Microsoft Azure Defender for IoT: IT vs. OT - What is OT and how is it different from IT

Поделиться
HTML-код
  • Опубликовано: 31 май 2024
  • In this video, we learn about the differences between Operational Technology (OT) and Industrial Control Systems (ICS) and gain an understanding of how this compares to the modern Internet of Things (IoT).
    Join James Cabe and Anthony Bartolo as they discuss how Microsoft is approaching cybersecurity for Industry 4.0 using Azure Defender for IoT. Learn about the challenges of securing OT networks, how ladder logic can cause cascading impacts, and how to use the Purdue model to help with communications between the IT and OT security teams as they build a cohesive end-to-end protection solution for modern cyber attacks.
    Learn more: aka.ms/SecurityCommunity
    0:00 - Intro
    1:55 - Operational Technology
    3:27 - Industry 4.0
    8:45 - Purdue Model for Control Hierarchy
    17:48 - Ladder Logic
    20:36 - Depth of Visibility in the OT Black Box
    25:49 - Azure IoT/OT Security
    32:58 - ICS-Specific Behavioral Analytics
    35:02 - Defender for IoT Sensor Concept
    ► Subscribe to Microsoft Security on RUclips here: aka.ms/SubscribeMicrosoftSecu...
    ► Follow us on social:
    LinkedIn: / microsoft-security
    Twitter: / msftsecurity
    ► Join our Tech Community: aka.ms/SecurityTechCommunity
    ► For more about Microsoft Security: msft.it/6002T9HQY
    #AzureDefender #IoT #MicrosoftSecurity
  • НаукаНаука

Комментарии • 6

  • @plchacker
    @plchacker Год назад +4

    The first PLC was Modicon. GE later bought out Modicon. But at the beginning they were not associated with each other at all. Please do not give GE credit for something they were not even interested in.

  • @plchacker
    @plchacker Год назад +6

    How to spend 38 minutes saying that you are vastly superior to manufacturing engineers and belittle their work. You really should spend real time in manufacturing environments beyond petroleum. PLC's are not the stupid little devices you make them out to be. OT bandwidth is a real concern. Speed in important for safety. S7 is a weak European attempt at PLC's so if that is your reference, I can almost understand your attitude. Ladder Logic is the app. The programming software is also an app. Communications protocols vary greatly and while different from standard IT, they are sophisticated beyond basic ethernet. In fact, if you are working only on ethernet and TCP/IP protocols, you are missing a great majority of industrial networks. This is typical of IT professionals. Microsoft certainly wants control of everything, but you have a long way to go before you are industry ready. As for your turn it off and restart comment, this has very little affect on PLC's. In fact, you are not playing with Windows anymore. Troubleshooting in most manufacturing facilities is far more robust, and requires far better results than you Windows jockies are capable of producing. Once again, I don't "Reboot" PLCs. That is a certain way to lose valuable information needed to solve the problem. Also, most manufacturers do not live in the "BlackBox" world you speak of. In fact most manufactures have their own controls people taking care of programming and day to day business.
    As for the IT professionals out there, do not mistake this as a solid strategy for industrial OT network security. OT security is complex and likely beyond your usual networking world. The "simple, little OS" this guy mentions is perfectly suited to the controls world. While it is small and lightweight, it is extremely efficient and unlike Windows, you do not have to reboot it when it quits working. Truth is, they don't stop very often. I have PLCs that have been running for years/decades. Do yourself a big favor and talk to the people in charge of the controls in your facility. I promise you they have specific demands and information that you will need to provide connections to the OT network. If the OT network is not separated from the business network, you will have issues. The two are very different in purpose. That is about the only thing the Microsoft blowhard got correct.

    • @edwardpate6128
      @edwardpate6128 Год назад

      Well stated! Most folks coming from the IT side really don't understand the requirements of OT networking. I worked for 30+ years in IT networking before moving to OT and it was eye opening.

  • @arielbaringholtz3139
    @arielbaringholtz3139 2 года назад +1

    this was very fluent and informative, thanks !
    those were global subjects on among other things why isolated networks are important , can you recommend on first steps of learning materials or certification in the field? not only in cloud technology such as Azure?

    • @plchacker
      @plchacker Год назад

      The first place to start is by working in the OT environment. You will find that there are many different networks/protocols you will need to understand. Ethernet/IP, Modbus, CAN, Devicenet just to name a few. It is a highly complex field. Anybody offering certs at this point is blowing smoke.

    • @ximix6557
      @ximix6557 Год назад

      @@plchacker thank you, already working in the field for about 2 years.
      it seems the world in general begin to understand the benefits of a complete separation (physical between the regular IT infrastructure from its twin brother Ot which has so different application and policies management).