Protection For Industrial Controls And Critical .

2y ago
81 Views
5 Downloads
895.23 KB
6 Pages
Last View : 1m ago
Last Download : 3m ago
Upload by : Aliana Wahl
Transcription

OpShield from GE DigitalProtection for industrial controls and critical infrastructure networksIf you connect it, protect it.Traditional industry is becoming digital industry. The embeddeddevices connected via critical infrastructure SCADA systems areincreasingly closing the air gap that operators have relied on to keepindustrial assets safe from cyber incidents.It’s important to use the right tools to protect these connectedindustrial assets. The stakes are high, with cyber mistakes and attackspotentially impacting safety, availability and asset health, as well asreputation and intellectual property.OpShield from GE Digital was created specifically to protect criticalinfrastructure, drawing on over ten years of embedded device testingand assessments of hundreds of industrial facilities.Outcomes Reduces risk of cyber-related unplanned downtime, which candecrease safety and availability Improves asset protection from cyber-related damage Helps safeguard protected health information (PHI) byprotecting networks from device compromise Reduces risk of damage to reputation and intellectual propertytheft due to cyber incidents Increases your confidence to connect and optimize your criticalassets01Inspect02EnforceTo protect it, you need to see it. OpShield provides increased visibilitywithin operational technology (OT) networks because it understandswhat IT firewalls can’t—OT commands and parameters in the contextof a defined control process.Knowing something’s wrong is useful, but having the ability to preventit is better. That’s why OpShield’s enforcement policies not only alert,but can also be configured to block traffic that is not on a whitelist ofallowable commands in the context of a particular data flow.OpShield supplements its whitelist capability with unique vulnerabilitysignatures. These heavily researched signatures help protect a device’sroot vulnerabilities vs. spotting known exploits one by one. The result isincreased effectiveness and signature life.03ProtectVulnerability Research TeamIn addition to the ongoing inspection and enforcement OpShieldprovides, it also helps protect OT networks structurally via virtualsegmentation. Segmentation creates zones that reduce the mobilityand damage of a misconfiguration or attacker.Our vulnerability research team focuses solely on devices and softwarethat control critical infrastructure. And whereas other research groupstypically identify and track threats, we painstakingly reverse engineerexploits and conduct our own tests to identify the root causes—theweakness in the software or embedded device.From segmentation to protocol inspection and command blocking,OpShield provides several layers of the defense-in-depth approachnecessary to help protect the people, assets, and operations that runcritical infrastructure.We then write signatures to block traffic that could exploit thevulnerability. This means longer life, more comprehensive protection fromexploit variants, and protection against currently unknown exploits.

OpShield from GE DigitalProtection for industrial controls and critical infrastructure networksFeaturesOverview OpShield protects your network bydeploying perimeter and field units intoyour existing network architecture, withminimal wiring changes and no changes tothe endpoint network configuration. Can deploy with minimal or no productiondisruptionField units inspect network traffic. Thereare two models: the OpShield 300 and400, both of which are fanless andenvironmentally hardened. Perimeter units manage the OpShield system andconfigure the operation of the field units. There arethree models: OpShield 3000, OpShield 4000, andthe Virtual Management Appliance (VMA).OpShield 3000 and 4000 provide inspection andmanagement capabilities . They are higherperformance models.OpShield VMA provides management capabilitiesin a software-only solution, allowing it to beinstalled on existing hardware on the network.3000-8400-4400-2-4s4000-4 Hardware available with fiber optic support,network modules, SFP ports, and HA featureslike hot-swappable dual power supplies OT protocol inspection engine reads OTpackets to the command and parameter levels Vulnerability signatures protect against rootcauses, not just one-off threats Configurable in tap, inline or router mode Record network traffic passing through OpShield Intelligent policy creation uses machine learningto suggest policy based on recorded trafficDrag-and-drop virtual network segmentationlimits misconfiguration and attacker impact Automatic topology creation based on recordednetwork trafficSecurity alerts can be delivered to themanagement console and SIEM tools Simplifies security administration with easy touse graphical interfaces—no CLI required

