Operational Technology Management - Connecting Your Ecosystem with a System of Action
my name is bill musson i am an engineer with servicenow i work in the it operations management space across the dod and intel communities and i get to talk about something that five years ago nobody would really cared a ton about but in the last month or so there's been a lot of activity in this space that has started to make operational technology something that people are being um very concerned about um i was going to put together a number of slides on current events and and things that have happened with operational technology and attacks that have happened in the space and when i got to 20 i just realized you know what i don't have enough space in my slides to do that suffice to say i will be talking about operational technology and how um we should be looking at um understanding a little bit better now everything that i'm talking about here i may talk about some future things so this is just my get out of jail free slide and um basically i'm going to talk a little bit about the challenges that we are seeing uh with operational technology and our level set too how many people understand what operational technology is vice information technology okay got a few so that's part of the problem too um traditionally operational technology has been around for many many many years i used to be the network security officer down here at pearl harbor with a gentleman by name mike dwyer many years ago and one of my jobs was to write up the 600 page document called an ssaa that kind of tells you how old i am describe all the security elements within the environment describe your networking describe all the systems that are being connected and i got the wonderful job of finding all of the scada systems and industrial control systems that pearl harbor had and it was a challenge to say the least when you go into an office and you talk to somebody that's in i.t and they're like yeah i think we got some of those uh go go talk to what's his name back there in the corner you know he he runs ot we don't like to talk to him so basically you had these systems that it would build out a network and say this is your network you're not going to touch our network go do whatever you want to do but don't call us and then so you would go talk to the gentleman he's like well i i think we've got these things i just know that you know if something breaks somebody eventually calls me and i go out and try and find it and i fix it that's the problem because when your operational technology fails you in many ways if you don't understand what the implication of that failure is it could be catastrophic i will bring up one thing that did happen it was in the headlines a few weeks ago and it was an attack against an operational technology system in russia basically they got into their gas pipelines and started messing with the pressure of the systems that were piping natural gas to their their their infrastructure to the point where they were able to burst their pipes and cause massive fires so what we are seeing i think more and more is that when there's going to be conflict rather than me facing you across the battlefield with uh you know rifles pointed at each other i'm going to be behind this and i'm going to be doing the best thing that i can do i probably will have a greater effect on my enemy or they will have a greater effect on me just by putting some commands into a keyboard so it's very important for us to understand the environment and then how to not only figure out what we have get that visibility that most of us don't see but how are we securing it how we understanding when there's vulnerabilities and how we're going to repair these things and then additionally how are we going to upgrade technology that's 60 years old i guarantee that there's sensors out there right now that are older than anybody in this room and ideally the individuals that are responsible for looking at this don't know what they have they don't know what it's going to cost for them to actually upgrade it they don't know what the path is for that upgrade and so we need to figure out a way of being able to do this a little bit of facts here again um it doesn't look like it's going to be a fun area for us to think about but operational technology hits across a lot of different things you might think about sensors right you go to your house you turn your thermostat the temperature gets to a certain point it recognizes that starts heating or cooling your abode but in our environments they're taking care of things like fuel flow or hvac to your data centers or other types of very critical infrastructure in your environment and we have to make sure that we understand what do we have and what's the implication if something is going to go down or we're going to do a repair on a specific node or a specific device that might take out a number of the different systems by being down for a certain period of time now the three areas that i think frankly i would agree with that we have problems with knowing what we have out there if you go talk to any of the folks that are responsible for your operational technology environments and ask them do you know where everything is the answer that you're going to get most of the time is i think so i've got a spreadsheet my spreadsheet's going to tell me everything i need to know how do they handle situations where something has happened and they need to go out and respond to it they need to go out and fix it do they even know that the system is down and most of the time they'll tell you until somebody calls me i have no idea and then finally of course how do we make sure that we're securing those environments now from our standpoint at servicenow we have been really investing a lot of time in the operational technology arena and you would think how does a cloud platform perform things that are going to help me in the operational environment so we're looking at understanding by bringing in visibility by discovering devices in the environment now if you understand