Industrial control systems supplemental rule pack

Prev Next

The Industrial Control Systems (ICS) Supplemental Rule Pack focuses on detecting evil activity lurking in industrial control systems. This rule pack contains 37 new rules, and provides enhanced detection capabilities in two key areas related to industrial control systems: malware that targets industrial control systems, and hostile, non-malware-based activity that can be detected through ICS protocols.

Initial deployment state

  • ICS Malware

    Enabled by default. Because ICS malware rules are narrowly focused on particular malware types, they have been enabled in your environment automatically. ICS Malware rules utilize HTTP proxy logs.

  • ICS Protocols

    Disabled by default. ICS protocols rules detect what can be considered normal activity in most environments, particularly without additional tuning. ICS Protocols rules utilize Bro logs that have been parsed by DNP and MODBUS.

Trellix recommends that you review each of these rules individually and read their descriptions in order to determine if they are suitable for your environment, detection strategy, and risk profile before determining whether or not to enable them for your environment.

Note

The ICS Protocols component of this rule pack rely on the presence of both DNP and MODBUS parsers. In order for the ICS Protocols rules to function in your environment, you must have a Bro sensor installed in your ICS network segment that has been correctly configured to send log files to Helix Enterprise.

Rules in the industrial control systems rule pack

The rules that comprise the Industrial Control Systems Rule Pack include:

  • ICS Amlware

  • ICS Protocols

  • MODBUS

  • DNP3

ICS malware

ICS malware families covered:

  • BLACKENERGY

  • PEACEPIPE (HAVEX)

Associated rules uncover ICS malware threats by detecting specific user agents, downloader and C2 URI patterns, and known C2 hosts.

ICS protocols

ICS protocols covered:

  • DNP3

  • MODBUS

DNP3 and MODBUS protocols do not themselves track inherently malicious activity, but can be used to uncover evidence of malicious activity depending on the environment in which they were found. Specific rules for these protocols include:

DNP3 rules
  • Disable Unsolicited Responses

  • Unsolicited Response Storm

  • Authorized Cold Restart

  • Unauthorized Cold Restart, Read Request, Write Request, Miscellaneous Request

  • Stop Application

  • Warm Restart

MODBUS rules
  • Illegal Function, Data Address, Data Value

  • Gateway Path Unavailable, Target Device Failed to Respond

  • Red Coils, Multiple Coils, Discrete Inputs, Holding Registers, Input Registers, Exception Status, File Records

  • Write Single Coil, Single Register, Multiple Registers, File Record, Mask Register

  • Get Comm Event Counter, Comm Event Log

  • Slave Device Failure, Busy

  • Acknowledgment

  • Memory Parity Error

  • Diagnostics