OpShield from GE DigitalProtection for industrial controls and critical infrastructure networksProtocol Support: Industrial and Medical*Protocol: SubprotocolProtocol Whitelisting CapabilityALSPA E8000 over S80001 interface, 10 commands, 3 parametersALSPA PCX7 commands, 9 parametersALSPA PGD27 commands, 5 parametersALSPA S80005 commands, 4 parametersBACnet16 interfaces, 310 commands, 3 parametersBently Nevada 35006 interfaces, 103 commandsCIP over ENIP2 interfaces, 330 commandsDCE-RPC over UDP11 commandsDCE-RPC over UDP: DCE-RPC over UDP Common2 interfaces, 12 commandsDCE-RPC over UDP: ProfinetAcyclic4 interfaces, 24 commandsDICOM1 interface, 29 commands, 12 parametersDNP334 commands, 17 parametersEGD20 commandsEGD Configuration (over HTTP)8 commands, 1 parameterICMP1 command, 1 parameterIEC-101 over TCP2 interfaces, 149 commandsIEC-1042 interfaces, 58 commands, 3 parametersiFix8 interfaces, 42 commandsModbus19 commands, 55 parametersMS-RPC20 commandsMS-RPC: DCOM13 interfaces, 72 commandsMS-RPC:OPC Common5 interfaces, 16 commandsMS-RPC: OPC Data Access19 interfaces, 137 commands, 86 parametersOPC UA Binary3 interfaces, 48 commandsSDI (Mark VI)2 interfaces, 91 commands, 1 parameterSDI (Mark VIe)217 commands, 2 parameters*OpShield is fluent in these protocols to the command level. OpShield recognizes over 20 additionalprotocols,including Siemens S7, OPC UA and EtherNet/IP-CIP

OpShield from GE DigitalProtection for industrial controls and critical infrastructure networksProduct Specifications by ModelOpShield-300-2 (end-of-sale)AC PowerRange Line VoltageNormal Line VoltageMax CurrentFrequencyRedundant PowerDC PowerPower SupplyPower Consumption (Avg/ Max)Redundant PowerEnvironmentalOperating TempStorage eld-400-2-4SOpShield-3000-8OpShield-4000-490 264 VAC100 240 VAC1.2 A (100 VAC)50/60 HzNo100 240 VAC100 240 VAC5.0A (100 VAC)50/60 HzHot Swappable AC PSU12 36 VDC13.8 W / 15.7 WDual DC Connectors12 36 VDC13.8 W / 15.7 WDual DC Connectors12 36 VDC13.7 W/20.5 WDual DC Connectors12 36 VDC13.7 W/20.5 WDual DC Connectors-40º 70º C-40º 85º C5% 95% (non-condensing)Passive (Fanless)-40º 70º C-40º 85º C5% 95% (non-condensing)Passive (Fanless)-40º 75º C-40º 85º C5% 95% (non-condensing)Passive (Fanless)-40º 75º C-40º 85º C5% 95% (non-condensing)Passive (Fanless)0º 40º C-10º -70º C20% 90% (non-condensing)Fan0º 45º C-25º 75º C5% 90% (non-condensing)Hot-swap fans146 mm / 5.75 inches65 mm / 2.56 inches127 mm / 5.00 inches1.0 kg / 2.2 lbsDIN (or optional Wall-Mount)146 mm / 5.75 inches65 mm / 2.56 inches127 mm / 5.00 inches1.0 kg / 2.2 lbsDIN (or optional Wall-Mount)146 mm / 5.75 inches78 mm / 3.07 inches127 mm / 5.00 inches1.25 kg / 2.75 lbsDIN (or optional Wall-Mount)146 mm / 5.75 inches78 mm / 3.07 inches127 mm / 5.00 inches1.25 kg / 2.75 lbsDIN (or optional Wall-Mount)44 mm / 1.73 inches438 mm / 17.24 inches292 mm / 11.50 inches8.6 kg / 19 lbs1U rack44 mm / 1.73 inches431 mm / 16.97 inches514 mm / 20.20 inches8.0 kg / 17.63 lbs1U rack, rails included (tool-less)-36 -72 VDC89.3 W/165.7 WOptional Hot Swappable DC PSU8x Gigabit SFP4x Gigabit CopperNetwork ModulesGigabit Ethernet RJ45Gigabit Ethernet SFPUSBConsole2 with bypass 1 mgmt port2Serial over DB94 with bypass 1 mgmt port2Serial over DB94 with bypass 1 mgmt port2 with bypass 1 mgmt port2Serial over DB942Serial over DB98 with bypass 2 mgmt ports2Serial RJ454 with bypass 2 mgmt ports(add’l ports via network modules)Supported via network module(s)2Serial RJ45

