Skip to Content
Exit

Tag Archive: Predator Secure DNC

When Machines Can’t Meet the Network Rules

Comments Off on When Machines Can’t Meet the Network Rules

The “significant security vulnerabilities” of SMBv1 that Microsoft warns of, which have exposed companies to crippling ransomware attacks like the infamous NotPetya, are often the same legacy protocol that can still be found on some CNC controllers today.

“The original SMB1 protocol is nearly 30 years old, and like much of the software made in the 80’s, it was designed for a world that no longer exists. A world without malicious actors, without vast sets of important data, without near-universal computer usage.” — Ned Pyle

But there’s not necessarily a simple fix for manufacturers. Remove SMBv1, acknowledges the software giant, and you can break compatibility with older equipment and software. You could try to isolate vulnerable systems or use port blocking and other compensating controls to reduce exposure. Or you can continue to run SMBv1, exposing your shop, and potentially your value chain, to cyberattacks, debilitating downtime, exorbitant costs and the loss of customer trust.

secure connectivity for legacy CNC machines - Shop Floor Automations

The challenge with machinery running SMBv1 is to preserve the communication it needs for production while creating a controlled connection that limits unnecessary network access and exposure.

Each approach addresses part of the problem, but none necessarily addresses the fundamental production challenge: How do you keep productive legacy equipment connected without leaving the door open to the network threats it was never designed to withstand?

For manufacturers, the answer may not be replacing the machine, patching around the problem, adding layers of microsegmentation and isolation or simply accepting the risk. It may be finding a more controlled way to connect it.

 A Familiar Standoff

That’s the tension manufacturers live with every day, even without a headline-making cyberattack to force the issue.

On one side, IT and cybersecurity teams are accountable for reducing exposure. They see an outdated protocol as a potential entry point, particularly when a machine sits on a network that also touches business systems, suppliers or other production assets.

SMBv1 vulnerabilities in manufacturing - Shop Floor Automations

IT teams need visibility into what your aging equipment communicates, with which systems, over which protocols and ports and in which direction, including the files, applications or services required for production.

On the other hand, operations sees a machine that needs to run. That CNC may be producing parts that customers are waiting for, tied to a validated process or simply too costly and disruptive to replace. Engineering knows the controller’s limitations, the tooling is dialed in and the process works.

Neither side is wrong.

That’s where the discussion needs to move beyond “turn it off” or “leave it alone,” to whether manufacturers can separate the equipment’s production requirements from the network exposure that comes with its legacy technology.

The Architecture to Accommodate Both

Production and IT teams should have a shared understanding of what the aging machine actually needs to communicate in order to find a way to give it that connection without opening the rest of the network to unnecessary exposure.

NIST’s OT security guidance takes a similar approach. Its recommendations recognize that manufacturing systems have different performance, reliability and safety requirements than traditional IT environments, while calling for network segmentation and controlled boundaries between systems to limit access and manage data flows.

That means teams should start with the equipment rather than the protocol by taking these steps to help plan out the process:

  1. What actually depends on SMBv1? Identify the machine(s), controller(s) or application(s) and understand why it/they need the legacy protocol.
  2. What needs to move and where? Map the CNC programs or other production data, their source and destination and the path they currently take across the network.
  3. What can be separated? Use segmentation, firewalls, access controls or other compensating controls to restrict the legacy equipment’s exposure without disrupting the production process.
  4. Can the connection itself be changed? Rather than relying on Windows shares or SMB to move CNC programs, a purpose-built DNC connection can provide a controlled path for transferring production files to and from equipment. Predator Secure DNC, for example, is designed to transfer files to CNC equipment through firewalls while eliminating dependencies on corporate domains, workgroups and Windows file shares.
  5. What is the long-term plan? Document the exception, the controls around it and the conditions that would eventually trigger an equipment or controller upgrade.
CNC machine network security - Shop Floor Automations

Production needs a clear understanding of what data the machine needs to send and receive, with which systems and for what production purpose, in order to assist IT in designing connectivity around those essential requirements while limiting unnecessary network exposure.

