Energy Central EnergyPulse Home
Home Subscribe Login Contribute to Energy Pulse Advertise on Energy Pulse About Energy Pulse Feedback to Energy Pulse
Search Articles:   
  You are here: Home > Grid Operations > Article Display


Free Newsletter
Sign up today for your free subscription to the EnergyPulse Weekly Update - delivered directly to your e-mail box.
e-mail:


 

Communicating Smart Meter Value

Sep 9 2010 - 2010-01-01 12:00:00 - Your City

If you are involved in Management or Customer Service and are responsible for communicating the value of smart meters to your utility customers, you don’t want to miss this online discussion - Communicating Smart Meter Value.  more...

Social Media: The new frontier in recruiting, communications and marketing

Sep 13 2010 - 2010-01-01 12:00:00 - Your City

Join social media mavens Matthew Burks and Amanda Shewmake as they provide an insider's perspective on how HR, communications and marketing professionals in energy companies can harness the power of social media to be more effective and productive. more...

Eliminating Obstacles and Delivering the Benefits of the Smart Grid - IBM's Optimized Energy Value Chain (OEVC)

Sep 14 2010 - 2010-01-01 12:00:00 - Your City

The convergence of power and information technologies in the smart grid has created opportunities for finer grained and broader controls of energy flows. These opportunities can improve electric service in multiple dimensions: lower cost, greater reliability, greater customer satisfaction, and more...

Achieving Operational Excellence - What to Consider Before Implementing or Upgrading Your Distribution Management Solutions

Sep 16 2010 - 2010-01-01 12:00:00 - Your City

Significant cost over runs. Changing business requirements. A well thought out plan is essential. Attend this free webcast discussion to hear inside hear three experts in utility operations discuss what utilities need to evaluate when they are considering upgrading or more...

Outsmarting the Smart Grid: IT, Security and Communication Infrastructure  Challenges & Opportunities for Utilities

Sep 21 2010 - 2010-01-01 12:00:00 - Your City

The smart grid is shifting the playing field for utilities. And when the game changes, it pays to be prepared. A nimble solutions partner can help you design the solutions that keep operations on track, even as new challenges come more...

1st CSP Today Concentrated Solar Thermal Power Summit India

Sep 7 2010 - Sep 8 2010 - New Delhi India

Deliver a profitable, productive and commercially successful large scale CSP business in India. Building on the success of past events in USA, Europe & MENA, CSP Today brings to New Delhi the most relevant international experience for the concentrated solar more...

Offshore Wind Energy in North America's Great Lakes Conference

Sep 9 2010 - Sep 10 2010 - Toronto

Two day conference that tackles the most important challenges. A blend of European knowledge from the companies who have been installing offshore wind turbines for the last decade alongside local state governing bodies and leading project developers. Permitting, securing long more...

Autovation 2010

Sep 12 2010 - Sep 15 2010 - Austin, TX - USA

Autovation 2010 is a not-to-miss educational forum that will attract utility executives from around the world looking for new ways to optimize their operations through automation technologies. more...

Global Sustainable Bioenergy North American Convention

Sep 14 2010 - Sep 16 2010 - Minneapolis, MN - USA

The North American convention provides a remarkable opportunity to play a part in guiding renewable energy policy for the 21st century. Attendees will create a resolution that, along with similar resolutions already drafted on four other continents, will help set more...

GridWise Global Forum

Sep 21 2010 - Sep 23 2010 - Washington, DC - USA

Hosted by the GridWise(R) Alliance and the U.S. Department of Energy, the GridWise Global Forum will convene thought leaders from the highest levels of government, business, NGOS, and academia from around the world to discuss the ultimate enabling potential of more...

1. Intro to Nat Gas Trading & Hedging 2. Option Applications in Energy

Sep 20 2010 - Sep 23 2010 - Houston, TX - USA

Introduction to Natural Gas Trading & Hedging - This program provides a comprehensive understanding of the structures that underlie Natural Gas trading. Beyond Essentials: Option Applications in Energy - This course provides a solid practical and conceptual (non-quantitative) understanding of more...

