Software-Defined Networking (SDN) Now for Operational Technology (OT) Networks SEL 2017

Similar documents
OTSDN What is it? Does it help?

Cybersecurity was nonexistent for most network data exchanges until around 1994.

SEL-5056 Software-Defined Network (SDN) Flow Controller

CSC 4900 Computer Networks: Network Layer

Software-Defined Networking (Continued)

Software Defined Networking

Software-Defined Networking Redefines Performance for Ethernet Control Systems

ASIT-33018PFM. 18-Port Full Gigabit Managed PoE Switch (ASIT-33018PFM) 18-Port Full Gigabit Managed PoE Switch.

Slicing a Network. Software-Defined Network (SDN) FlowVisor. Advanced! Computer Networks. Centralized Network Control (NC)

RRPP. Compared with Spanning Tree Protocol (STP), RRPP features:

Lesson 9 OpenFlow. Objectives :

Chapter 5 Network Layer: The Control Plane

Spanning-Tree Protocol

Cisco Extensible Network Controller

Upgrading From a Successful Emergency Control System to a Complete WAMPAC System for Georgian State Energy System

Index. Numerics. Index 1

Optimizing Ethernet Access Network for Internet Protocol Multi-Service Architecture

Configuring ARP attack protection 1

Software Defined Networking

Lessons Learned and Successful Root Cause Analysis of Elusive Ethernet Network Failures in Installed Systems

Internetwork Expert s CCNP Bootcamp. Hierarchical Campus Network Design Overview

Chapter 4 Network Layer: The Data Plane

Web-Based User Interface for the Floodlight SDN Controller

Network Security. Thierry Sans

Spanning Tree Protocol(STP)

Using SDN and NFV to Realize a Scalable and Resilient Omni-Present Firewall

JUNIPER JN0-643 EXAM QUESTIONS & ANSWERS

AdvisorSLA. The next IP SLA generation Solution. Advisor SLA. Network & Application Performance Monitoring Solution.

Internetwork Expert s CCNA Security Bootcamp. Mitigating Layer 2 Attacks. Layer 2 Mitigation Overview

: Building Cisco Multilayer Switched Networks

Network+ Guide to Networks 7 th Edition

Configuring Rapid PVST+ Using NX-OS

H3C S10500 Attack Protection Configuration Examples

OPENFLOW & SOFTWARE DEFINED NETWORKING. Greg Ferro EtherealMind.com and PacketPushers.net

OpenFlow Ronald van der Pol

Ferdinand von Tüllenburg Layer-2 Failure Recovery Methods in Critical Communication Networks

Manual:Interface/Bridge - MikroTik Wiki

Network Security: Network Flooding. Seungwon Shin GSIS, KAIST

H3C S1850 Gigabit WEB Managed Switch Series

Chapter 5: STP. * What is STP? How does STP work?

Configuring ARP attack protection 1

26-Port Full Gigabit Managed PoE Switch

Implementing VXLAN. Prerequisites for implementing VXLANs. Information about Implementing VXLAN

14-port Gigabit Managed Industrial POE Switch

Configuring Dynamic ARP Inspection

Configuring Rapid PVST+

Huawei Technologies engaged Miercom to evaluate the S12700

Zone-Based Policy Firewall High Availability

Chapter. Managed Switch Software Monitoring. In This Chapter...

DevoFlow: Scaling Flow Management for High Performance Networks

IQ for DNA. Interactive Query for Dynamic Network Analytics. Haoyu Song. HUAWEI TECHNOLOGIES Co., Ltd.

1756-EN2TP Parallel Redundancy Protocol Module Network Redundancy

Configuring Rapid PVST+

Chapter 5. Spanning Tree Protocol (STP) Part II

Configuring STP. Understanding Spanning-Tree Features CHAPTER

this security is provided by the administrative authority (AA) of a network, on behalf of itself, its customers, and its legal authorities

Configuring OpenFlow 1

Overview of the Cisco OpenFlow Agent

Configuring Spanning Tree Protocol

cisco. Number: Passing Score: 800 Time Limit: 120 min.