A Different Way to Connect

In the quest to minimize security vulnerabilities, the goal isn’t necessarily to make a legacy machine conform to a network architecture it was never designed for. The goal is to understand what the machine needs to do its job and then design the connection around those requirements.

That could mean segmentation at the network level, tightly-controlled firewall rules, isolation of particularly vulnerable equipment and other compensating controls. In some environments, it may also mean replacing a legacy Windows file-sharing dependency with a purpose-built DNC connection.

A solution like Predator Secure DNC can be part of that approach, providing a controlled path for CNC program transfers without relying on corporate domains, workgroups or Windows shares. But software alone doesn’t solve the problem. The right architecture depends on the machines, controllers, network environment and production requirements already in place.

Shop Floor Automations, as a manufacturing integrator, brings together the equipment, connectivity hardware, software and implementation expertise needed to work through that gap. SFA assesses the existing machine and network environment, identifies the communication requirements, helps design the connectivity architecture, deploys the appropriate hardware and software and validates the result with the teams responsible for IT, engineering and production.

The result can mean fewer exceptions to manage and a known production process that keeps reliable machines running. It also creates something more valuable than a workaround: a practical path toward a more secure shop floor without treating every aging machine as a replacement project or major IT burden.

If you’re looking to connect aging and/or vulnerable equipment without creating a new IT problem, talk with an SFA manufacturing integration expert today.

Tag Archive: Predator Secure DNC

Building Resistance into Aged CNC Machines

Comments Off on Building Resistance into Aged CNC Machines

How CNC program transfers can overcome the vulnerabilities of SMB1 for greater security and efficiency

It took mere hours. In May of 2017, a devastating ransomware cryptoworm called WannaCry impacted more than 200,000 computers across 150 countries, ultimately amassing over $4 billion in damages. Only months later, a variation of this worm spread to 10,000 machines in Apple’s single supplier of SoC components for iPads and iPhones, causing a production stoppage for a full day and shipment delays among its major tech customer base. The original worm was halted, but IT services management company Cloudflare asserts that WannaCry attacks continue today.

Ransomware on CNC Machines

The ransomware cryptoworm WannaCry notably affected TSMC, which manufactures processors and other silicon chips for major technology companies such as Qualcomm, AMD and Apple, due to a Windows SMB1 server vulnerability.

Starting with SMB1

What happened to the National Health Service (NHS), FedEx, Taiwan Semiconductor Manufacturing Company (TSMC) and so many others? The WannaCry worm exploited “vulnerabilities in the Windows SMB v1 server to remotely compromise systems, encrypt files and spread to other hosts,” explains a fact sheet from the National Cybersecurity and Communications Integration Center (NCCIC). While patches have since been issued by Microsoft, the software company admits there are still instances in which manufacturers may need to run SMB1:

    1. Your company is running XP or Windows Server 2003 under a custom support agreement
    2. You have old management software that demands admins browse via the “network,” also known as the “network neighborhood” master browser list
    3. You run old multi-function printers with antiquated firmware in order to “scan to share”

For manufacturers experiencing such cases, there are workarounds. SMB1 could be disabled on every system connected to the network, recommends the NCCIC. You can block port 445 (Samba). You can verify that there isn’t any unexpected SMB1 network traffic. You can isolate vulnerable embedded systems. But these options may not necessarily be viable for efficient and protected CNC file transfers among aged equipment.

Transfer CNC Programs on SMB1 Machines

Manufacturers can struggle to disable SMB1 on every machine and still transfer CNC programs efficiently, effectively and securely.

