Energy Central EnergyPulse Home
Home Subscribe Login Contribute to Energy Pulse Advertise on Energy Pulse About Energy Pulse Feedback to Energy Pulse
Search Articles:   
  You are here: Home > Grid Operations > Article Display


Free Newsletter
Sign up today for your free subscription to the EnergyPulse Weekly Update - delivered directly to your e-mail box.
e-mail:


 

Biofuels: The Promise of the Next Generations

Feb 10 2010 - 1:00 PM Eastern - Your location

The second wave of biofuels such as cellulosic ethanol, algae and others bypass the food vs. fuel controversy and are on the cusp of commercialization. This webinar will review the latest developments in the advanced biofuel space with leading companies more...

Conducting a distributed chorus

Feb 17 2010 - 12:00 Eastern - Your City

Join Intelligent Utility managing editor Kate Rowland, along with a panel from PHI including Rob Stewart, manager of technology evaluation and implementation, and Todd McGregor, AMI director, for an interactive discussion about this company's work to build a more intelligent more...

21st Century T&D: Building the Transmission Piece of Smart Grid

Feb 18 2010 - 12:00 Eastern - Your City

Join industry leaders and Marty Rosenberg, Editor-in-Chief of EnergyBiz magazine, for an interactive discussion about the critical relationship between transmission and distribution (T&D) investment and smart grid success. As the energy enterprise gets smarter toward the consumer end with smart more...

Transforming the Electrical Grid: Addressing Transformation Strategies to Implementing A Smart Grid

Feb 25 2010 - 3:00-4:00pm Eastern - Your City

This webcast should be attended by those individuals that are responsible for identifying, planning and evaluating Smart Grid solutions, including those that empower and engage consumers and are easily assimilated with existing or new technology and business processes. more...

Smart Grid Revolution

Feb 18 2010 - Feb 19 2010 - AUSTIN, TX - USA

ACI's Smart Grid Revolution February 18-19, 2010 A two day strategic event bringing together utility professionals, government & state officials & consultants involved in deployment of the smart grid. To learn strategies which will improve energy efficiency programs & operations, more...

EnergyBiz Leadership Forum 2010: Energy's Emerging Architecture

Feb 28 2010 - Mar 2 2010 - Washington, DC

In 2009, a global economic meltdown collided with an energy crisis to turn the world on its ear. In the United States we've witnessed an unprecedented spending on energy resource development and infrastructure. As a result, a new energy architecture more...

CERAWeek 2010

Mar 8 2010 - Mar 12 2010 - Houston, TX - USA

CERAWeek, IHS CERA's 29th Executive Conference, is recognized as a leading forum offering insight into the energy future. Each year senior policymakers, energy and power executives, and financial and technology leaders from over 55 countries engage with CERA experts in more...

2nd Annual Thin Film Solar Summit Europe

Mar 17 2010 - Mar 18 2010 - Berlin Germany

The conference will provide a comprehensive analysis of the thin film industry and its key challenges in an interactive manner. Leading companies will share their experiences through panel debates and high-level presentations. A great opportunity to network with the whole more...

Gas and Electric Business Understanding Seminar

Feb 24 2010 - Feb 25 2010 - New York, NY - USA

Gas and Electric Business Understanding provides a comprehensive overview of the natural gas and electric industries. Position yourself for career success by gaining a solid understanding of how each business works, including key physical, market and regulatory aspects, as well more...

Gas Business Understanding Seminar

Mar 1 2010 - Mar 2 2010 - Houston, TX - USA

Gas Business Understanding provides a comprehensive overview of the natural gas industry. Position yourself for career advancement by gaining a solid understanding of how the gas business works including key physical, market, and regulatory aspects and how market participants navigate more...

Electric Business Understanding Seminar

Mar 3 2010 - Mar 4 2010 - Houston, TX - USA

Electric Business Understanding provides a comprehensive overview of the electric industry. Position yourself for career advancement by gaining a solid understanding of how the electric business works including key physical, market, and regulatory aspects and how market participants navigate this more...

