3 ms·
What you're describing is a whole bunch of bespoke engineering. That is the opposite of cheap. It would be interesting to go down this design path trying to ma
by mindslight 2mo ago
What you're describing is a whole bunch of bespoke engineering. That is the opposite of cheap.
It would be interesting to go down this design path trying to make a generic product. I'd aim to dovetail into the bespoke engineering that PLCs already involve. I'd be tempted to design it as something like a modbus target (that PLC engineers would set up the system to write data to), except that modbus sucks rocks as a data format, never mind lacking the abstractions to do express multiples of the same systems. So then I guess you're left with some schema language that you're trying to appeal to PLC engineers to write securely. Maybe akin to the IEC 61131-3 Functional Block Diagram language, but with a very clear "this is the airgapped dividing line" ?
But in the general case, you still need to get control data back into most systems system. So your data link will likely still be bidirectional, but with the goal to keep the protocol small and simple, to keep the attack surface small.
The main problem is that it still only takes one PLC engineer to connect the two sides of the network for their own expedience. From what I can tell this is how the horror stories abound. PLCs generally use ethernet/IP these days, so one has to do deliberate work to segment the networks. And it just takes one too-smart-for-their-own-good person who wants to make that PLC available from their desk/home/vacation to ruin it.
- mikewarot 2mo agoThere are plug and play devices that do multiple flavors of SCADA, but as you've said, they aren't trivial, thus not cheap.
- mikewarot 2mo ago> only takes one PLC engineer to connect the two sides of the network for their own expedience The fuzzy way we depreciate the term Engineer shows up in situations like this. An actual Professional Engineer, with a state issued license, would be assuming liability for their actions, and would know better than to bypass an air gap in this manner. Someone who uses the term willy-nilly, as most programmers seem to do these days, has no such restraints, nor caution, nor deep consideration of consequences.
- mindslight 2mo agoAs a former professional embedded design engineer, I'm not terribly swayed by arguments that "real engineering" involves licenses from the state. Nor do I think that personal liability is a great avenue for moving the needle here, as that would really just be creating indirect regulation through insurance companies (with a specific focus on what the Professional Engineer might be found liable for), while creating an ongoing tax (the insurance premiums) for anyone involved in such work. Why not just write and mandate those codes directly? something like the National Electric Code but focused on best practices for setting up secure control networks. (And while the NEC does enter into the PE dynamic, there is plenty of work subject to the NEC but that doesn't involve a PE)