Profiling OT manufacturing devices
In this section, we will create the profile definitions for manufacturing Operational Technologies (OT) devices. The method in which FortiNAC handles the OT devices is the same as IoT. However, in the OT setup, we will use FortiGuard IOT/OT signatures to ensure device identification. In this use case, we will create the device profiling rule for a Siemens S7-1500 as PLC device that provides control for Oil Pump Jack.
Device profiling through FortiGuard method and FortiGuard IoT scans will provide a confidence score for target endpoints (IoT Devices). Most IoT devices send unencrypted traffic and use different hardware and operating systems that introduce vulnerabilities that could expose the network to risks since users are not aware of the security implications of their use. The confidence value is a parameter we can use to define how trustworthy or secure we can consider a device and create a risk profile on it. It gives an assurance that the device has a certain level of security capabilities and we can rely on it. FortiNAC has a confidence range between 0 - 255 where values equal to or greater than 120 are considered as a good rating. |
Profile OT manufacturing devices
-
In the FortiNAC management interface, go to Users & Hosts and click Device Profiling Rules. Click Add.
-
In the General tab, configure the following options:
-
Check the Enabled checkbox
-
Name:Programmable Logic Controllers
-
Registration: Automatic
-
Type: Click Add and use “PLC” in the field and click “OK”
-
Role: Click Add and use “PLC” in the field and click OK.
-
Register as: Device in Host View
-
Check Add to Group: Add a new group, use the “PLC Device Group” as group name.
-
-
Click on the Methods tab and then follow the steps below:
1. Check both FortiGuard and Vendor OUI.
2. On the Vendor OUI tab, click Add.
3. For the Field option, select Vendor Name.
4. Add “SIEMENS BUILDING TECHNOLOGIES AG” and click OK.
5. On the FortiGuard tab, check “Match Custom Attributes”.
6. Click Add and use the attributes below:
Category: Industry
Sub-Category: Energy
Vendor: Siemens
Model: S7-15007. After filling in the attributes, click OK.
8. The profile has been defined and you click on OK again.
To explore more devices and attributes found in the FortiGuard OT database:
-
Search using the MAC Address of your OT/IoT device
-
All the returned attributes can be used to create a new device profiling.