OpShield from GE DigitalProtection for industrial controls and critical infrastructure networksProduct Certifications8 Port (3000, 4000)2/4 Port (300, 400)RoHSRoHSSafetyIP30 (Ingress Protection)ATEX C1D2 (300 only)ULUL 60950-1, 2nd Edition, 2011-12-19UL 60950-1, Information Technology Equipment Safety Part 1: GeneralRequirementsCSA C22.2 No. 60950-1-07, 2nd Edition, 2011-12CSA C22.2 No. 60950-1-07, Information Technology Equipment SafetyPart 1: General RequirementsFCC Part 15 Class A or BFCC Part 15, Subpart B: 2012 Class AIC ICS-003ICES-003 Issue 5: 2012 Class AFCCCEIEC 60068-2-64 VibrationIEC 60068-2-27 Mechanical ShockEN-55022: 2010 AC: 2011 (Class A or B)EN 55022: 2010 AC: 2011 Class AEN-61000-3-2: 2006 A1: 2009 A2: 2009EN 61000-3-2: 2006 A1: 2009 A2: 2009 Class AEN-61000-3-3: 2008EN 61000-3-3: 2008EN 55024: 2010EN55024: 2010IEC 61000-4-2: 2008IEC 61000-4-2: 2008IEC 61000-4-3: 2006 A1: 2007 A2: 2010IEC 61000-4-3: 2006 A1: 2007 A2: 2010IEC 61000-4-4: 2012IEC 61000-4-4: 2012IEC 61000-4-5: 2005IEC 61000-4-5: 2005IEC 61000-4-6: 2008IEC 61000-4-6: 2008IEC 61000-4-8: 2009IEC 61000-4-8: 2009IEC 61000-4-11: 2004IEC 61000-4-11: 2004IEC 61000-4-12: 2006VCCIVCCIOpShield is now availablewith or without fiber,high availability features,and SFPs. Contact usto learn about the righttechnology for youroperational environment.LEARN MORE

OpShield from GE DigitalProtection for industrial controls and critical infrastructure networksServicesRelated productsContinue your IIoT journeyIn the world of Industrial Internet of Things (IIoT), organizations are able tooptimize productivity, reduce costs, and achieve operational excellence. Whilethis is an exciting time for opportunity and growth, it can also bring on newchallenges, questions, and uncertainty. No matter where you are on your IIoTjourney, GE Digital has the right services offering for you.GE Digital's OT cyber security suite helps protect industrial and healthcarecompanies against misconfigured devices and unplanned downtime dueto cyber incidents. We can help you test, certify, and secure industrialconnected devices, applications, and processes.Transforming your business requires innovative foundational solutionsthat lay the groundwork for optimized performance.Advisory Services We can help you plan and start your IIoT journey in a waythat aligns to your specific business outcomes.Managed Services We can help you maintain your critical machines fromone of our remote locations around the world using model-based predictiveanalytic technology.Implementation Services Our team will help develop a collaborative, multigenerational plan that will marry your existing investments to the right processenhancements and technology.Education Services We specialize in education services to ensure thatyou’re leveraging our solutions to the fullest extent with our training andcertificate programs.Achilles Test PlatformBuild in product security. Achilles TestPlatform discovers vulnerabilitiesand faults to be reproduced, isolated,identified, and resolved beforeproduct introduction.HistorianOptimize asset and plantperformance through time-seriesindustrial data collection andaggregation, leveraging Predix IIoTconnectivity.PredixInnovate and transform yourbusiness with the cloud-basedoperating system for the IndustrialInternet, purpose-built for industry.iFIXGain visibility into your operationsand secure agility for smarterdecision making that drives results.GlobalCare Support Services Let us help by ensuring that your businesscontinues to operate at its highest efficiency, all while mitigating risks toyour investments.Asset Performance ManagementMove from reactive to proactivemaintenance to reduce unplanneddowntime, minimize maintenancecosts, improve efficiency and extendasset life.Cyber Security Services Our solutions provide industrial-grade security for awide range of OT network and application topologies.About GEContactGE (NYSE: GE) is the world’s Digital Industrial Company, transforming industry with software-defined machines and solutions that are connected, responsiveand predictive. GE is organized around a global exchange of knowledge, the “GE Store,” through which each business shares and accesses the same technology,markets, structure and intellect. Each invention further fuels innovation and application across our industrial sectors. With people, services, technology and scale,GE delivers better outcomes for customers by speaking the language of industry.Americas: 1-855-YOUR1GE (1-855-968-7143)gedigital@ge.comwww.ge.com/digital 2019 General Electric. All rights reserved. *Trademark of General Electric. All other brands or names are property of their respective holders. Specifications aresubject to change without notice. 10 2019