i mentioned it which is your traditional servers your routers your switches those are all very simply discovered in your environments using traditional tcp methodologies to identify those systems operational technology sensors operate in a different paradigm a different protocol if you will they're using things like modbus or rpi bus these are things that you know most of us don't even run into when we're in ittech so what servicenow is doing is partnering with third-party organizations third-party tool sets if you will that do that passive understanding at the lower levels of the operational technology environments it's referred to as a purdue level it's basically five levels of understanding of how an environment would be put together so level zero one two and three are the areas in which operational technology devices operate and are basically running protocols that are not visible to a traditional scanner for example for example anything above that is where your servers your your human machine interface uh devices maybe even you know your historians will reside everything else the sensors the programmable logical controllers the uh the robotics the the uh actuators all those things operate at the lower levels and so we need an ability to be able to discover those most organizations do not want you actively scanning their operational technology devices and if you equate that to a medical look at these type of devices it's kind of like your heart monitor right it's a it's actually a sensor right it's trying to determine how fast your heart is beating and your ekgs and things like that and it would be a bad day for you if you were having open heart surgery and somebody kicked off a scan and knocked those devices offline well think of the same thing with operational technology in an industrial environment we don't want to knock them offline either so you need a passive methodology to actually be able to understand what you have that's where a lot of players in the past you would consider them to be very small companies they did that one little thing and that's all they did but now you're starting to see companies like dragos or nozumi or clarity or even microsoft you know they're they're now seeing that there are so many of these devices out in the world that there's an opportunity for them to not only understand the problem but also of course make a great business case for what they want to do we're partnering with those organizations to provide an ability for them to send the information that they discover into servicenow's configuration management database tie that to the it information that we can discover and then give the operators the visibility as to what they have in their environment additionally these companies are doing research into vulnerabilities that are apparent in the devices so we're able to in take that vulnerability information into servicenow and identify that against the devices so that you have a clear picture of that device has got a vulnerability we need to go do something about it and then finally you know the other area is what i like to call the upgrade path right most organizations don't know if i've got device x dot one what's the upgrade path now 30 years later from that device is it x.2 is the deck stock 10 being able to understand the device maker's intent on being able to upgrade those is also very very important ideally understanding not only what the upgrade path is but how much is that going to cost how are you going to plan that out i was having a conversation with a gentleman in the army who said basically i've got three four hundred thousand of these things out there that i need to figure out how i'm going to upgrade i don't know what it's going to cost i don't know what i have and even if i did i wouldn't know how to actually palm that out so ideally what servicenow is bringing to the table is bringing in all this information into the configuration management database that we have and providing that ability to use our capabilities to get those answers so it all basically is part of understanding what do you have all right and ideally using terminology that your operational technology personal use so i mentioned the term purdue levels no one outside of operational technology actually speaks like that right so we try to um make it understandable so that the operators can understand what we're trying to do in their language and then identify everything that's in the environment all right what is the manufacturer what is the the um version that you may have whether that is hardware or software where is it located what is talking to what more importantly now remember earlier when i spoke i said that i got to go out and ask well where are all these devices i was usually given a spreadsheet and i would have to go crawl in very very dirty places to try and find these things um i would have killed for a map back then to visually understand what is connected to what so the idea from a servicenow standpoint is to not only get the information but now show how your infrastructure is put together in a pictorial view so that if i see something go down what's the effect of that against the rest of your operational environment and i can do that at a glance couldn't do that before additionally understanding what vulnerabilities do we have and can i apply the vulnerabilities that are being reported on daily against the devices that i have right again i said that there's been 20 different types of vulnerabilities and attacks discovered the last few weeks we can't stay ahead of that unless we have some sort of automated way to identify those vulnerabilities and then have a plan in place to remediate them um the one thing that i think that servicenow brings to the table more than anything else and this really kind of dovetails into what alex was talking about was our capability to build workflows based off of the ideas that our personnel have to make things better so if i understand what is out there and i have an idea of how i might want to use a workflow to assess something or to be able to