What About Whitelisting?

March 31, 2012
One security tactic gaining momentum in the industrial sector is whitelisting. This security method involves a layer of security that only allows pre-approved applications to run on the system. No exceptions.

Brian Ahern, president and CEO, Industrial Defender (www.industrialdefender.com), says that “if we can run whitelisting on the mission critical server side, that allows us to address gaps from a patching perspective, because vendors can’t certify an operating system patch fast enough.” These patches usually takes six months to develop before they are ready for release.

Though whitelisting is an effective strategy for control system security, industry is still very early in its adoption of this tactic. Fewer than 5 percent of Industrial Defender’s customers have adopted this approach, but Ahern says there is increasing interest in it.

The downside to whitelisting, according to Ahern, is that it is “fairly invasive and does require compatibility and interoperability testing with the OEM vendor. As soon as you only allow certain applications to run, you need to understand the DLLs, executables, and what’s happening on a mission critical server so that, if it spawns another DLL, you’ll be able to understand that it’s allowed.”

>> Click here to read Automation World's full report: The Stuxnet Effect on Cyber Security

Companies in this Article

Sponsored Recommendations

Wireless Data Acquisition System Case Studies

Wireless data acquisition systems are vital elements of connected factories, collecting data that allows operators to remotely access and visualize equipment and process information...

Strategizing for sustainable success in material handling and packaging

Download our visual factory brochure to explore how, together, we can fully optimize your industrial operations for ongoing success in material handling and packaging. As your...

A closer look at modern design considerations for food and beverage

With new and changing safety and hygiene regulations at top of mind, its easy to understand how other crucial aspects of machine design can get pushed aside. Our whitepaper explores...

Fueling the Future of Commercial EV Charging Infrastructure

Miguel Gudino, an Associate Application Engineer at RS, addresses various EV charging challenges and opportunities, ranging from charging station design strategies to the advanced...