with, or after initiating (and / or completing) a lock. In one embodiment, a set of ASICs included in the switch may obtain the set of network addresses using data associated with the connection of the device set to at least a portion of the communication port set. Alternatively or additionally, the device set may include one or more devices within the process plant and / or one or more additional devices (or additional switches) that can be connected to one or more switches. In a particular embodiment, switch 146 may obtain (i) a first network address of a first device connected to a first communication port (i.e., device connection), and (ii) multiple network addresses of multiple devices connected to a second communication port via additional switches (i.e., switch connections). Network addresses may be obtained from another device on the process control network.
[0121] Switch 146 may optionally obtain a set of physical addresses (e.g., MAC addresses) of a set of devices connected to at least a portion of the set of communication ports in connection with initiating a lock (block 615). It should be understood that the switch may obtain this set of physical addresses before, during, or after initiating (and / or completing) a lock. For example, the switch may obtain and record the set of physical addresses before initiating a lock. In one embodiment, a set of ASICs (e.g., circuitry 230) included in switch 146 may use data associated with the connection of the set of devices to at least a portion of the set of communication ports to obtain the set of physical addresses.
[0122] Switch 146 can generate an address matching table 222 (block 620) for switch 146, wherein address matching table 222 can match the physical address set of a set of devices with the network address set of that set of devices. Address matching table 222 can also match the physical address set and network address set with at least a portion of a set of communication ports. That is, for each device connected (directly or indirectly) to a specific port of switch 146, address mapping table 222 can list the address pairs of network address and physical address for that specific port. Therefore, a port connected to multiple devices will have multiple associated address pairs (i.e., one address pair per connected device). Switch 146 can store the address matching table locally (e.g., using content-addressable memory) for access and viewing.
[0123] Switch 146 can receive data packets from the device via one of the communication ports in the communication port set (block 625), wherein the data packets can at least indicate (i) the device's network address and (ii) the device's physical address. In an embodiment, the device can connect to one of the communication ports in the communication port set before or after switch 146 initiates a lock. Alternatively, the device can replace another device previously connected to one of the communication ports in the communication port set (i.e., in the case of cable replacement). Alternatively, the device can connect to an unlocked communication port or a communication port in a portion of the communication port set (i.e., a locked communication port).
[0124] According to an embodiment, data packets may represent an ARP spoofing attack performed by a device, and switch 146 may be configured to determine the ARP spoofing attack by determining whether the device's network address and physical address are included in address matching table 222 (block 630). Specifically, the device's network address and physical address, as a pair, may not match the mapped network address and mapped physical address included in the address matching table of the communication port to which the device is connected. For example, if the device is connected to communication port "3", and either or both of the device's network address and physical address do not match the corresponding mapped address of communication port "3", then a mismatch exists.
[0125] If switch 146 determines that the address matches (“Yes”), the process can end, repeat, or continue to other functions. Conversely, if switch 146 determines that the address does not match (“No”), an ARP spoofing attempt may have occurred, and switch 146 can generate an alarm (block 635). In an embodiment, the alarm may indicate a communication port in a set of communication ports to which the device is connected, and / or other information including the device’s network address and / or physical address. Additionally, switch 146 may cause the alarm to be displayed on a user interface (block 640), wherein the user interface may be included on another device or component within the process plant. Thus, a user (e.g., a plant technician or administrator) can view the alarm content and initiate appropriate action.
[0126] Switch 146 can also determine whether to allow or deny the transmission of data packets (block 645). In embodiments, this determination may be a default selection (e.g., always allow or always deny), or switch 146 may dynamically determine whether to allow or deny transmission based on one or more factors, such as the content of the data packet itself, the physical address of the device, the network address of the device, and / or other factors.
[0127] If the switch determines that transmission is allowed (“Allow”), the switch may allow the transmission of the data packet (block 650). Conversely, if the switch 146 determines that transmission is denied (“Reject”), the switch may reject the transmission of the data packet (i.e., may discard the data packet).
[0128] Figure 7 A block diagram of an exemplary method 700 for detecting security issues associated with switch 146 is shown. The implementation of method 700 can be facilitated by switch 146.
