How to Address OT Environment Challenges with a Single Solution
Ransomware attacks have been impacting production facilities and social infrastructure around the world for the past several years. In March, Norwegian aluminum manufacturing plant’s operation stopped, and in July, a South African power company's system crashed. In addition, a logistics company based in Los Angeles was infected by ransomware, while factories in South Korea suffered from Clop ransomware attack.
Massive financial damage and social panic could occur within an hour of production facility or social infrastructure shutdown. Production facilities and social infrastructure have been damaged by malware infections, such as Stuxnet, even before the rise of ransomware attacks. ICT-based Smart Factory and the Fourth Industrial Revolution is just around the corner. Even so, security incidents in production facilities and social infrastructures still occur, making Operational Technology (OT) environment the talking point of security. At the RSA Conference 2019 held in San Francisco late February, major global security vendors, including Cisco, emphasized the need for security measures for OT environment or industrial fixed function systems.

Concerns and Challenges for OT Security
Compared to the traditional IT environment, the OT environment has a more complicated operational sensitivity and environmental limitations for devices. This is because security solutions can impact the operational stability of production facilities and may operate disconnected from network.
Security requirements of production facilities include: preventing system and network failures caused by malware; controlling unauthorized applications or network connections for facility operation; impacting system resources less. This is why AhnLab EPS is recognized as the optimal security solution for fixed function systems, including industrial control systems of production facilities. AhnLab EPS is widely adopted and operated in production facilities of various fields, such as semiconductor, electronics, and chemical. AhnLab recently released a new EPS lineup to address the security threats in the operations of multi-structured production facilities.
AhnLab Expands its OT Protection Scope via EPS Standalone
Most production facilities have some sort of standalone systems, disconnected from all internal network or external internet. As a result, central management is impossible and security holes are created. Inadequately managed standalone operations could lead to the installation of unnecessary applications, as well as malware infection, resulting in the deletion or alteration of essential files and programs for system operation.
To address these security concerns, AhnLab launched “AhnLab EPS Standalone” to protect fixed function system operating in offline environments. AhnLab EPS Standalone is an ultra-lightweight agent solution that uses minimal system resources compared to that of the traditional security solutions, requiring no additional engine updates since the initial installation, thus ensuring system availability and operational stability. To address the needs of customers already using AhnLab EPS, AhnLab EPS Standalone has essential functions for security management of standalone systems that are difficult to centralize.
The inventory-based lockdown function protects industrial fixed function systems from various security threats by only allowing authorized applications required for operation to run and restricting creation and alteration of files, folders, and processes. Security administrators do not have to use whitelist technology. Instead, they can use an exclusive inventory technology to effortlessly deploy and operate policy settings for specific applications used in certain environments.
EPS Standalone agent installed in each system is designed to directly configure security policies and check logs of the fixed function systems. The security administrator can check the security events that have occurred in the fixed function system via the log information of EPS standalone. They can also set up an administrator password to allow the security administrators to change the security policies of each system.
Figure 1. AhnLab EPS Standalone policy management and log screen (AhnLab EPS Agent)
EPS Standalone provides a lock mode that prevents the creation or alteration of executable files (PE) in individually operated fixed function systems, thereby preventing damage caused by malware, such as ransomware. If the lock mode of the fixed function system needs to be unlocked due to the maintenance of the production facility or other unavoidable circumstances, it is possible through the “emergency scan mode setting” for a certain period. While the lock mode is unlocked, the security administrator can perform tasks, such as system configuration and facility program update.
Figure 2. Force-disable Lock Mode via emergency scan mode
Minimal Security Holes Without Relying on the Security Administrator
AhnLab EPS Standalone protects against a variety of security threats without impacting the resources or business processes of the standalone fixed function systems disconnected from network. Above all, it resolves security holes for systems in offline environments via its proactive prevention system.
A corporate operating a multi-structural production facility can provide seamless response to security threats throughout the whole facility by deploying AhnLab EPS Standalone, as shown in Figure 3. AhnLab EPS provides efficient malware detection and prevention through central management and servers. Customers using AhnLab EPS solutions can operate without worrying about operational burdens caused by adding additional security solutions or conflicts between various security solutions.

Figure 3. AhnLab EPS Standalone deployment diagram
AhnLab is scheduled to add a new EPS line-up for Linux-based fixed function system with a reinforced malware detection function later this year.
To learn more about AhnLab EPS, visit www.ahnlab.com.