Home » Firewall Introduced for OPC Classic by Byers
Firewall Introduced for OPC Classic by Byers
ControlGlobal.com
10/28/2010
By Industrial Automation Insider
OPC Classic is widely used in control systems as an interoperability solution, interfacing control applications from multiple vendors, and this has made it very difficult to secure. The new Tofino OPC Enforcer Loadable Software Module (LSM) has been developed by Byres Security and is now available from MTL Instruments. This extension to the MTL Tofino product line of industrial network security products is claimed to be the first ever industrial firewall for managing OPC traffic. It covers OPC Classic systems; i.e.. all OPC variations except OPC-UA (unified architecture).
The Tofino OPC Enforcer inspects, tracks and secures every connection made by an OPC application, opening only the exact TCP port required for a connection between an OPC client and server. The result is improved network reliability, availability and security for the process control and SCADA industries.
The Enforcer is implemented without any control system changes. The Tofino hardware is simply installed into the live network and configured using a drag-and-drop editor to select permitted clients and servers. Once installed, network security is assured, with all OPC traffic managed behind the scenes.
While a lot of the headlines around cyber security focus on hacker attacks, in fact many incidents result from internal network incidents. "Past plant shutdowns, for example, haven't been caused by hackers. Instead they were the result of badly configured software causing traffic storms that impacted critical controllers and other systems," said Eric Byres, security expert and chief technical officer at Byres Security. "The Tofino OPC Enforcer LSM does much more than block hackers and viruses from accessing the safety system. Its dynamic port management and built-in traffic-rate controls prevent many basic network problems from spreading throughout a plant."
Tricon launch earlier in 2010
Earlier this year, to enable greater interoperability of its Triconex safety systems, Invensys pioneered embedding OPC servers within its Tricon communications module (TCM). To ensure that these modules were cyber secure, Invensys also teamed with Byres Security, which had recently introduced the content inspection firewall for the Modbus TCP protocol, to create a firewall specifically for Triconex systems. The two companies then enlisted the services of MTL Instruments to build the security hardware. The result was the Triconex OPC Tofino firewall, which was introduced for Invensys customers using the Triconex TCM with the embedded OPC solution, in May 2010.
Situation with OPC-UA
Thomas J Burke, president, OPC Foundation commented on the OPC-UA development: "The next generation of the OPC Foundation interoperability specifications, the OPC Unified Architecture, incorporates similar cyber security protection, based on the excellent work of founding companies like Byres Security, MTL Instruments and Invensys. As the use of OPC Unified Architecture expands, we look forward to collaborating with these market leaders to develop additional innovative, readily deployable solutions for the benefit of the entire OPC user community."
To provide further background on the problems in achieving OPC security, Eric Byres has co-authored a paper with Thomas J. Burke, the President of the OPC Foundation, entitled "Securing Your OPC Classic Control System."
More News:
- 05/23/2012 MESA, WBF to merging, expanding operations, B2MML focus
- 05/23/2012 IFS acquires mobile field service vendor Metrix LLC
-
05/21/2012
Eaton to Acquire Cooper Industries
Complementary Products and Markets Create Opportunities for Growth in Global Electrical Industr
-
05/15/2012
ISA, Automation Federation and FIRST Championships Inspire Kids to Be Interested in Automation Careers
ISA and the Automation Federation Join FIRST Championship to Talk About Careers in Automation. Meet the 2012 Team Winners
-
05/10/2012
Process Fieldbus Implementation and Operational Aspects Survey
Participate in this survey on process fieldbus selection criteria, installation, and challenges associated with the implementation and operational phase of the technology
-
05/09/2012
Emerson acquires ISE Magtech
Deal Enables Emerson Process Management to Provide Complete Liquid Level Measurement Solutions Across the Process Industry.
-
05/08/2012
Yokogawa to Host Cybersecurity Webcast
Yokogawa Introduces Its Cybersecurity Strategy on Multiple Levels to Prevent Cybercrime
-
05/07/2012
Yokogawa, Sensorex Earn Lloyds and ISO Certifications
Two Process Automation Product and Systems Providers Have Been Tapped by Certification Organizations in Recognition of Their Product and Production Quality
-
05/07/2012
Complimentary Energy Management System Webinar from InduSoft
Explore How Energy Management Systems (EMS) Can Be Created Using InduSoft Web Studio, With Guest Speaker Tom Ellingson of Noble Conservation Solutions!
-
05/07/2012
Attend the SCADA MENA 2012 Summit
Optimize Your Operational Performance Through Advanced SCADA/DCS Applications to Maximize Your Process Control
- All news »
Sponsored Links
Control Digital Edition
Access the entire print issue on-line and be notified each month via e-mail when your new issue is ready for you. Subscribe today.
- Featured White Papers

Print page