UNDERSTANDING SENETAS LAYER 2 ENCRYPTION TECHNICAL-PAPER

CSC 401 Data and Computer Communications Networks

Routing Between VLANs Overview

Layer 2 Implementation

SAE-PE QSFP-NMS

Application of SDN: Load Balancing & Traffic Engineering

Designed for Railway application and fully compliant with the requirement of EN50155/EN standard

Cisco Nexus Data Broker for Network Traffic Monitoring and Visibility

Cisco Certified Network Associate ( )

Gigabit Managed Ethernet Switch

CMPE 150 Winter 2009

Configuring STP and RSTP

Configuring RRPP. Overview. Basic RRPP concepts. RRPP domain

Designed, built, and tested for troublefree operation in extreme conditions

lecture 18: network virtualization platform (NVP) 5590: software defined networking anduo wang, Temple University TTLMAN 401B, R 17:30-20:00

isco Understanding Spanning Tree Protocol Topology Chan

The multiple spanning-tree (MST) implementation is based on the IEEE 802.1s standard.

Campus Networking Workshop. Layer 2 engineering Spanning Tree and VLANs

COMP211 Chapter 4 Network Layer: The Data Plane

CISCO EXAM QUESTIONS & ANSWERS

SDN-based Network Obfuscation. Roland Meier PhD Student ETH Zürich

Fault Tolerance for Highly Available Internet Services: Concept, Approaches, and Issues

Modular Policy Framework. Class Maps SECTION 4. Advanced Configuration

Bridging Traffic CHAPTER3

ZyXEL ES-2108PWR V3.80(ABS.1)C0 Release Note/Manual Supplement

SDN in TETRA Group Communication - Voice Switching

Rapid spanning tree protocol

GUIDELINES FOR USING DEVICE LEVEL RING (DLR) WITH ETHERNET/IP. PUB00316R ODVA, Inc. Page 1 of 18

Avnu Alliance Introduction

ISCOM2948GF-4C Intelligent Ethernet Service Aggregation

User Handbook. Switch Series. Default Login Details. Version 1.0 Edition

PassTorrent. Pass your actual test with our latest and valid practice torrent at once

Configuring Spanning Tree Protocol

DGS-1510 Series Gigabit Ethernet SmartPro Switch Web UI Reference Guide. Figure 9-1 Port Security Global Settings window

Adversarial Network Forensics in Software Defined Networking

VXLAN Overview: Cisco Nexus 9000 Series Switches

1Industrial Ethernet Switch

Cisco Implementing Cisco IP Switched Networks (SWITCH v2.0)

ISCOM RAX 711 (B) Ethernet Demarcation Device

DaoliNet A Simple and Smart Networking Technology for Docker Applications

Transcription:

Software-Defined Networking (SDN) Now for Operational Technology (OT) Networks SEL 2017

Traditional Ethernet Challenges Plug-and-play Allow all ROOT D D D D Nondeterministic Reactive failover Difficult to test Lacks cybersecurity profile R A A A D D R A Blocked ports

OT Network Goals Deterministic failover with fixed latency Distribute precise time Low latency and jitter Fast fault detection, isolation, and recovery Cybersecurity designed in Continuous monitoring, self-testing, and alarming Compliant with IEEE 1613 (rugged)

SDN Basics Traditional Ethernet Switch Individual Control and Data Planes at Each Node SDN Switch Centralized Control Plane, Individual Data Planes Traditional Switch Control Plane Data Plane Centralized Control Plane SDN Switch Data Plane

Traditional SDN Real-Time Control Decisions Rule SDN Switch IT Flow Controller 10% Server Rule SDN Switch 75% Rule SDN Packet Switch IED Packet

OT SDN Operation Decisions Already Made Rule SDN Switch OT Flow Controller Server Rule SDN Switch Rule SDN Switch IED Packet IED

Proactively Engineer Traffic for Reliability SEL-5056 Flow Controller SEL SEL-3355 SEL SEL-2740S X SEL Relay SEL SEL SEL-2740S X SEL SEL-2740S SEL RTAC SEL SEL-2740S Primary Path Backup Path Secondary Path

