The Industrial Control Systems (ICS) Supplemental Rule Pack focuses on detecting evil activity lurking in industrial control systems. This rule pack contains 37 new rules, and provides enhanced detection capabilities in two key areas related to industrial control systems: malware that targets industrial control systems, and hostile, non-malware-based activity that can be detected through ICS protocols.
Initial deployment state
ICS Malware
Enabled by default. Because ICS malware rules are narrowly focused on particular malware types, they have been enabled in your environment automatically. ICS Malware rules utilize HTTP proxy logs.
ICS Protocols
Disabled by default. ICS protocols rules detect what can be considered normal activity in most environments, particularly without additional tuning. ICS Protocols rules utilize Bro logs that have been parsed by DNP and MODBUS.
Trellix recommends that you review each of these rules individually and read their descriptions in order to determine if they are suitable for your environment, detection strategy, and risk profile before determining whether or not to enable them for your environment.
Note
The ICS Protocols component of this rule pack rely on the presence of both DNP and MODBUS parsers. In order for the ICS Protocols rules to function in your environment, you must have a Bro sensor installed in your ICS network segment that has been correctly configured to send log files to Helix Enterprise.
Rules in the industrial control systems rule pack
The rules that comprise the Industrial Control Systems Rule Pack include:
ICS Amlware
ICS Protocols
MODBUS
DNP3
ICS malware
ICS malware families covered:
BLACKENERGY
PEACEPIPE (HAVEX)
Associated rules uncover ICS malware threats by detecting specific user agents, downloader and C2 URI patterns, and known C2 hosts.
ICS protocols
ICS protocols covered:
DNP3
MODBUS
DNP3 and MODBUS protocols do not themselves track inherently malicious activity, but can be used to uncover evidence of malicious activity depending on the environment in which they were found. Specific rules for these protocols include:
DNP3 rules
Disable Unsolicited Responses
Unsolicited Response Storm
Authorized Cold Restart
Unauthorized Cold Restart, Read Request, Write Request, Miscellaneous Request
Stop Application
Warm Restart
MODBUS rules
Illegal Function, Data Address, Data Value
Gateway Path Unavailable, Target Device Failed to Respond
Red Coils, Multiple Coils, Discrete Inputs, Holding Registers, Input Registers, Exception Status, File Records
Write Single Coil, Single Register, Multiple Registers, File Record, Mask Register
Get Comm Event Counter, Comm Event Log
Slave Device Failure, Busy
Acknowledgment
Memory Parity Error
Diagnostics