Simplifying Network Setups

An alternate route is to simplify network setups altogether. A modern DNC software, like Predator Secure DNC, enables you to remove Windows shares, corporate domains, workgroups, homegroups, Microsoft SMB, CFS, FTP, DNS, WINS, NETBUI and IPX/SPX within shop floor VLANs, WANs or subnets for DNC or file transfers. This can be especially useful for manufacturers running older CNC equipment with Windows-based controls that lack compatibility with newer operating systems. It can also alleviate the need for system upgrades and service packs to maintain the older versions of Windows.

The original WannaCry worm was halted, but Cloudflare asserts that WannaCry attacks continue today.

In other cases, controllers like Haas classic controllers can be upgraded to another SMB version by contacting the machine tool builder or segmenting the network to address CNC machines that are not upgradable or do not run a Windows operating system. The point is, regardless of your SMB1-dependent machinery environment, you can reduce your ransomware risk while gaining the latest benefits in efficiency and productivity.

An experienced manufacturing integrator possesses the technical expertise to properly assess, assign and execute custom solutions for your company. Contact Shop Floor Automations to understand your full scope of SMB1 options today.

Tag Archive: Predator Secure DNC

Overcoming the Risks of Outdated Windows-based CNC Machines

Comments Off on Overcoming the Risks of Outdated Windows-based CNC Machines

Over the years, Windows-based CNC machines, robots, CMMs, test stands and other manufacturing equipment have proven popular, largely due to their Ethernet-based networking using the corporate network. But as Windows operating systems (OS) reach the end of their lifecycle, Microsoft technical assistance, software updates or security fixes no longer become available. The options, then, for manufacturers needing Ethernet CNC file transfers and running CNCs with Windows 2000, 2003 or older OS are limited: upgrading to a newer Windows OS can be cost prohibitive and involve a lack of support from the equipment manufacturer; or there’s no upgrade path available, thereby necessitating that the whole machine be replaced. 

The IT Imperative

To protect manufacturers from security risks associated with OS lifecycle completions, IT departments have led the initiative to remove older Windows OSs from corporate domains and discontinue support, while eliminating the use of FTP or Windows shares on untrusted VLANs altogether. This movement often relegates manufacturing operations to isolate a PC from the corporate network and go back to manually loading files through portable media – which presents its own set of security risks. TechAdvisory.org reports that 25 percent of malware is spread today through USB devices. Even the United States Computer Emergency Readiness Team (US-CERT) recommends banning portable media devices from the workplace. And for manufacturers subject to CMMC 2.0, the continued use of removeable media devices may involve severe restrictions or nonacceptance altogether.

Manufacturers needing Ethernet CNC file transfers and running CNCs on older Windows operating systems have limited, cost-efficient options. 

All of this leads to a collision course of lost productivity for the shop floor and some major challenges for IT, as programmers struggle to minimize time spent physically transferring files to equipment and maintain accurate version control and IT strives to minimize risk. The good news is that there are other Ethernet CNC file transfer options available than the common scenario above.

Ethernet CNC file transfers

CNC machines running on outdated operating systems lead to a collision course of lost productivity for the shop floor, as programmers struggle to minimize time spent physically transferring files to equipment and maintain accurate version control, and some major challenges for IT as it strives to minimize risk.

Fortified Ethernet Connectivity

A modern DNC networking system, for one, allows manufacturers to still take advantage of Windows 95 and newer OS, Ethernet as well as your existing network infrastructure, all while removing them from your corporate domain and eliminating the use of FTP, unsecure USB, Windows Administrator access and more. This secure version of DNC software, like Predator Secure DNC software, still enables you to transfer your CNC programs, CNC variables, offsets, parameters, PLC registers and other production data to and from your manufacturing equipment – but adds a layer of security with automatic authentication, encryption and data compression.

Machine tools with an RS232 connection, or those with an option for it, can be connected to Predator Secure DNC to avoid connectivity risks. You’ll need knowledge of your CNC machine’s communication parameters, including baud rate, data bits, stop bits and parity settings or the network connection, such as FTP, FileShare, etc. Consult with an expert manufacturing integrator to explore any other prerequisites to connect your CNC machines through a next-generation DNC networking system.