Gas Market Dynamics Seminar

Mar 3 2010 - Mar 4 2010 - Houston, TX - USA

Gas Market Dynamics offers participants an in-depth understanding of North American natural gas markets and how they function. Enhance your career by furthering your knowledge of market structure, supply and demand, services offered in gas markets, and how various participants more...

Energy Central
Power Network




Grid Operations


We know you have something to say!
There is an immediate need for articles on the hot topics in the Power Industry! EnergyPulse, like no other publication, also provides a means for our readers to immediately interact with experts like you.
 
Contribute Today!
Please view our Author Guidelines and send submissions to the editor.

Click For More Articles on Grid Operations
 
Application Whitelisting and Energy Systems: A Good Match?
4.1.09   Toney Jennings, President and CEO, CoreTrace Corporation

Article Viewed 2442 Times
2 Comments
E-mail Article Printer Friendly
 
  • Email This Author
  • Comment On Article
  • About The Author
  • More Articles By This Author

    Part I of this two-part article will discuss the technology behind application "whitelisting."

    A new security technology has emerged that can provide a heightened degree of security for energy industry information and control systems. Application whitelisting takes the traditional approach of the antivirus vendors and turns it 180 degrees. Rather than constantly maintaining a blacklist of malicious software that can get loaded onto a computer system, why not just maintain a whitelist of the authorized applications that are installed and make sure it doesn't change?

    This article is broken into three basic sections. With any given security technology, the strength of the solution is always in the implementation. The first section describes the short history of application whitelisting and provides a detailed perspective on how the technology works. The second section discusses the use of whitelist technologies in a SCADA and Energy environment and how it can help solve unique security challenges. The third and final section provides some perspective on how this technology is adapting to function in a constantly changing environment where software changes are always needed.

    <

    b>The Technology

    In the late 1990s, the concept of application whitelisting began to emerge. It became evident that the antivirus and anti-malware companies were having an increasingly difficult time keeping up with all the rogue software appearing on the Internet. Their products began to bloat with larger and larger databases of bad programs and the impact on the protected system became more intrusive, consuming time and resources. What if the IT staff could install known software on a system and somehow keep it in that tested, functional configuration without allowing viruses and malware to run? The term applied to this security approach is application whitelisting. Rather than look for bad software off a list of 'blacklisted' applications and stop it from running, this new technology looks at a list of good or 'whitelisted' software and allows only it to run.

    The concept of tracking which software is fundamental to configuration management. There have been many configuration management systems over the years that simply used the file pathname and date to ensure the proper file was in the proper place on any given computer. Over time, additional technologies have surfaced to aid in identifying the files and ensuring they have not been unintentionally corrupted. These began as simple checksums and have evolved into ever more complex cryptographic algorithms to include MD5, SHA-1, and SHA-2 families. The first step toward application whitelisting had begun, years before the concept was even introduced.

    The Fundamentals

    While there are many challenges to designing an application whitelisting solution, all solutions need to enforce a list of approved applications and then enable an efficient, IT-friendly change process for the addition of new and updated applications. Not including the management of the solution, which will be discussed later, each whitelisting solution must have three fundamental capabilities. First and foremost, it requires a way to securely and efficiently enforce the whitelist on the computer. Second, it must have a way of building or acquiring the whitelist of applications for any given computer. And third, it must have the ability to report any attempts to violate the security policy it is enforcing. These three capabilities together provide the security required to protect the computer, while at the same time reporting on system status.