Electric Business Understanding Seminar

Sep 20 2010 - Sep 21 2010 - Houston, TX - USA

Electric Business Understanding provides a comprehensive overview of the electric industry. Position yourself for career advancement by gaining a solid understanding of how the electric business works including key physical, market, and regulatory aspects and how market participants navigate this more...

Electric Market Dynamics Seminar

Sep 22 2010 - Sep 23 2010 - Houston, TX - USA

Electric Market Dynamics offers participants an in-depth understanding of North American electric markets and how they function. Enhance your career by furthering your knowledge of market structures, pricing mechanisms, services offered in markets, and how various participants use the markets more...

Gas and Electric Business Understanding Seminar

Oct 5 2010 - Oct 6 2010 - Los Angeles, CA - USA

Gas and Electric Business Understanding provides a comprehensive overview of the natural gas and electric industries. Position yourself for career success by gaining a solid understanding of how each business works, including key physical, market and regulatory aspects, as well more...

Energy Central
Power Network




Grid Operations


We know you have something to say!
There is an immediate need for articles on the hot topics in the Power Industry! EnergyPulse, like no other publication, also provides a means for our readers to immediately interact with experts like you.
 
Contribute Today!
Please view our Author Guidelines and send submissions to the editor.

Click For More Articles on Grid Operations
 
Application Whitelisting and Energy Systems: A Good Match?
4.1.09   Toney Jennings, President and CEO, CoreTrace Corporation

Article Viewed 3680 Times
2 Comments
E-mail Article Printer Friendly
 
  • Email This Author
  • Comment On Article
  • About The Author
  • More Articles By This Author

    Part I of this two-part article will discuss the technology behind application "whitelisting."

    A new security technology has emerged that can provide a heightened degree of security for energy industry information and control systems. Application whitelisting takes the traditional approach of the antivirus vendors and turns it 180 degrees. Rather than constantly maintaining a blacklist of malicious software that can get loaded onto a computer system, why not just maintain a whitelist of the authorized applications that are installed and make sure it doesn't change?

    This article is broken into three basic sections. With any given security technology, the strength of the solution is always in the implementation. The first section describes the short history of application whitelisting and provides a detailed perspective on how the technology works. The second section discusses the use of whitelist technologies in a SCADA and Energy environment and how it can help solve unique security challenges. The third and final section provides some perspective on how this technology is adapting to function in a constantly changing environment where software changes are always needed.

    <

    b>The Technology

    In the late 1990s, the concept of application whitelisting began to emerge. It became evident that the antivirus and anti-malware companies were having an increasingly difficult time keeping up with all the rogue software appearing on the Internet. Their products began to bloat with larger and larger databases of bad programs and the impact on the protected system became more intrusive, consuming time and resources. What if the IT staff could install known software on a system and somehow keep it in that tested, functional configuration without allowing viruses and malware to run? The term applied to this security approach is application whitelisting. Rather than look for bad software off a list of 'blacklisted' applications and stop it from running, this new technology looks at a list of good or 'whitelisted' software and allows only it to run.

    The concept of tracking which software is fundamental to configuration management. There have been many configuration management systems over the years that simply used the file pathname and date to ensure the proper file was in the proper place on any given computer. Over time, additional technologies have surfaced to aid in identifying the files and ensuring they have not been unintentionally corrupted. These began as simple checksums and have evolved into ever more complex cryptographic algorithms to include MD5, SHA-1, and SHA-2 families. The first step toward application whitelisting had begun, years before the concept was even introduced.

    The Fundamentals

    While there are many challenges to designing an application whitelisting solution, all solutions need to enforce a list of approved applications and then enable an efficient, IT-friendly change process for the addition of new and updated applications. Not including the management of the solution, which will be discussed later, each whitelisting solution must have three fundamental capabilities. First and foremost, it requires a way to securely and efficiently enforce the whitelist on the computer. Second, it must have a way of building or acquiring the whitelist of applications for any given computer. And third, it must have the ability to report any attempts to violate the security policy it is enforcing. These three capabilities together provide the security required to protect the computer, while at the same time reporting on system status.

