News & Updates | Site Map

Cybersecurity Safeguards for Smart Manufacturing and the Industrial Internet

2019-10-185871

On July 26 this year, ten Chinese authorities led by the Ministry of Industry and Information Technology jointly issued the Guiding Opinions on Strengthening Industrial Internet Security Work, marking the fundamental completion of the top-level design and overall framework for China’s Industrial Internet development. The top-level architecture of China’s Industrial Internet consists of three major systems: the network system, the platform system, and the security system.

Network System (Foundation): It covers all industrial elements including personnel, objects, equipment and workshops, and runs through design, R&D, production, management and other full industrial links. It realizes pervasive and in-depth interconnection across entire industrial systems, industrial chains and value chains.

Platform System (Core): Serving as the hub for all industrial elements, the platform aggregates massive industrial data. It not only realizes universal data interconnection, but also supports real-time equipment status monitoring, on the basis of which it enables optimal resource allocation, intelligent analysis and other core industrial capabilities.

Security System (Guarantee): The security system identifies and resists various cyber threats and effectively mitigates diverse industrial security risks, forming an essential safeguard for stable industrial operation.

Issued to comprehensively enhance the security guarantee capability and service level for the innovative development of the Industrial Internet, the guiding opinions put forward seven key tasks for the security system: implementing security responsibilities, building a standardized security management system, improving enterprise security protection capabilities, strengthening Industrial Internet data security protection, constructing national industrial Internet security technical capabilities, enhancing public security service capacities, and promoting technological innovation and industrial upgrading.

The document clarifies the core tasks and development goals of the security system for the Industrial Internet era. Implementation-level research results are urgently required to define the security system adapted to the new paradigms of Industry 4.0, Industrial Internet and smart manufacturing, clarify emerging cyber security challenges, and elaborate the connotation, scope, depth, span and difficulty of relevant tasks. Targeted countermeasures, implementable solutions and practical case studies are essential to achieve both short-term and long-term cyber security goals.

Timely and complementary to this demand, the European Union Agency for Cybersecurity (ENISA) released the report Industry 4.0 Cybersecurity: Challenges and Recommendations, based on its research on good practices for IoT security in smart manufacturing environments. As the EU’s central professional hub for cyber and information security expertise serving member states, private sectors and citizens, ENISA points out that despite uneven Industry 4.0 maturity and varying digital manufacturing development levels among enterprises, as well as differentiated construction progress of network and platform systems, all industrial players face identical cyber security challenges and core tasks. Therefore, the report’s analytical conclusions and recommendations provide valuable references and practical implementation guidance for all major industrial countries, enabling global sharing of research outcomes and joint responses to cross-border cyber security risks.

Common Themes of the New Industrial Era

Industry 4.0, the Industrial Internet and smart manufacturing represent the shared developmental themes of the new industrial era for humanity. They fundamentally resolve the inherent drawbacks of traditional industry, including isolated information islands, fragmented data, segmented networks and decentralized management, and build a new industrial ecosystem featuring universal interconnection of humans, machines and objects. In this innovative industrial paradigm, humans, machines and physical objects run through the entire lifecycle of industrial design and interconnection, making cyber security guarantee and protection the top priority of industrial development.

The cyber security characteristics of the new industrial era can be summarized in four dimensions: breadth, depth, span and difficulty. The breadth refers to global pervasive network interconnection; the depth means real-time synchronous data transmission of internal and external status of humans, machines and objects, with dynamically changing information interaction scenarios; the span covers the full lifecycle of human-machine-object integration; the difficulty stems from multiple practical bottlenecks. These include unintegrated OT and IT systems, inconsistent security cognition and systems, fragmented technologies and standards, shortages of interdisciplinary and cross-industry talents, and the absence of unified cognitive standards. In addition, the complex industrial supply chain lacks clear responsibility division among multiple stakeholders, including suppliers, operators, manufacturers, regulators and research institutions, requiring continuous exploration and innovative technological development at all levels. Such difficulties constitute core industrial challenges, which demand high-level strategic guidelines as well as executable, operable detailed implementation plans.