    In leading products, the whitelist enforcement mechanism is in the form of a tamper-proof client installed on each computer. It is very important that the enforcement provided by this engine cannot be circumvented by either the local user or a malicious user or program with network access. To this end, the client installed on the computer must function in the operating system kernel. Through tight integration with the operating system, the solution is able to protect the system and have greatest efficiency -- it essentially functions as part of the operating system rather than as an add-on security feature. From within the operating system kernel, the client reads in the whitelist or policy, and ensures that only those applications on the whitelist are allowed to run. The process begins during boot time when the operating system is starting. The client is loaded as early as possible and then reads in the whitelist; it can then check all the executables that loaded before and after itself to ensure they are all authorized. Once the computer is up and running, the client only performs checks when a new application or process attempts to start. From within the operating system, this is very quick with no delay perceived by the user. And because the whitelist is small compared to the massive blacklists in today's antivirus products, the amount of memory, disk space and CPU consumed by the client is also small.

    The application whitelist is what makes this security solution unique. There are many different approaches to produce the list and also many different technologies that may be involved. Experience using this technology has shown that no two computers are exactly alike, so there is rarely a match of whitelists across platforms. For example, orders placed with any major computer manufacturer for computers with identical specifications will have slightly different executables due to variations in chipsets on motherboards, network cards, video cards, memory and so forth. Thus, the whitelist must be assembled for each computer individually. Leading solutions perform this automatically, scanning the computer and building the whitelist. As part of building the whitelist, the client collects a series of parameters to uniquely identify each executable file. These can include the pathname, digital digest, size, digital certificate if it is signed by the vendor, or other identifiers. As mentioned previously, it is the checking of some combination of these parameters by the client during application startup that determines the file has not been modified and is allowed to run. And finally, it is important the security of the whitelist itself is maintained. The whitelist is generally stored in an encrypted and digitally signed file that only the client can decrypt and verify.

    Although a good whitelisting solution will prevent unauthorized applications from running, it is important to monitor and capture related activity from the computer. This activity can take a number of forms. The whitelisting solution can log attempts to overwrite, possibly trojanizing, protected applications on the computer. Likewise, it can log attempts to run unauthorized applications that may have been copied onto the protected system. The whitelisting solution can provide insight into whether this is a local attack initiated on the computer itself or if this is activity from across the network. In addition to basic policy or whitelist violation attempts, the solution logs administrative activity related to managing the whitelist itself. Events here include administrative actions like uninstalling and reinstalling the client on the computer. All these events can be used for client verification and reporting.

    Secure Management

    Application whitelisting is designed and architected to be an enterprise solution. The fundamental capabilities previously described for an individual computer must be centrally managed to make it cost-effective for deployment and long-term management. Fundamental to any enterprise management system today and with limited IT resources to run it, the system must be secure, intuitive, and require minimal training. More importantly, the system must be able to automatically -- without requiring IT involvement -- update the whitelist whenever new applications are added or existing ones are upgraded. Application whitelisting without the ability to handle change is simply lockdown.

    Most application whitelisting systems use a dedicated central server or management appliance to maintain information about and communications with endpoint clients. Command and control of the protected computers must be over a secure channel. This can be accomplished via SSL or a more secure and robust IPSec connection. The communications between the client software and the management appliance must provide some form of authentication, to ensure the client is not spoofed into communicating with a rogue management system. This authentication is typically performed using some form of digitally signed certificates. In addition to management system-to-client authentication, the communications channel itself must be encrypted for confidentiality of information. This prevents easy interception and analysis of configuration changes, security events, and so forth, carried by the communications channel.

    During the initial setup of the client, the vast majority of information exchanged will be whitelist related, where the list is assembled and the overall protection policy built in and applied on the client. Once the policy is in place, the channel is mainly event information sent from the client and collected on the management system. At the central point of the management system, events from all protected endpoints are collected and compiled. Because configuration of all clients is conducted from the central system, these events are easily logged as well. The management system can assemble both the security and configuration-related event information into reports for additional analysis or to meet compliance requirements. Event or configuration information may also be distributed off of the management system in the form of syslog messages for compilation and analysis on other third-party systems.