remediate something in a faster way servicenow provides that capability today inheriting our platform now you might ask who do we play with so if you take a look at this a lot of the major players in the operational technology workspace are the organizations that we are working with today whether it's from a robotic standpoint or control systems or other types of things but over on the right where you see ot network and security unfortunately i've got a blockage there i'll just try and move that or not these are all the players that you generally see working at that lower level the purdue area and identifying passively what those devices are in the environment forescout nozumi tenable dragos for example um we have been actively engaged working with these companies to allow us not only to understand the information that they can provide to us from a visibility standpoint but also taking the vulnerabilities that they have found and bringing that into the system as well to apply that against the devices so that we can more quickly identify and remediate the problems all right so just go ahead and i think that uh what i'd like to do is just show you a couple of things that i'm trying to stay on time for everybody um i'm going to go directly into what it looks like inside of our system so within the servicenow platform when we set up a connection to a third-party system in this case i've been working with nozumi to directly import information from a nozumi environment using their tool set so what you're seeing here is actually real data it's not demo data and i was pulling in information plc sensors that sort of thing so the idea here is to be able to understand what are all your assets and i can identify those i can decide you know what ip addresses they may be using for example what versions what model numbers are most importantly identifying where they're located at so i have the ability now to actually do location awareness based off the information that's being provided by the third party tools remember i said that it's important for us to actually be able to report and notify so i want to understand what do i have i can look at things at a glance i can drill down into any one of these and understand exactly what is at a particular site i can drill into one of these for example and be able to understand how is this configured who made it what version number what firmware are you running and then ideally and this is the part that i would have killed for show me how it's all put together in a pictorial view so this plc that i just hit goes down i know it's going to affect this entire structure here as being something i've got to be worried about or if any one of these specific areas goes down i can quickly understand the implications of okay i'm going to do some remediation on this hmi well then that hmi is going to affect these programmable logical controllers or these sensors or if that sensor goes down i don't have any visibility in things so the whole idea here is to have a program in place to identify what you have be able to remediate that based off the vulnerabilities that you see and then have a plan of action to be able to figure out how i'm going to upgrade yes sir so i'd like to ask you about this the state of the industry find ics scada or security sensor data formats standards apis so ideally you would want this enterprise to be able to auto discover pretty much every data element every essential element of information week that doesn't happen because the whole power here is economy and scale right so so you want to be able to auto discover these devices one other thing i mentioned good news is it's a very good question sir um there are standards out there today but there exists more in the commercial world than in the shall we say the dod space even within the navy you have something called mosaics and um if you look at mosaics at a high level it is a a a a a research tool if i would like to put it this way where you've got 20 or 25 different vendors that have tried to come together to work as a team to provide capability to the navy they've reached out and have realized that i have all of these different players here that don't talk to one another they all have their one little niche they're trying to figure out well how do i put all this information together into a single location a single source of truth if you will to be able to um you know make everybody play nicer in the sandbox that's not here yet unfortunately i think that the industry itself is it's it's growing very very fast and um it's um getting better but there's no one nirvana yet right yeah so so what we are seeing is with federal credible infrastructure program there is and nist is kind of driving the standards there but all these vendors we brought in have the ability to discover basically multiple protocols and when you saw the picture that bill showed briefly leveraging service graph connector that enables us to etl that up into a common format into the cmdb so we can drive workflows but that discovery is automated so you could schedule it but then if we see an incident we can drive and push a discovery to validate that incident so if you get a trap for example we can go back and pull it and say okay is this accurate at the endpoint device so so the standards are coming critical infrastructure is kind of driving that but nist is kind of what everybody is going to at least the for the basic table stakes yeah and most of these are not snmp for example right so if you look at plc's these controllers that that the pipeline's got those are not those are different protocols and all these vendors we work with once again servicenow we don't touch the network down there we can see if it's an ip we can't tell you what it is or the relationship attributes so we deal with these partners who do that they build the asset model from a security perspective but then we ingest that into our data model so we can drive workflow any other questions from anybody all right terrific then i think i will turn it over to mark
https://www.youtube.com/watch?v=jgUFlZiZeio