Industrial Threat Library
The Industrial Threat Library detection engine performs several checks on the monitored data to look for known vulnerabilities, possible misconfiguration and other known threats. The Industrial Threat Library (ITL) provides a large number of pre-configured checks and controls to detect ICS weaknesses and threats at an early stage and offers intelligence about the cause and remediation of the problem. The checks are divided into three categories:
- Networking: To detect device and network misconfiguration, such as hosts not receiving NTP responses or connectivity issues.
- Operations: To detect problems and threats to the industrial process, such as malfunctioning or misbehaving devices or the use of potentially dangerous operations (e.g., restart commands).
- Security: To detect security threats and vulnerabilities, such as the use of insecure protocols or protocol versions (e.g., TELNET or SSHv1), exploits of known vulnerabilities, Indicators of Compromise (IoCs) and user defined blacklists (e.g., blacklisted IPs).
The user can configure which checks will be performed by the Sensor on the Industrial Threat Library page (accessed by clicking on "Industrial threat library checks" on the Sensor page). Each individual check can be enabled or disabled for the entire network or only for some of the monitored hosts, by defining "Exceptions" (exceptions can be defined by clicking on the corresponding entry on the tree menu on the left of the page). Some checks have configuration settings, these check-specific parameters can be configured from the Industrial Threat Library page as well by clicking on the individual check in the table.
Multi-factor File Dissection
eyeInspect Passive Sensors have the ability to isolate files transferred over the network via SMB and TFTP and perform checks on them. In particular, Passive Sensors scan files against known malicious hashes (MD5) and YARA rules. If a malicious files transfer is detected, a corresponding ITL alert is raised and the malicious file is made available to the user for download and offline analysis. In addition to the analysis within eyeInspect, users can also forward isolated files to third-party systems (e.g. sandboxing solutions) leveraging the "new alert" SD Script callback. The following restrictions apply to the Multi-Factor File Dissection functionality:
- Only files up to 1 GB are analyzed against known malicious hashes
- Only files up to 4 MB are analyzed against YARA rules
- Only files up to 4 MB are accessible via script callback associated with an alert and made available to the user for download
- Archives and encrypted files are not analyzed
Select one or more Industrial threat library (ITL) checks by selecting the checkbox(es) in the first column, to enable the action menu above the ITL table. You can pause/resume, export and share the ITL configurations.
Open an ITL check by clicking the name to view the following ITL attribute details:
- Overview
- List of all checks
- Exceptions
- Checks by category
- Checks by protocol
To run individual checks, select them using the checkbox in the first column and click the Play button on top of the checks table.
The following options are available in the secondary nav bar in the Industrial threat library page:
Back
Navigate to the previous page.
Finish
Save the ITL configurations.
Reset
Reset the ITL configurations.
Reload
Reload the ITL configurations.