ENISA’s report puts forward high-level targeted recommendations for different stakeholders to promote standardized and secure innovative development of Industry 4.0. Key stakeholders cover core industrial entities closely related to industrial networks: Industry 4.0 security experts (OT and IT security), industrial operators (solution providers and manufacturers), regulatory authorities, standardization organizations, academic and R&D institutions. The report systematically analyzes prevalent Industry 4.0 cyber security challenges from three dimensions: personnel, processes and technologies, and proposes practical, operable and targeted solutions. Focusing on tactical-level specifications, applied research and technological innovation, it aims to address current practical difficulties in talent cultivation, operational processes and technical iteration.

Strengthening Industrial Cyber Security Construction

As a leading industrial power in the EU, Germany has always attached great importance to cyber security construction under the new industrial ecosystem of Industry 4.0, Industrial Internet and smart manufacturing. Beyond the five major stakeholders covered in the ENISA report (enterprises of all sizes, research institutions and national regulators), Germany has established numerous interdisciplinary and cross-industry collaborative mechanisms and institutions. These institutions focus on fundamental and applied research, product development and promotion, standard formulation and implementation, and coordinated regulatory governance for Industry 4.0 cyber security, uniting all stakeholders to jointly tackle major security problems and drive industrial cyber security progress.

As early as 2010, Germany’s Fraunhofer Institute put forward seven core suggestions on cyber security in its research reportCyber Security 2020 Strategic White Paper: Challenges for Information Technology Research:

1. Highlight the unique importance of digital sovereignty in core key information technology security. As a core field of information interaction technology under Industry 4.0, it provides testable and reliable information security solutions, which must be prioritized in information infrastructure construction, industrial enterprise software, embedded systems and cross-industry future projects.

2. Establish and improve operational industrial cyber security application laboratories, and carry out systematic interdisciplinary research projects for Industry 4.0. Conduct targeted research and achievement demonstration on cyber intrusion, network attacks and economic espionage, and define industry-oriented research directions.

3. Implement security-by-design principles. Full lifecycle security guarantee for humans, machines and objects must be embedded in the initial design stage. Security technologies shall be fully considered in the whole process of product, solution and service development. Systematic research on methodologies, processes and tools supports continuous full lifecycle security optimization, while realizing compatibility, integration and reliable testing of existing systems to upgrade overall security levels.

4. Ensure the security and reliability of industrial components, products, solutions and full lifecycle services through third-party verifiable security certification and detection mechanisms.

5. Grant private data the same level of security protection as economic, national and civic data privacy. Minimize losses caused by network intrusion and espionage attacks, and continuously optimize personal private data protection mechanisms.

6. Improve decision-makers’ situational awareness of industrial security status and risks.

7. Realize human-centric and human-controllable information technology mechanisms. Develop user-friendly security technologies, tools and processes through innovative research on accessible information security systems.

Nevertheless, these seven suggestions still require further improvement and supplementation. The fourth industrial revolution is advancing rapidly with continuous technological innovation. New technologies and products are widely and rapidly applied in Industry 4.0 and smart manufacturing, featuring fast iteration and extensive coverage. Accordingly, cyber security challenges have become more arduous, extensive and in-depth, penetrating all industrial, social and private fields. Although the current ENISA report comprehensively analyzes the breadth, depth, span and difficulty of cyber security risks covering mainstream industrial scenarios, it still leaves room for in-depth exploration of segmented and specialized fields.

Attaching Importance to Industrial Information Security

Industrial information security is a core pillar of cyber security for smart manufacturing and Industry 4.0. As core digital assets comparable to "digital gold", industrial information faces intensive and targeted cyber attacks. In terms of industrial control information security, the global industrial sector is currently plagued by growing annual vulnerabilities, persistent high-risk vulnerabilities, delayed vulnerability remediation, and declining technical thresholds for vulnerability exploitation. Targeted attacks on industrial enterprises are on the rise with increasingly diversified and advanced attack methods, focusing on manufacturing, construction, transportation and engineering industries. An increasing number of industrial control systems and devices exposed on the Internet have become global industrial security vulnerabilities, with more than half of China’s industrial control systems having suffered cyber attacks.

Monitoring data from the National Industrial Information Security Development Research Center shows that the number of publicly exposed industrial control systems and devices worldwide continues to rise, leading to growing industrial information security risks. In the first half of 2018, China ranked sixth globally in terms of the severity of industrial control system cyber attacks, with an attack ratio of 57.4%. Despite a slight drop in global ranking, the attack proportion increased year-on-year.

