OT - Asset Management Tool
ASSET MANAGEMENT TOOL FOR CRITICAL INFRASTRUCTURE SECURITY
Brief Description
Asset Management Tool for CI Security is focused towards increasing the visibility into control system assets and monitoring industrial control system networks in hybrid/ non-intrusive mode in real time providing situational awareness. As part of active scanning, only vendor approved commands will be used. The solution leverages its deep packet inspection and deep content inspection capabilities to parse the protocol.The asset owners are provided with the latest updated assets with behavioral based anomaly detection to ensure security, safety and reliability of CI. Also the passive network security monitoring allows to detect a variety of network, security, and operational based anomalies.
Use Cases
1.Devices discovery, identification, monitoring and management
2.Identifying protocols used for communication between devices
3. Anomaly detection - protocol, baseline and behavioural
4. Asset verification and auditing
5. Offline network security analysis of OT systems ( OT PCAP Analyzer)
Salient Features
1. Cyber Assets Discovery & Identification
2. Hybrid scanning - combination of active (select probing) and passive scanning
3. Identifying protocols used for communication between devices
4. Creating baseline of the system
5. Inventory of Authorized and Unauthorized Devices
6. Inventory of software
7. Mapping the asset properties against common vulnerability exposure (CVE)/ National vulnerability database (NVD )
8. Continuously monitor the Industrial control systems (ICS) network to detect vulnerabilities
9. Devices monitoring and management
10. Dynamic network map with devices and its communication patterns
11. Identification of anomalies in the network
Technical Specifications
Operational Specification
AMT sensors run on a single board computer assuming that support will be provided by the field personnel to sniff the traffic through the mirrored port.
Provision for required configuration of tools for deployment in AMT server
System Specification
AMT Sensors
Minimal configuration required for AMT sensor
SBC with Quad core, 64-bit SoC @ 1.5GHz,
8GB RAM and Gigabit Ethernet,
64 GB storage
AMT Server
Minimal configuration required for AMT Server
No. of Cores 16
Processor Description: 2.9Ghz
RAM 256 GB DDR4 SDRAM
Hard Disk 20 TB HDD
Contact Details
Name : L Mahendra
E-mail Id : rtsg@cdac.in