Purdue Model for ICS Security - Check Point Software
Purdue Model for ICS Security
Network segmentation is an effective tool for improving the security of companies with IT and OT networks. The Purdue Reference Model, as adopted by ISA-99, is a model for Industrial Control System (ICS) network segmentation that defines six layers within these networks, the components found in the layers, and logical network boundary controls for securing these networks.
What is the Purdue Model for ICS Security?
Developed in the 1990s, the Purdue Reference Model, a part of Purdue Enterprise Reference Architecture (PERA), is a reference data flow model for Computer-Integrated Manufacturing (CIM), i.e., using computers to control the entire production process.
Purdue Reference Model, "95" provides a model for enterprises where end-users, integrators, and vendors can collaborate in integrating applications at key layers of the enterprise network and process infrastructure.
The Purdue Reference Model was adopted by ISA-99 and used as a concept model for ICS network segmentation. It shows the interconnections and interdependencies of all of the main components of a typical Industrial Control System (ICS), dividing the ICS architecture into two zones – Information Technology (IT) and Operational Technology (OT) – and subdividing these zones into six levels starting at level 0.
At the base of the Purdue model is the OT, the systems used in critical infrastructures and manufacturing to monitor and control physical equipment and operational processes. In the Purdue Model, this is separate from the IT zone, which can be found at the top of the model. In between, we find a DMZ to separate and control access between the IT and OT zones. Within the zones, we find separate layers describing the industrial control components found in each layer, including:
- Level 0: Level 0 includes the physical components that build products, such as motors, pumps, sensors, valves, etc.
- Level 1: Level 1 consists of systems that monitor and send commands to the devices at Level 0, including Programmable Logic Controllers (PLCs), Remote Terminal Units (RTUs), and Intelligent Electronic Devices (IEDs).
- Level 2: At Level 2 are devices that control the overall processes within the system, like human-machine interfaces (HMIs) and SCADA software that enable monitoring and management of the process.
- Level 3: Level 3 supports management of production workflows, including batch management and manufacturing operations management/manufacturing execution systems (MOMS/MES).
- Industrial DMZ (iDMZ) Zone: The iDMZ creates a barrier between the IT and OT networks to prevent infections within each environment and control access.
- Level 4: At Level 4, systems like Enterprise Resource Planning (ERP) software, databases, and other systems manage logistics of manufacturing operations and provide communications and data storage.
- Level 5: Level 5 is the enterprise network which collects data from ICS systems.
Is the Purdue Reference Model Still Relevant?
Is a model that was initially developed in the 1990s still relevant for securing ICS networks? The relevance depends on the extent to which your OT network still utilizes the technology in the model.
The Purdue model's hierarchy helps define system components into distinct layers, providing logical places for network segmentation to control access. The model may not perfectly fit current OT networks but serves as a solid foundation for enhancing OT security.
The Need for Zero Trust in ICS
ICS network operators often prioritize uptime, leading to vulnerabilities from both legacy and new IIoT devices. Recognizing and responding to cyber threats has become crucial due to incidents like Stuxnet and recent ransomware attacks.
A zero trust security model can fortify defenses by assuming that threats exist inside and outside the network perimeter. This involves verifying everything attempting to connect to the system and pushing for micro-segmented borders to protect data and assets.
Check Point ICS Security Solution
Check Point secures ICS systems by implementing a zero trust approach, enabling least privileged access controls across the defined zone boundaries in the Purdue model. This approach ensures that security measures do not disrupt OT operations.
By creating and monitoring east-west communication between ICS assets, applying granular security rules based on application and device attributes, and enabling secure remote access, organizations can protect vulnerable system components.