    In leading products, the whitelist enforcement mechanism is in the form of a tamper-proof client installed on each computer. It is very important that the enforcement provided by this engine cannot be circumvented by either the local user or a malicious user or program with network access. To this end, the client installed on the computer must function in the operating system kernel. Through tight integration with the operating system, the solution is able to protect the system and have greatest efficiency -- it essentially functions as part of the operating system rather than as an add-on security feature. From within the operating system kernel, the client reads in the whitelist or policy, and ensures that only those applications on the whitelist are allowed to run. The process begins during boot time when the operating system is starting. The client is loaded as early as possible and then reads in the whitelist; it can then check all the executables that loaded before and after itself to ensure they are all authorized. Once the computer is up and running, the client only performs checks when a new application or process attempts to start. From within the operating system, this is very quick with no delay perceived by the user. And because the whitelist is small compared to the massive blacklists in today's antivirus products, the amount of memory, disk space and CPU consumed by the client is also small.

    The application whitelist is what makes this security solution unique. There are many different approaches to produce the list and also many different technologies that may be involved. Experience using this technology has shown that no two computers are exactly alike, so there is rarely a match of whitelists across platforms. For example, orders placed with any major computer manufacturer for computers with identical specifications will have slightly different executables due to variations in chipsets on motherboards, network cards, video cards, memory and so forth. Thus, the whitelist must be assembled for each computer individually. Leading solutions perform this automatically, scanning the computer and building the whitelist. As part of building the whitelist, the client collects a series of parameters to uniquely identify each executable file. These can include the pathname, digital digest, size, digital certificate if it is signed by the vendor, or other identifiers. As mentioned previously, it is the checking of some combination of these parameters by the client during application startup that determines the file has not been modified and is allowed to run. And finally, it is important the security of the whitelist itself is maintained. The whitelist is generally stored in an encrypted and digitally signed file that only the client can decrypt and verify.

    Although a good whitelisting solution will prevent unauthorized applications from running, it is important to monitor and capture related activity from the computer. This activity can take a number of forms. The whitelisting solution can log attempts to overwrite, possibly trojanizing, protected applications on the computer. Likewise, it can log attempts to run unauthorized applications that may have been copied onto the protected system. The whitelisting solution can provide insight into whether this is a local attack initiated on the computer itself or if this is activity from across the network. In addition to basic policy or whitelist violation attempts, the solution logs administrative activity related to managing the whitelist itself. Events here include administrative actions like uninstalling and reinstalling the client on the computer. All these events can be used for client verification and reporting.

    Secure Management

    Application whitelisting is designed and architected to be an enterprise solution. The fundamental capabilities previously described for an individual computer must be centrally managed to make it cost-effective for deployment and long-term management. Fundamental to any enterprise management system today and with limited IT resources to run it, the system must be secure, intuitive, and require minimal training. More importantly, the system must be able to automatically -- without requiring IT involvement -- update the whitelist whenever new applications are added or existing ones are upgraded. Application whitelisting without the ability to handle change is simply lockdown.

    Most application whitelisting systems use a dedicated central server or management appliance to maintain information about and communications with endpoint clients. Command and control of the protected computers must be over a secure channel. This can be accomplished via SSL or a more secure and robust IPSec connection. The communications between the client software and the management appliance must provide some form of authentication, to ensure the client is not spoofed into communicating with a rogue management system. This authentication is typically performed using some form of digitally signed certificates. In addition to management system-to-client authentication, the communications channel itself must be encrypted for confidentiality of information. This prevents easy interception and analysis of configuration changes, security events, and so forth, carried by the communications channel.

    During the initial setup of the client, the vast majority of information exchanged will be whitelist related, where the list is assembled and the overall protection policy built in and applied on the client. Once the policy is in place, the channel is mainly event information sent from the client and collected on the management system. At the central point of the management system, events from all protected endpoints are collected and compiled. Because configuration of all clients is conducted from the central system, these events are easily logged as well. The management system can assemble both the security and configuration-related event information into reports for additional analysis or to meet compliance requirements. Event or configuration information may also be distributed off of the management system in the form of syslog messages for compilation and analysis on other third-party systems.