[0129] Method 700 may be initiated when switch 146 optionally initiates (block 705) a lock on the set of communication ports of switch 146, as described herein. In embodiments, switch 146 may initiate a lock on a portion or all of the set of communication ports such that, in some cases, one or more communication ports may remain unlocked if needed.
[0130] In connection with initiating a lock on a set of communication ports, switch 146 can obtain a set of network addresses (e.g., a set of IP addresses) of a set of devices connected to at least a portion of the set of communication ports. It should be understood that switch 146 can obtain the set of network addresses before, simultaneously with, or after initiating (and / or completing) the lock. In one embodiment, a set of ASICs included in switch 146 can obtain the set of network addresses using data associated with the connection of the set of devices to at least a portion of the set of communication ports. Alternatively or additionally, the set of devices may include one or more devices within a process plant and / or one or more additional devices (or additional switches) that can be connected to one or more switches. In a particular embodiment, switch 146 can obtain (i) a first network address (i.e., device connection) of a first device connected to a first communication port, and (ii) multiple network addresses (i.e., switch connections) of multiple devices connected to a second communication port via additional switches.
[0131] Switch 146 may optionally obtain a set of physical addresses (e.g., a set of MAC addresses) of a set of devices connected to at least a portion of the set of communication ports, in connection with initiating a lock. It should be understood that the switch may obtain this set of physical addresses before, during, or after initiating (and / or completing) a lock. For example, switch 146 may obtain and record the set of physical addresses before initiating a lock. In one embodiment, a set of ASICs included in switch 146 may use data associated with the connections of the set of devices to at least a portion of the set of communication ports to obtain the set of physical addresses.
[0132] Switch 146 can also generate and access address matching table 222 (block 710), wherein address matching table 222 can match the physical address set of a set of devices with the network address set of the set of devices. Address matching table 222 can also match the physical address set and the network address set with at least a portion of a set of communication ports. Thus, each communication port with a device connected to it can have the associated physical address and network address of the device. In one embodiment, a set of ASICs included in switch 146 can generate address matching table 222. Switch 146 can locally store (e.g., using content-addressable memory) the address matching table for access and viewing.
[0133] Switch 146 may broadcast a mapping request specifying a destination network address that matches a network address in a set of network addresses included in the address matching table (block 715). In one embodiment, the mapping request may be in the form of an ARP request that includes an IP address from the address mapping table, wherein the ARP request is intended to find the MAC address corresponding to the IP address, and wherein the ARP request may be sent to each device connected to the switch.
[0134] Switch 146 can receive a response to the mapping request from the responding device via one of the communication ports in the communication port set (block 720), wherein the response may indicate (i) the destination network address and (ii) the physical address of the responding device. According to an embodiment, the response from the responding device may indicate an ARP spoofing attack attempted by the responding device, and switch 146 may be configured to identify such an ARP spoofing attack.
[0135] Therefore, switch 146 can determine whether the physical address of the reply device matches any physical address in the set of physical addresses of the device set included in the address matching table (block 725). Specifically, for the communication port to which the reply device is connected, the physical address of the reply device may not match the mapped physical address included in address matching table 222. For example, if the reply device is connected to communication port "3", and the physical address of the reply device does not match the corresponding mapped physical address of communication port "3", then a mismatch exists. In one implementation, a set of ASICs included in the network can make this determination.
[0136] If switch 146 determines that the physical address matches (“Yes”) (i.e., no ARP spoofing attack attempt is being attempted), the process can end, repeat, or continue to other functions. Conversely, if switch 146 determines that the physical address does not match (“No”), an ARP spoofing attempt may have occurred, and the switch can generate an alarm (box 730). In an embodiment, the alarm may indicate a communication port in the set of communication ports to which the response device is connected, and / or other information including the network address and / or physical address of the response device. Additionally, switch 146 may cause the alarm to be displayed on a user interface (box 735), wherein the user interface may be included on another device or component within the process plant. Therefore, a user (e.g., a plant technician or administrator) can view the alarm content and initiate appropriate actions.
