How Is Industrial Security Evolving in the Age of AI Factories?... Cybersecurity Past and Future Based on IEC 62443
TECHWORLD ·
✦ AI Summary
U.S. cybersecurity authorities have identified Siemens S7-series PLCs as potential targets and urged stronger security measures.
In industrial sites, AI and digital technologies are expanding into production planning, quality inspection, predictive maintenance, and energy optimization, while converging with digital twins, IIoT, and cloud platforms.
IEC 62443 is presented as a security framework that considers the full lifecycle of ICS, and the field is said to need systematic design and management of Asset Visibility, network segmentation, access control, and operational processes.
As cyber threats targeting key industrial site equipment have recently emerged, U.S. cybersecurity authorities have identified Siemens S7-series PLCs as potential targets and urged stronger security measures.
PLC is a core device that directly controls factory production equipment and industrial machinery. If this device is exposed to cyberattacks, it can lead to information leaks, and it can also cause operational shutdowns and production disruptions.
At the same time, AI and digital technologies are spreading across industrial sites. AI is expanding its scope across manufacturing processes, including production planning, quality inspection, predictive maintenance, and energy optimization.
These AI and digital technologies are converging with digital twins, industrial IoT (IIoT), and cloud platforms. As a result, industrial sites are entering the era of the 'AI Factory.'
The sharp increase in connectivity in ICS is driving higher productivity and greater operational efficiency. However, increased connectivity also expands the cyberattack surface.
In the past, many OT environments were operated as externally separated, closed networks, but today MES, ERP, cloud platforms, remote maintenance systems, and AI analytics platforms are connected in a single data flow. Amid this shift, manufacturing has recently seen increases in ransomware, supply chain attacks, and stolen remote-access accounts, and the expansion of OT integration is cited as a background factor behind the rise in attacks on manufacturing.
As the environment changes, the role of industrial security is also expanding. Industrial security is emerging as a key element not only for protecting equipment, but also for ensuring business production continuity and safety.
As a response standard, 'IEC 62443' is gaining prominence as the representative international standard for industrial security. Rather than prescribing a specific security solution, IEC 62443 takes the form of a security framework that considers the full lifecycle of ICS, and its scope of application covers design, construction, operation, and maintenance.
Security concepts related to IEC 62443 are now used as basic design principles in most smart factory projects. Representative concepts include Zone & Conduit-based network segmentation, defense in depth, the principle of least privilege, and security level definition.
The application of this IEC 62443-based security architecture is expanding across various domestic industries. Industries seeing broader adoption in Korea include automotive, semiconductors, batteries, power plants, offshore wind, and data centers.
However, simply applying the standard does not immediately secure a high level of security. In actual field settings, vulnerabilities remain, such as inaccurate understanding of OT assets, flat network structures, and unmanaged partner remote access.
Accordingly, what matters is the systematic design and management of Asset Visibility, network segmentation, access control, and operational processes.
Based on a basic security framework, the next stage of industrial security is expected to move toward a zero-trust-centered model and AI-based security operations. Accordingly, the principle of access control is presented as allowing access only to the resources needed. In addition, the scope of continuous trust verification is expected to expand beyond user authentication to OT equipment such as PLCs, HMIs, and industrial PCs.
In this process, the importance of continuous trust verification for OT equipment and a minimum-access-allowance framework is increasing. Micro Segmentation is presented as having the effect of limiting the spread of attacks from compromised devices across the entire production network. This is presented as a change aligned with applying access control that does not assume trust to industrial environments.
A major change is AI-based OT security operations. AI is presented as playing a role in analyzing network traffic and industrial protocols in real time, detecting abnormal behavior and abnormal communications, and carrying out responses by threat level. In addition, an intelligent security operations framework consists of Asset Visibility, Deep Packet Inspection: DPI, AI-based anomaly detection, and SOAR(Security Orchestration, Automation and Response), and this integrated intelligent security operations framework is expected to expand.
The competitiveness of an AI Factory cannot be judged by the level of production equipment automation alone. Factors such as safely operating a connected and intelligent production environment, and reliably operating a connected and intelligent production environment, are also important as criteria for judging AI Factory competitiveness.
The direction industrial security should take to meet these demands is presented as being based on IEC 62443. It is also presented as combining zero trust, AI-based security operations, and continuous Asset Visibility.
Source: TECHWORLD · Park Sung-gu, Esnet Systems AIoT Innovation Technology Team Executive Vice President
Original: https://www.epnc.co.kr/news/articleView.html?idxno=406918
References
This article was produced with the help of an automated content generation algorithm.
Source: TECHWORLD
View originalThis article was summarized and organized by BizCrush based on the original article from TECHWORLD. For exact quotations and full details, please refer to the original article.