Cyber Shield
Presented by: Dennis Murphy Director, SCADA Cybersecurity Elbit Systems
Fides SCADA Anomaly Detection System Has Your Six
Elbit Systems Corporate Snapshot Elbit Systems of America is a wholly owned subsidiary of Elbit Systems Ltd. (ESL): A leading global source of innovaQve, technology-­‐based systems for diverse defense and commercial applicaQons. q 
Israeli-based, multi-domestic
defense electronics company
Publicly traded on NASDAQ and
Tel Aviv stock exchange (ESLT)
Annual revenues: $2.9B
13,000 employees across 13
Europe 25% USA 30%
History repeats itself… World War II A new dimension on the battlefield The evolution of protecting against air warfare Comprehensive Defense Maturity THREAT IS RUNNING WILD German Army – Luftwaffe - launches high level bombers INADEQUATE PREVENTION Barrage balloons of little use against high-level bombers OUT OF CONTEXT, SILOED DETECTION Radar is able to warn but not defeat the threat INTEGRATED DETECTION, MITIGATION & CONTROL Integrated War rooms with detection and mitigation The evolution of protecting against advanced cyber threats Comprehensive Defense Maturity THREAT IS RUNNING WILD APTs are well-targeted, with multi-surface attacks INADEQUATE PREVENTION Anti-virus, firewalls and traditional prevention techniques are inadequate OUT OF CONTEXT, SILOED DETECTION Siloed detection capabilities cannot effectively stop the threat in time INTEGRATED DETECTION, MITIGATION & CONTROL Centralized cyber operation that facilitate integrated early detection, effective response, people and policies Market Trends and Challenges
"There is no such thing as 100% prevention and there never will be" - Gartner 2014. Companies worldwide spend an estimated $12 billion on basic cyber-crime prevention. Stand alone prevention is inadequate. Too many high priority alerts - 10,000 alerts per hour with no actionable insight. 20 days alert went unchecked before breach announcement. "Those alarms [should] have been impossible to miss, they went off early enough that the hackers hadn't begun transmitting the stolen card data out of Target's network"
Why traditional prevention doesn't work THE GREY ZONE Green Light Red Light
Red Light
APT – they play in the grey: Injections, Dropper, Creating new process, Screen shots, Close process, Driver load Why traditional prevention doesn't work Hacker Red Light
Red Light
APT – they play in the grey: Injections, Dropper, Creating new process, Screen shots, Close process, Driver load Blacklist
There is a seismic shift to detection. Enterprise information security budgets allocated to rapid detection and response: 10% in 2014, 60% in 2020. Enterprises with a security data warehouse: 5% in 2015, 40% in 2020. Over the next 5 years there will be a significant shift to rapid detection and response approaches.
Elbit Cyber Security Portfolio: Context-aware detection & mitigation for actionable insight. Technologies & tools - Advanced technology for full range of cyber threats. Policies, practices, procedures - Holistic approach to protecting your organization. Trained personnel - Cooperation, collaboration, intelligence. Trained professionals equipped for dynamic threat. Leverage wider "community" for enhanced protection.
Shield AnD
AnD for IT
Cyber Shield Context-aware cyber threat detection & mitigation for actionable insight. Intelligent holistic view of advanced cyber threats across multiple types of infrastructure for early detection and effective response to protect isolated and semi-isolated networks. 
Cyber Shield AnD (Analysis Detection): Event management, Situational awareness, Contextual Impact Engine, SOC Manager. Anomalies detection of behavioral patterns. Cross domain correlation. Cyber Shield Sensors
Detect local anomalies. Smart data collection. CS-ICS (SCADA) External Prevention
PrevenQon CS-­‐IT
CS -­‐ Weapon Systems Mapping & Assessment IT infrastructure
CS-­‐Mobiles SIEM
IT infrastructure enrichment
CyberShield AnD SCADA
(Analysis & Detection)
Protecting Critical Infrastructure
SCADA Networks • 
Most critical networks are geographically dispersed.
The applications and protocols used in the SCADA network were designed without security.
All security measures are aimed to isolate the control network from the enterprise – but in reality, interconnectivity is increasing.
Good news – SCADA networks tend to be more deterministic and predictable, especially at the protocol level.
Solution Goal: Monitoring and APT detection system of Independent SCADA/DCS network. Reliability, Visibility, Control, Safety, Security, Compliance.
modular computing nodes
Distributed architecture scalable up to
hundreds of monitoring appliances per
server installation
Passively monitors the SCADA network
traffic without reconfiguring or
redesigning the existing network
The sensors are capable of monitoring
RS-232 and RS-485 network protocols
such as Profibus and IEC-101
Cyber Shield AnD for SCADA – Typical Deployment Control Center
Enterprise Management
Corporate LAN
Syslog \ SNMP
SCADA Server
AnD Server
Syslog \ SNMP
CommunicaQon Backbone
Vlan\Inline\Separate Physical Network
SCADA Network
Remote SCADA Network
Mirror\Tapping port Ethernet\Serial
AnD Blackbox
SIEM / Incident Management
AnD Components
ExisQng System
Cyber Shield AnD for SCADA – Operation Network Forensics SCADA Alerts
SCADA Alerts
Built-in client application for network
Summary list of all alerts
All SCADA network traffic is logged in a
central relational database for historical
analysis and correlation
Columns can be selected and advanced
filters set in place to perform advanced
network forensics
Export capability to rebuild the pcap files
for a defined event or time period
List can be filtered to find relevant
Allows for advanced analysis of
suspicious traffic anomalies
White List Rule Definition
Enables the user to manually or automatically
define rules on what transmissions are allowed
in the network, a relatively simple definition in
SCADA networks.
Monitors on all layers from physical (MAC) to
application-specific data (process data values)
Supported Protocols DF1
Cyber Shield
leads the market with the
most comprehensive
support for SCADA
Profinet/Profibus , Teleperm XP, TIM MDLC / MDLC over IP
Cyber Shield AnD for SCADA – Unique Offering AnD for SCADA – a full
suite of features
Complete Packet logging
for forensics
Context aware alerts
Passive Connectivity
Core Inspection
The only solution
providing legacy serial
inspection integrated
with TCP/IP inspection
Connectivity to
CyberShield provides
context aware
intelligence driven
response to enterprise
cyber security
CyberShield TnS
(Training & Simulation)
Cyber Shield Training and SimulaQon
An Enterprise level trainer - enabling the organization to train the Cyber Defenders and simulate
complex scenarios on the specific IT and SCADA networks
Simulating multistage, highly
advanced APT
Maximizing the
awareness and
improving the skills
of the cyber
Automatic attack machine - generating real-life scenarios training all the various Cyber
Defenders roles. Focused on accurately simulating multi-stages, multi-vectors, Cyber
attacks on the enterprise. Reflecting the real - operational network environment,
including IP and SCADA networks
Thank You!
February 2015
