Cybersecurity Startup Focuses on Industrial Networks
Over the past two years, weāve noticed a clear uptick in interest in the topic of industrial cybersecurity among Automation World readers. Along with this increasing interest, thereās been a corresponding increase in the number of suppliers entering the marketplace to address industryās need for greater security.
The most recent entrant into the space is Claroty, whose cybersecurity platform was designed to secure and optimize operations technology (OT), i.e., plant floor, networks. The company heavily promotes its OT origins and focus, saying: āWeāre not just fluent in every protocol, weāre OT native speakers. We were born and raised in the world of Modbus, Profibus and DeviceNet. We think in S7 and dream in DNP3. We go beyond Ethernet/IP into the realms of the most arcane fieldbus and serial protocols. No corner of the ICS network is dark to us and no event remains misunderstood.ā
Clarotyās software reportedly creates a detailed inventory of an end userās industrial network assets, monitors traffic between those assets, and analyzes communications at their deepest level on the network. Detected anomalies are reported to plant and security personnel with actionable insights to help enable efficient investigation, response and recovery.
āThe Claroty platform can detect a bad actorās activities at any stage, whether theyāre trying to gain a foothold on a network, conduct reconnaissance or inflict damage,ā said Amir Zilberstein, co-founder and CEO, Claroty. āIt also can detect human errors and other process integrity issues, which are often more common than threats from bad actors. For example, the software monitors for critical asset changes that, if done incorrectly, could result in unexpected downtime. The system also identifies network configuration issues that could expose a system to outside threats.ā
Following a lengthy competitive review process, Rockwell Automation selected Claroty for network anomaly detection in large part due to it being purpose-built for industrial network security. The companies are now working together to combine their security products and services into packaged security offerings for future release. Claroty has also joined the Rockwell Automation Partner Network Encompass program.
At the ARC Forum 2017 event, I met with Patrick McBride, chief marketing officer of Claroty, and Umair Masud, manager of consulting services portfolio at Rockwell Automation, to discuss the partnership between the two companies.
Rockwell Automation has been āworking on cybersecurity mitigation with hardware products and features within software for the past five to 10 years,ā said Masud. āWe have a defense-in-depth approach because we know you can't rely on just one security control.ā He added that Rockwell chose to work with Claroty because it wantedĀ a more active defense āto increase visibility into the operations environmentāsomething that can see the makeup of your system and how it interacts to identify what actions are normal and what actions arenāt.ā
Masud also noted that Rockwell Automation wanted software that would work passively on the network. The difference between passive and active network monitoring comes down to this: Active monitoring places test traffic on a network to monitor the traffic; passive monitoring simply monitors the traffic on the network without adding to the traffic. Passive monitoring is the preferred approach for OT networks so as not to disrupt critical communications between the controllers, actuators and other devices on the network.
āWe also wanted the solution to be agnostic in nature, regardless of the supplier source.Ā Thatās why we chose Claroty,ā Masud said.
āOur design principle number one is to do no harm,ā said McBride, in reference to Clarotyās passive monitoring capability. āThe length and breadth of coverage we provide over TCP/IP, serial and protocolsĀ allows us to deliver a fine-grained model to detect network anomalies,ā he added.
Clarotyās alerting method was also highlighted by McBride. āMost cybersecurity software provides an events stream; our alerts are specific to what happened and are delivered in plain language to increase the situational awareness of the operator,ā he said.
The starting point of a Claroty alert is a description of whatās happening, said McBride. For example, it will tell you if someone at a workstation tried to change a specific PLC at that workstation. āWeāre focused on reducing mean time to resolution; we want to find anomalies faster and better and resolve the problem more quickly. The additional, situational context Claroty provides helps direct a fast remediation process.ā
About the Author
David Greenfield, editor in chief
Editor in Chief

Leaders relevant to this article:

