The CISA Alert: Security Beyond Solitary Confinement
3 hours ago
- CISA warns about the dangers of exposing operational technology (OT) to the public Internet and urges immediate actions like removing connections and changing default passwords.
- Eliminating connectivity is not always feasible; alternative defenses are needed that do not consume excessive controller resources or rely solely on stronger cryptography.
- The public Internet is highly hostile, with automated scans and attacks that can consume controller processing power, leading to denial-of-service conditions.
- Strong authentication and encryption can be turned against OT devices by forcing them to perform expensive cryptographic operations for each unwanted connection.
- SYN greylisting offers a lightweight defense by deliberately ignoring initial TCP SYN packets, forcing scanners to retry, while legitimate clients succeed naturally.
- Testing on JNIOR controllers showed that SYN greylisting kept processor idle 95% of the time, whereas disabling it led to SSH attacks consuming resources and causing watchdog resets.
- The approach shifts the cost of unwanted interactions back to attackers and deserves broader adoption in embedded TCP/IP stacks to improve industrial cybersecurity without heavy hardware upgrades.