SDN Fast Failover Is Awesome! Product Topology Healing Method Failure Point Healing Time Manufacturer Device 1 10-Node Ring STA (Rapid-PVST) L4 97 ms Manufacturer Device 2 4-Node Ring STA (RSTP) L1 or L2 60 ms SEL-2730M 10-Node Ring STA (RSTP) L4 10 ms SEL-2740S 10-Node Ring SEL SDN Fast Failover L4 <100 µs

Getting to Know SDN Terminology Flow Single communications session that matches ingress rule and has a set of forwarding instructions OpenFlow A protocol with an open source standard that defines an interoperable way for switches and flow controllers to communicate for configuration and monitoring purposes Flow controller Central controller that programs switch flow tables

How SDN Works Control plane inspects each Ethernet packet and performs the following functions Match fields Match rule based on portion of Ethernet packet Instructions Perform one or more programmed actions Counters Increment counters and send counter data to centralized point

OT SDN Redefines Ethernet for Mission-Critical Applications Fast Deterministic Secure Simple Interoperable Visible

Multilayer Matching Rules Flow rules to only forward approved packets Capture packets that do not match rules Can add time element to make temporary flows SDN Flow Match Rule Port Layer 1 Ethernet Header Layer 2 IP Header Layer 3 TCP / UDP Header Layer 4 Payload

OpenFlow Match / Action Example Ethernet Hub Physical Port ID Src MAC Dst MAC Ether Type VLAN ID IPv4 Src IPv4 Dst TCP/UDP Src TCP/UDP Dst * * * * * * * * * Action Output Forward All (Flood) Packet 2 Packet OpenFlow Middlebox Packet 1 Packet3 4

OpenFlow Match / Action Example L2 Unmanaged Switch Physical Port ID Src MAC Dst MAC Ether Type VLAN ID IPv4 Src IPv4 Dst TCP/UDP Src TCP/UDP Dst 1 * * * * * * * Action 00:30:A7:06:11:97 Output Forward Port 4 2 Packet OpenFlow Middlebox Packet 1 3 4

OpenFlow Match / Action Example L3 Forwarding Physical Port ID Src MAC Dst MAC Ether Type VLAN ID IPv4 Src IPv4 Dst TCP/UDP Src TCP/UDP Dst 1 * * * * 1.1.1.2 2.2.2.2 * * Action Output Forward Port 3 Packet 1 2 OpenFlow Middlebox Packet 3 4

OpenFlow Match / Action Example Application Specific Forwarding Physical Port ID Src MAC Dst MAC Ether Type VLAN ID IPv4 Src IPv4 Dst TCP/UDP Src TCP/UDP Dst 1 * * * * 1.1.1.2 2.2.2.2 * TCP 20000 Action Output Forward Port 4 Packet 1 2 OpenFlow Middlebox 3 Packet 4

For Attackers, a Network Straitjacket No ability to accumulate ARP knowledge No ability to scan / probe the network No ability to use protocols or reach hosts not already configured First unrecognized packet goes straight to IDS!

Cybersecurity Benefits Security model Deny-by-default Secure control plane Eliminate MAC table and BPDU spoofing Situational awareness Know what flows are on your network and where they are all the time (packet and byte awareness)

Performance Benefits Integrate seamlessly with existing infrastructure OpenFlow 1.3 support Ensure mission-critical application performance <100 µs failover Efficiency No blocked ports

Future APIs Enable Solution-Focused Applications Application Layer Control Plane OpenFlow Data Plane OAM Applications Network Visualization Configuration Programming Network Operating System Simple Packet- Forwarding Hardware Simple Packet- Forwarding Hardware Simple Packet- Forwarding Hardware GUI Flow creation Visibility Continuous monitoring Policy enforcement IDS / IPS / inspection Syslog

DOE-Sponsored Application: Chess Master Deny-by-default, whitelisted traffic engineering Multiple proactively engineered security and methods to quickly transition automatically or manually OpenFlow counters to know what is on the network

Available Now www.cyberscoop.com www.linkedin.com

Accelerate Evaluation and Adoption SDN evaluation kit (Part Number 915900421) Four SEL-2740S Switches SEL-5056 Flow Controller SEL-3355 Computer Ethernet cables Application support

More Information Visit SEL in Booth 304 Website: https://selinc.com/products/2740s/ Email: security@selinc.com