Major countries worldwide have taken active measures to strengthen industrial information security capabilities. The United States, the European Union, Japan, the United Kingdom and other regions have launched institutional establishment, strategic layout, legal and standard formulation, capital investment and technical research initiatives to consolidate industrial security defenses.

In terms of institutional development, the United States has built a complete system of cyber security research institutions, including the Idaho National Laboratory (INL), Sandia National Laboratories (SNL) and Pacific Northwest National Laboratory (PNNL). The United Kingdom has established a national cyber emergency response team and the country’s first cyber security academy for professional talent training. Japan’s Control System Security Center (CSSC) specializes in industrial information security protection, conducting R&D on advanced control system security technologies, security verification and controllable testbeds, and hosting regular professional cyber security seminars. In addition, Germany has set up the Federal Office for Information Security, while France has established the National Agency for Cybersecurity of Information Systems.

Cyber attack incidents frequently target key industrial infrastructures including power grids, petroleum, natural gas and transportation systems, with nuclear facilities, energy production and supply systems, aviation and petroleum sectors serving as high-priority attack targets. Global ransomware outbreaks have spread rapidly across power, rail transit, petroleum, finance and telecommunications industries. Transportation systems and government institutions also face persistent cyber threats. Criminals exploit vulnerabilities in remote monitoring systems through source code intrusion to illegally control industrial equipment, causing direct and indirect severe economic losses to enterprises.

Industrial information security refers to information security involved in all links of industrial operation, covering industrial control system security, Industrial Internet security, industrial big data security, industrial cloud security and industrial e-commerce security. Compared with traditional cyber security, industrial information security faces greater protection difficulties, as it must adapt to the real-time and high-reliability requirements of industrial equipment and systems, as well as the complexity of diverse industrial protocols.

Current Tasks and Countermeasures

Cyber security challenges in talent cultivation, operational processes and technical iteration under Industry 4.0 bring new tasks and innovative opportunities for applied industrial research. The information technology industry should strengthen application-oriented research, market-oriented product development and practical industrial cases, so as to protect industrial economic data and network security, reduce the cost of cyber security products, and develop globally competitive industrial technologies, products and solutions for large-scale promotion and application.

Reliable cyber security guarantee must be provided for the circulation of core national digital assets such as smart manufacturing systems, transportation infrastructure and energy production and supply systems. In cyber security R&D, mature applied cases should guide demonstrative technological innovation. Intensive application-oriented systematic research has become an urgent task for all industrial countries advancing smart manufacturing.

Only by developing reliable systematic solutions, cooperating with industrial partners to launch market-mature products, and continuously delivering innovative technologies can entities effectively drive real economic development, realize the value creation goals of Industry 4.0 and smart manufacturing, and provide systematic security guarantees for the sustainable development of industrial ecosystems.

Cyber security has evolved into a high-priority research field. Comprehensive support from national policy guidance, capital allocation and market collaborative mechanisms provides in-depth technical, service and solution guarantees for industrial cyber security. Current research tasks cover a wide range of fields, including cloud security, cyber-physical system protection, data privacy management, energy production and supply security, early warning systems, intelligent factory upgrading, mobile information technology R&D, cyber security infrastructure construction, network attack defense, cyber-physical system security, mobile system security engineering, three-dimensional security management system establishment, and full-lifecycle system security and privacy protection. The systematic index of the report provides valuable reference and actionable guidance for all implementation levels of industrial cyber security construction.


image.png

Regrettably, there have been few research findings, guiding opinions or strategic reports focusing on emergent challenges and corresponding emergency countermeasures from a strategic perspective. To illustrate, in extreme socio-political and economic contexts, deteriorating international relations triggered by wars or cross-border political, economic and trade frictions may lead to cyber security attacks or malicious network disruptions. This will force the disconnection of product operation, network channels and data control mechanisms. Such risks are essential factors that must be fully considered for the new industrial ecosystem and social environment underpinned by Industry 4.0, the Industrial Internet and smart manufacturing.

Although the probability of extreme natural disasters and man-made crises remains low, the absence of targeted emergency response strategies will result in devastating and fatal blows to industrial operations and social stability once such crises occur.


Source: Informatization and Software Service Network