Securing Critical Operational Technology in the AI Era
The acceleration of vulnerability discovery, particularly with advancements in artificial intelligence (AI), poses a significant challenge for organizations managing operational technology (OT) systems. Many OT systems, crucial for modern life functions such as medical equipment, building management, and industrial control systems, are inherently difficult or impossible to patch due to certification requirements, operational constraints, or end-of-life status. This reality leaves them exposed to newly identified weaknesses. Ignoring this problem, as illustrated by the significant impact of the WannaCry worm on the U.K.’s NHS health system in 2017, is not a viable strategy. More recently, end-of-life software exploitation facilitated access to governmental systems in 2023, underscoring the ongoing risk, according to Talos Intelligence.
The Challenge of Unpatchable Systems
Traditional vulnerability management relies heavily on applying vendor patches. However, OT environments frequently present scenarios where patching is not feasible. Systems might be certified for specific software versions, or vendors may no longer offer support. Even seemingly bespoke platforms often incorporate common libraries and protocols susceptible to vulnerabilities. Furthermore, threat actors who gain internal network access can identify and target these unpatchable systems, regardless of whether they are publicly exposed.
Advances in AI-assisted code analysis are uncovering decades of technical debt in software, leading to a constant cadence of patches that many organizations, especially those with extensive OT infrastructure, struggle to implement. This creates a widening gap where unsupported or unpatchable systems remain vulnerable to known exploits.
How to Secure Unpatchable OT Systems
While applying approved patches remains the optimal defense, alternative strategies are essential when patching is impossible. The inherent predictability of OT system behavior offers unique opportunities for protection.
Prioritizing Visibility and Micro-segmentation for Legacy Operational Technology
The first step in securing any environment is achieving comprehensive visibility. Legacy OT systems often present unique network fingerprints, making them identifiable for inventorying and risk assessment. Once identified, micro-segmentation for legacy operational technology becomes a critical defensive layer. By using Virtual Local Area Networks (VLANs) combined with Access Control Lists (ACLs), vulnerable systems can be isolated on private networks. This ensures that only a small, authorized set of devices can communicate with them, thereby significantly minimizing the attack surface and making it incrementally harder for attackers to launch exploits.
Virtual Patching Strategies for Industrial Control Systems
Another key compensatory control involves deploying next-generation firewalls (NGFWs) directly upstream of OT systems. When equipped with an up-to-date intrusion prevention system (IPS), these firewalls can perform deep packet inspection to detect and block exploit attempts before they reach the vulnerable device. This effectively creates virtual patching strategies for industrial control systems. By filtering out known malicious content, NGFW/IPS solutions act as a crucial barrier, especially when coupled with network segmentation, to ensure that only trusted systems communicate securely with the vulnerable OT assets.
The Myth of the Air Gap
While theoretical air gaps offer complete network separation, achieving and maintaining them in practice is challenging. Operational discipline is paramount, as shortcuts like temporary data transfer bridges or unauthorized wireless connectivity often compromise air gaps. Even data diodes, designed for one-way data flow, can be circumvented. Defenders should view air gaps as a temporary or partial solution, continuously monitoring for breaches and supplementing them with other controls.
Recommendations and Mitigations
In an environment where AI continually improves vulnerability discovery, defenders must adopt a multi-layered approach to protect unpatchable OT systems:
- Asset Inventory and Visibility: Thoroughly identify all OT assets, their software versions, and known vulnerabilities.
- Network Micro-segmentation: Implement strict network segmentation to isolate vulnerable OT systems, restricting communication to only essential, authorized devices.
- Next-Generation Firewall (NGFW) with IPS: Deploy NGFW/IPS solutions upstream of OT systems for virtual patching and deep packet inspection to block exploit attempts.
- Regular Monitoring: Continuously monitor network traffic for anomalous behavior or attempted exploits, even within segmented environments.
- Security Awareness: Educate personnel on the risks of circumventing security controls, especially concerning air-gapped systems.
By combining these strategies, organizations can establish a powerful compensatory security posture, ensuring that even if vulnerabilities are discovered and remain unpatched, attackers face significant hurdles in exploiting them within critical operational technology environments.
Related: AI Overwhelms Patching: Rapid7 Warns of Exposure Crisis, OT Security: Legacy System Vulnerabilities in Critical Infrastructure