    The management system provides checks and balances on the protected endpoint systems. It contains a copy of the whitelist that is enforced by the client on the endpoint. It is constantly checking that the whitelist has not been either accidentally corrupted or illegally modified. When a laptop or desktop computer leaves the network for some length of time and then reconnects, the management system can verify the policy has not been modified while offline. Once they reconnect, the policies are immediately updated. Policy changes are securely transmitted to the newly connected client, the whitelist is unencrypted, and the policy is immediately loaded and enforced by the client without rebooting the system.

    The user interface on application whitelisting management systems can take several forms. Some use a web-based browser back to the system which can introduce security issues by itself. Dedicated console appliances are available to interact with the management appliance or central server. And some solutions offer remote desktop protocol (RDP), opening a secure channel between the management system and a remote computer or laptop. This final option provides the greatest flexibility while maintaining security for the overall system. The interfaces themselves vary greatly in terms of look and feel, but all strive for ease of use with an intuitive workflow.

    Part II of this article will deal with whitelisting's applications in SCADA and other energy industry security systems.

    For information on purchasing reprints of this article, contact Tim Tobeck ttobeck@energycentral.com.
    Copyright 2010 CyberTech, Inc.
     
    Contact The Author
    Email the author
    E-mail Article Printer Friendly
     
  • Click Here For More Articles on SCADA


  • Click Here For More Articles By Toney Jennings
  • Do you agree or disagree with this article? Send in your own article.

     

    Readers Comments

    Date Comment
    Bassem Muhi AL-Din
    4.2.09
    Dear Sirs,

    I hope that this message will find you well. I'm very much interested in applying for the job opening in your organization.

    Kindly find attached a copy of my resume.

    Should you need any further information regarding my past experience, please do not hesitate to contact me.

    Yours,

    Bassem M. Al Katheeb

    Mobile: +32 487 594 702

    Land Line: +32 42 762 806

    E-mail address: bmmd67@yahoo.com

    Bassem Muhi AL-Din
    4.2.09
    Personal Information

    Name: Muhi Al-Din Bassem Mohammed Address: Rue Doumier, 10 4430 ANS Liège – Belgium Gsm: +32 487594.702 Landline: +32 42762806 E-mail: bmmd67@yahoo.com , bmmd1967@hotmail.com Place of Birth: Baghdad – Iraq Date of Birth: 1-1-1967 Marital Status: Married – 3 children Current Residency Nationality Status: Political refugee in Belgium with valid travel document

    Membership: Iraqi American chamber of commerce and industry Education Year Educational institution Level 1985 College of Baghdad Upper secondary studies (Including mathematics, chemistry, Physics, Zoology) 1988 Petroleum Training Institute of Baghdad Baccalaureate + 3 Measurement and control (Including engineering drawing, mathematics, electronic s, electrical technique, Industrial safety)

    Professional Experience Period Firm / Sector / Function Duties Nov 2004 – August 2006 Zagros Company / Executive Director Technical team management and installation of IT materials Apr 2003 - Aug 2006 Ministry of science Technology / Technical Manager Work with pipeline & Hazardous materials safety Administration electronic services 1998 – Apr 2003 National Committee of Technology Transfer / Librarian Management of Scientific database reporting Nov 1988 – Apr 2003 Iraqi Atomic Energy Organization. Technician / Full time Maintenance of Nuclear centrifuge and helicon process

    Languages Language Fluency Arabic Mother tongue English Fluent spoken, good written

    Computer Literacy Software Category O. S. MS windows XP, Millennium, Windows 98 Word Processor Microsoft word Spreadsheet Basics of Microsoft Excel Database Microsoft Access Other Power Point, Internet explorer

    Add your comments:
    Please log in to leave a comment!

    Top

        Home | Register | Subscribe | Contribute | Advertise | About Us | Feedback
       Copyright © 2002-2010, CyberTech, Inc. - All rights reserved. Read our Terms of Service.