IEC 61000-4-5: 2005 IEC 61000-4-5: 2005 IEC 61000-4-6: 2008 IEC 61000-4-6: 2008 IEC 61000-4-8: 2009 IEC 61000-4-8: 2009 IEC 61000-4-11: 2004 IEC 61000-4-11: 2004 IEC 61000-4-12: 2006 VCCI VCCI OpShield is now available with or withou

Related Documents:

Bruksanvisning för bilstereo . Bruksanvisning for bilstereo . Instrukcja obsługi samochodowego odtwarzacza stereo . Operating Instructions for Car Stereo . 610-104 . SV . Bruksanvisning i original

10 tips och tricks för att lyckas med ert sap-projekt 20 SAPSANYTT 2/2015 De flesta projektledare känner säkert till Cobb’s paradox. Martin Cobb verkade som CIO för sekretariatet för Treasury Board of Canada 1995 då han ställde frågan

service i Norge och Finland drivs inom ramen för ett enskilt företag (NRK. 1 och Yleisradio), fin ns det i Sverige tre: Ett för tv (Sveriges Television , SVT ), ett för radio (Sveriges Radio , SR ) och ett för utbildnings program (Sveriges Utbildningsradio, UR, vilket till följd av sin begränsade storlek inte återfinns bland de 25 största

Hotell För hotell anges de tre klasserna A/B, C och D. Det betyder att den "normala" standarden C är acceptabel men att motiven för en högre standard är starka. Ljudklass C motsvarar de tidigare normkraven för hotell, ljudklass A/B motsvarar kraven för moderna hotell med hög standard och ljudklass D kan användas vid

LÄS NOGGRANT FÖLJANDE VILLKOR FÖR APPLE DEVELOPER PROGRAM LICENCE . Apple Developer Program License Agreement Syfte Du vill använda Apple-mjukvara (enligt definitionen nedan) för att utveckla en eller flera Applikationer (enligt definitionen nedan) för Apple-märkta produkter. . Applikationer som utvecklas för iOS-produkter, Apple .

This presentation and SAP's strategy and possible future developments are subject to change and may be changed by SAP at any time for any reason without notice. This document is 7 provided without a warranty of any kind, either express or implied, including but not limited to, the implied warranties of merchantability, fitness for a .

och krav. Maskinerna skriver ut upp till fyra tum breda etiketter med direkt termoteknik och termotransferteknik och är lämpliga för en lång rad användningsområden på vertikala marknader. TD-seriens professionella etikettskrivare för . skrivbordet. Brothers nya avancerade 4-tums etikettskrivare för skrivbordet är effektiva och enkla att

Den kanadensiska språkvetaren Jim Cummins har visat i sin forskning från år 1979 att det kan ta 1 till 3 år för att lära sig ett vardagsspråk och mellan 5 till 7 år för att behärska ett akademiskt språk.4 Han införde två begrepp för att beskriva elevernas språkliga kompetens: BI