    The management system provides checks and balances on the protected endpoint systems. It contains a copy of the whitelist that is enforced by the client on the endpoint. It is constantly checking that the whitelist has not been either accidentally corrupted or illegally modified. When a laptop or desktop computer leaves the network for some length of time and then reconnects, the management system can verify the policy has not been modified while offline. Once they reconnect, the policies are immediately updated. Policy changes are securely transmitted to the newly connected client, the whitelist is unencrypted, and the policy is immediately loaded and enforced by the client without rebooting the system.

    The user interface on application whitelisting management systems can take several forms. Some use a web-based browser back to the system which can introduce security issues by itself. Dedicated console appliances are available to interact with the management appliance or central server. And some solutions offer remote desktop protocol (RDP), opening a secure channel between the management system and a remote computer or laptop. This final option provides the greatest flexibility while maintaining security for the overall system. The interfaces themselves vary greatly in terms of look and feel, but all strive for ease of use with an intuitive workflow.

    Part II of this article will deal with whitelisting's applications in SCADA and other energy industry security systems.

    For information on purchasing reprints of this article, contact Tim Tobeck ttobeck@energycentral.com.
    Copyright 2010 CyberTech, Inc.
     
    Contact The Author
    Email the author
    E-mail Article Printer Friendly
     
  • Click Here For More Articles on Grid Operations


  • Click Here For More Articles By Toney Jennings
  • Do you agree or disagree with this article? Send in your own article.

     

    Readers Comments

    Date Comment
    Bassem Muhi AL-Din
    4.2.09
    Dear Sirs,

    I hope that this message will find you well. I'm very much interested in applying for the job opening in your organization.

    Kindly find attached a copy of my resume.

    Should you need any further information regarding my past experience, please do not hesitate to contact me.

    Yours,

    Bassem M. Al Katheeb

    Mobile: +32 487 594 702

    Land Line: +32 42 762 806

    E-mail address: bmmd67@yahoo.com

    Bassem Muhi AL-Din
    4.2.09
    Personal Information

    Name: Muhi Al-Din Bassem Mohammed Address: Rue Doumier, 10 4430 ANS Liège – Belgium Gsm: +32 487594.702 Landline: +32 42762806 E-mail: bmmd67@yahoo.com , bmmd1967@hotmail.com Place of Birth: Baghdad – Iraq Date of Birth: 1-1-1967 Marital Status: Married – 3 children Current Residency Nationality Status: Political refugee in Belgium with valid travel document

    Membership: Iraqi American chamber of commerce and industry Education Year Educational institution Level 1985 College of Baghdad Upper secondary studies (Including mathematics, chemistry, Physics, Zoology) 1988 Petroleum Training Institute of Baghdad Baccalaureate + 3 Measurement and control (Including engineering drawing, mathematics, electronic s, electrical technique, Industrial safety)

    Professional Experience Period Firm / Sector / Function Duties Nov 2004 – August 2006 Zagros Company / Executive Director Technical team management and installation of IT materials Apr 2003 - Aug 2006 Ministry of science Technology / Technical Manager Work with pipeline & Hazardous materials safety Administration electronic services 1998 – Apr 2003 National Committee of Technology Transfer / Librarian Management of Scientific database reporting Nov 1988 – Apr 2003 Iraqi Atomic Energy Organization. Technician / Full time Maintenance of Nuclear centrifuge and helicon process

    Languages Language Fluency Arabic Mother tongue English Fluent spoken, good written

    Computer Literacy Software Category O. S. MS windows XP, Millennium, Windows 98 Word Processor Microsoft word Spreadsheet Basics of Microsoft Excel Database Microsoft Access Other Power Point, Internet explorer

    Add your comments:
    Please log in to leave a comment!

    Top

        Home | Register | Subscribe | Contribute | Advertise | About Us | Feedback
       Copyright © 2002-2010, CyberTech, Inc. - All rights reserved. Read our Terms of Service.