Purdue Model for ICS Security - Check Point Software

Purdue Model for ICS Security

Network segmentation is an effective tool for improving the security of companies with IT and OT networks. The Purdue Reference Model, as adopted by ISA-99, is a model for Industrial Control System (ICS) network segmentation that defines six layers within these networks, the components found in the layers, and logical network boundary controls for securing these networks.

What is the Purdue Model for ICS Security?

Developed in the 1990s, the Purdue Reference Model, a part of Purdue Enterprise Reference Architecture (PERA), is a reference data flow model for Computer-Integrated Manufacturing (CIM), i.e., using computers to control the entire production process.

Purdue Reference Model, "95" provides a model for enterprises where end-users, integrators, and vendors can collaborate in integrating applications at key layers of the enterprise network and process infrastructure.

The Purdue Reference Model was adopted by ISA-99 and used as a concept model for ICS network segmentation. It shows the interconnections and interdependencies of all of the main components of a typical Industrial Control System (ICS), dividing the ICS architecture into two zones – Information Technology (IT) and Operational Technology (OT) – and subdividing these zones into six levels starting at level 0.

At the base of the Purdue model is the OT, the systems used in critical infrastructures and manufacturing to monitor and control physical equipment and operational processes. In the Purdue Model, this is separate from the IT zone, which can be found at the top of the model. In between, we find a DMZ to separate and control access between the IT and OT zones. Within the zones, we find separate layers describing the industrial control components found in each layer, including:

Is the Purdue Reference Model Still Relevant?

Is a model that was initially developed in the 1990s still relevant for securing ICS networks? The relevance depends on the extent to which your OT network still utilizes the technology in the model.

The Purdue model's hierarchy helps define system components into distinct layers, providing logical places for network segmentation to control access. The model may not perfectly fit current OT networks but serves as a solid foundation for enhancing OT security.

The Need for Zero Trust in ICS

ICS network operators often prioritize uptime, leading to vulnerabilities from both legacy and new IIoT devices. Recognizing and responding to cyber threats has become crucial due to incidents like Stuxnet and recent ransomware attacks.

A zero trust security model can fortify defenses by assuming that threats exist inside and outside the network perimeter. This involves verifying everything attempting to connect to the system and pushing for micro-segmented borders to protect data and assets.

Check Point ICS Security Solution

Check Point secures ICS systems by implementing a zero trust approach, enabling least privileged access controls across the defined zone boundaries in the Purdue model. This approach ensures that security measures do not disrupt OT operations.

By creating and monitoring east-west communication between ICS assets, applying granular security rules based on application and device attributes, and enabling secure remote access, organizations can protect vulnerable system components.