[0137] The locking and address mapping routines described herein can be implemented in software, hardware, firmware, or some combination thereof. Therefore, the methods 300, 325, 350, 500, 600, and 700 described herein can be implemented in a standard multipurpose CPU and / or on specially designed hardware or firmware such as an ASIC. When implemented in software, the software can be stored in any computer-readable storage medium, such as a hard disk, laser disk, optical disk, or other storage medium, or in the RAM or ROM of a computer or processor. The software can be delivered to the user or process control system via any known or desired transmission method, including, for example, on a computer-readable disk or other transportable computer storage medium, or via communication channels such as telephone lines, the Internet, etc. (considered the same as or interchangeable with providing such software via a transportable storage medium).
[0138] Generally, as used herein, the phrase “memory” or “memory device” refers to a system or device that includes a computer-readable medium (“CRM”). “CRM” refers to a medium or medium accessible to the relevant computing system for placing, storing, and / or retrieving information (e.g., data, computer-readable instructions, program modules, applications, routines, etc.). Note that “CRM” refers to a medium that is inherently non-transitory and does not refer to intangible transient signals such as radio waves.
[0139] For reference Figure 1A The network 150 is a collection of nodes (e.g., devices or systems capable of sending, receiving, and / or forwarding information) and communication links connected to enable communication between nodes. Generally, the term "node" refers to a connection point, redistribution point, or communication endpoint. A node can be any device or system (e.g., a computer system) capable of sending, receiving, and / or forwarding information. For example, a terminal device or system that initiates and / or ultimately receives a message is a node. Intermediate devices that receive and forward messages (e.g., between two terminal devices) are also often considered "nodes." A "communication link" or "link" is a path or medium connecting two or more nodes. A link can be a physical link and / or a logical link. A physical link is the interface and / or medium on which information is transmitted and can be wired or wireless in nature. Examples of physical links may include cables with conductors for transmitting electrical energy, fiber optic connections for transmitting light, and / or radio electromagnetic signals that carry information via alterations to one or more properties of electromagnetic waves.
Claims
1. A method for locking a process control switch, comprising: The detection process controls the activation of the switch's locking mechanism; Detect the second switch connected to the port of the process control switch; Check whether the second switch is lockable; The response to detecting that the second switch is not lockable is achieved by the following steps: (i) receiving from the second switch a set of addresses of a known set of devices that have been transmitted by the second switch, and (ii) converting the process control switch to a locked state where the port is locked, such that traffic at the port is limited to messages received from or addressed to addresses included in the set of addresses received from the second switch. as well as The process control switch is switched to a locked state (where the port is not yet locked) in response to the detection that the second switch is lockable, wherein... Detecting that the second switch is lockable includes performing a handshake operation between the process control switch and the second switch.
2. The method according to claim 1, wherein, The addresses in the address set are physical addresses or network addresses.
3. The method according to claim 1 or 2, wherein, Leaving the port unlocked includes: not checking the address of messages received via the port.
4. The method according to claim 1 or 2, wherein, Leaving the port unlocked includes checking the address of messages received via the port and not discarding messages received via the port.
5. The method according to claim 1 or 2, wherein, The address set includes physical addresses, and the method further includes: Track network addresses included in the address set; The physical address of the message was detected to be inconsistent with the tracked physical address; and Issue a warning or discard the transmission information from the device that sent the message.
6. The method according to claim 1 or 2, further comprising: Monitor messages transmitted via the second switch; as well as Record the addresses associated with the monitored messages to compile the address set.
7. The method according to claim 1 or 2, further comprising: The process control switch is locked upon detection of malicious devices connected to the network.
8. The method according to claim 1 or 2, further comprising: A user interface is provided, which is configured to receive user instructions from the process control switch and to initiate a lock on the process control switch.
9. The method according to claim 1 or 2, further comprising: Before returning the process control switch to the locked state, the state of the process control switch is changed to the unlocked state for a predetermined period of time.
Citation Information
Patent Citations
One button security lockdown of a process control network
US8590033B2
Method for performing calibration time delay error testing on time delay calibration switch of intelligent substation
CN104836705A
Information synchronization method, and terminals
CN106411864A