Wurldtech Unveils the “Achilles Controller Certification” Program at the 2007 Process Control Systems Forum in Atlanta
Vancouver, BC. - March 13, 2007 - Wurldtech Security Technologies, a leading provider of security products and services for the industrial automation industry, introduced its Achilles Controller Certification Program at the Process Control Systems Forum (PCSF) in Atlanta on Monday, March 5.
Dr. Nate Kube, Wurldtech CTO, presented the program to a private audience of large energy organizations on Monday, March 5 and followed up with an open presentation to general PCSF attendees on Wednesday, March 7. The program, in development since June 2006, is conducted independently by Wurldtech Labs, the research arm of Wurldtech, and was developed to provide a benchmark for the certification of secure controllers deployed in industrial systems worldwide.
Industry response to the program introduction was exceptionally positive, according to Dr Kube. “In today’s security-conscious environment, controller security is a critical issue for industry and all attendees were excited and interested in seeing how this program is structured and how it can positively impact critical core aspects of their businesses,” said Dr. Kube. “They were pleased to see that the Level 1 Certification program is now available, which is the first step toward hardening the security of industrial controllers.”
Wurldtech’s Achilles assurance platform is used by Wurldtech Lab’s to systematically test devices for the presence of configuration errors, vulnerabilities and abnor¬mal behaviors. Dr. Kube explained “…the challenge in testing these devices lies in a lack of detailed information available to vendors about protocol stacks they are using, especially when used in conjunction with their own proprietary protocols.”
Dr. Kube went on to explain, “Achilles solves this problem by combining mathematically rigorous test-packet generation and stateful recognition with highly advanced “black box” monitoring techniques. Complex sequences of test packets generated automatically enable precise trace identification for any points of concern to discover both known and unknown errors and vulnerabilities.”
Dale Peterson of Digital Bond, involved in developing the certification with Wurldtech, explained the objectives for certification are to “...raise the bar for the protection of critical infrastructure by providing vendors with a level playing field for certifying that new products have been tested to a consistent, objective and measurable set of security requirements.”
Level 1 Controller Certification now available
Level 1 Controller Certification conducts more than 30 million individual tests, including protocol implementations at OSI layers 2 through 4 generally found in most controllers with an Ethernet interface including Ethernet, ARP, IP, ICMP, TCP and UDP.
In addition to Level 1 certification, a “+ Protocol Certification” is available to include protocols unique to the control system community. These include Modbus/TCP, DNP3, Ethernet/IP, IEC and others. These protocol implementations, typically written by a control system vendor, have rarely undergone any black box or independent security analysis or robustness testing.
Achilles Level 1 Certified Controllers will be published on the Wurldtech website beginning in May 2007. The test results are always product-specific, including version number, and build in the report as well as whether the default configuration was modified to achieve certification or if a security product, such as a firewall, was required. If a specific configuration or security product was required to achieve Achilles Controller Certification, an MD5 checksum of the configuration documentation will be included in the report to ensure that asset owners properly configure and implement the device in accordance with the Certification.
About Wurldtech Security Technologies:
Wurldtech™ Security Technologies, headquartered in Vancouver, BC, Canada, is a leading provider of SCADA security solutions, industrial automation security, and critical infrastructure protection. Wurldtech™ is committed to delivering breakthrough products and services that help protect global critical infrastructure and address the cyber security needs of major industrial organizations and government agencies worldwide. |