Check Point Infinity: A complete security framework for Maritime Industry, 01/12/20

Social 1200x628 set2

A.M.M.I.TE.C and Check Point welcomed executives & engineers from the maritime industry to discuss the challenges that maritime sector faces while trying to comply with cyber security frameworks amidst the covid-19 era. Covid-19/The pandemic served as an accelerator for digital transformation forcing companies to provide their workers a means for remote working. Α major concern that troubles even senior management is the level of security awareness of their employees, not only those on the land but the crews at sea as well. Cyber-attacks are without doubt on the rise with various threat actors trying to advantage of the great exposure companies have due to remote working. At the same time, IMO’s resolution for maritime companies to develop a cyber security program or strengthen their existing one, is becoming mandatory in the very near future. “The companies in the maritime industry should not face these challenges alone, but with a strategic technology ally such as Check Point”, stated Mr. Sabanis - President of the Board of Directors of A.M.M.I.TE.C.

It is common for most companies to neglect the cyber security frameworks. There is this misconception that these frameworks are good in theory but cannot be applied in real world conditions. The truth is that they must be considered as equally important as frameworks for physical security for the vessels. “The most important benefit of a cyber security framework is that it provides guidance” noted Mr. Nikolopoulos – Team Leader of Security Engineering at Check Point. Frameworks such as ISO 27001 lay the foundations of a solid cyber security posture. In the same context, IMO published the guidelines (MSC-FAL.1-Circ.3) for maritime cyber risk management to safeguard shipping from current and emerging cyber threats and vulnerabilities. These guidelines make clear that risk management is fundamental to safe and secure shipping operations. Vulnerable systems could include, bridge systems, cargo handling and management systems, access control systems, communication systems etc. but first they must be identified and then proceed to securing them. Apart from securing these types of systems, maritime companies need to strongly consider the distinction between information technology and operation technology systems. These guidelines (even though they were released on 2016) take into effect as of 1 January 2021 and alongside ISO 27001 they can act as enablers for maritime companies and guide them to build or enhance their cyber security program, shielding them from cyber threats.

Through this discussion we observed how the controls of the various frameworks can be translated to actionable items. According to ISO 27001, for example, there is a control against malicious code distribution. This has been mapped by Check Point Compliance blade to near 30 distinctive items that ensure the security and compliance of the environment. The Compliance blade, which is part of Check Point’s consolidated architecture, continuously and automatically evaluates the compliance status of the infrastructure, while providing the administrator actionable items to further increase the security posture of the organization.

The threat landscape for companies of the maritime industry evolves around Industrial Control Systems (ICS) and endpoints. ICS assets are inherently vulnerable because they share the following traits:

  • Run on Legacy OS
  • No Built-in Security
  • Impossible to Patch
  • Weak/Hardcoded Password

The traditional security solutions cannot identify the various ICS assets and their vulnerabilities. They have insufficient knowledge of ICS behavior and security needs. ICS-specific threat intelligence is missing as a result they cannot offer threat prevention.

Check Point’s solution for securing ICS is based on the following best practices:

  • Threat Prevention – Block OT related attacks
  • Segmentation – Between IT and OT
  • ICS Discovery & Enforcement

Check Point’s motto being “One Step Ahead” means that Threat Prevention is based on the largest Threat Intelligence network called ThreatCloud, which detects more than 7000 unknown malware daily. ThreatCloud offers enriched threat intelligence and distributes attack information, which turns zero-day attacks into known signatures for all Check Point customers across the globe. 

Segmentation starts by building a boundary protection between the IT and OT zones. Next, granular visibility is built into the SCADA protocols and commands which are exchanged between the control and field systems on the vessels. Capitalizing on the high level of visibility, micro segmentation can also be applied to protect the networks of the vessels.

Upon Discovering the ICS assets and their exact communication patterns, a policy is generated automatically per each asset. The policy is able to include the specific vendor and type of the device, as well as, the specific SCADA protocol and even type of command that needs to be allowed! Ultimately resulting to the Enforcement of specific types of communication. Additionally, Check Point’s solution for ICS offers the ability of Virtual Patching to protect vulnerable devices from threats and known exploits by utilizing the IPS blade of the security gateways with hundreds of OT-related signatures out-of-the-box available to customers.

Endpoint devices are also the target of cyber threats. Endpoints at shore or on the vessels are facing daily cyber-attacks such as phishing and ransomware many of which are sophisticated. It is apparent that traditional antivirus products cannot protect against signature-less attacks. Furthermore, a common concern of the majority of shipping companies is port protection as such some have implemented separate solutions to reduce the attack surface as well as comply with IMO requirements (ISM Code 1.2.2.2). “Having disparate and individual solutions for protecting each attack vector of the endpoint results in high maintenance costs in terms of human effort, increased TCO and makes forensic investigation almost impossible”, highlighted Ms. Koukou – Check Point Evangelist.

Check Point SandBlast Agent is a complete endpoint security solution built to protect the remote workforce and crews from today’s complex threat landscape. It prevents the most imminent threats to the endpoint such as ransomware, phishing or drive-by malware, while quickly minimizing breach impact with autonomous detection and response.

One single, unified agent for EPP, EDR, VPN, NGAV, data, and web-browsing protection, so the organization can streamline processes and reduce TCO.

Block malware coming from web browsing or email attachments before it reaches the endpoint, without impacting user productivity. Every file received via email or downloaded by a user through a web browser is sent to the Threat Emulation sandbox to inspect for malware. Files can also be sanitized using a Threat Extraction process (Content Disarm & Reconstruction technology) to deliver safe and cleaned content in milliseconds.

Gain runtime protection against ransomware, malware, and file-less attacks, with instant and full remediation, even in offline mode. Once an anomaly or malicious behavior is detected, Endpoint Behavioral Guard blocks and remediates the full attack chain without leaving malicious traces. Anti-Ransomware identifies ransomware behaviors such as encrypting files or attempts to compromise OS backups and safely restores ransomware-encrypted files automatically. SandBlast Agent uses a unique vaulted space locally on the machine that is only accessible to Check Point signed processes - in case the malware attempts to perform a shadow copy deletion, the machine will not lose any data.

Phishing Protection - Prevent credential theft with Zero-Phishing® technology that identifies and blocks the use of phishing sites in real-time. Sites are inspected and if found malicious, the user is blocked from entering credentials. Zero-phishing® even protects against previously unknown phishing sites and corporate credential re-use.

Auto-generated forensic reports: providing detailed visibility into infected assets, attack flow, correlation with the MITRE ATT&CK™ Framework. The Forensics capability automatically monitors and records endpoint events, including affected files, processes launched, system registry changes, and network activity, and creates a detailed forensic report. Robust attack diagnostics and visibility support remediation efforts, allowing system administrators and incident response teams to effectively triage and resolve attacks.

SandBlast Agent is a tailor-made solution for the needs of the maritime industry offering important benefits such as low bandwidth requirements and simplified installation process.

Mr. Grivas – Information Security Officer of Angelicoussis Group elaborated on how integral are the security frameworks for maritime security. “Cyber security is based on three core pillars: People, Processes and Technology”, he emphasized. Regarding technology, Check Point is able to solve the security challenges of Angelicoussis Group, with industry-leading and state-of-the-art products, under a unified management & consolidated architecture called Check Point Infinity.

Summarizing, shipping companies can benefit from Check Point’s expertise and tailor-made solutions for the maritime industry, to secure their infrastructure and comply with regulations, security frameworks and guidelines, such as IMO’s Resolution MSC.428(98).

The Greek office of Check Point was founded by Mr. Gikas thirteen years ago and through this time it has grown to be an undisputed cyber security leading force in Greece & Cyprus. Check Point was the first cyber security company that invested in the Greek market empowering the maritime industry with leading cyber security solutions. Check Point is active in most maritime forums such as ShipIT and A.M.M.I.TE.C events. Check Point offers a consolidated security architecture, tailor-made for the needs of the maritime industry and is based on robust products with the highest standards for secure software development.

pic9

Ammitec-event-konstantina.pdf

Amitec_Event_share.pdf

Surfing_through_the_Cyber_Waves_CheckPoint_Infinity.cleaned.pptx

Sabanis

Grivas


Association of Maritime Managers of Information Technology and Communications

Follow us

E-mail: This email address is being protected from spambots. You need JavaScript enabled to view it., This email address is being protected from spambots. You need JavaScript enabled to view it.

Akti Miaouli 93, PIRAEUS 185 38

Copyright © 2017 AMMITEC. All Rights Reserved. Web Design by Web and Art Solutions