A security analyst is reviewing network traffic on a segment hosting critical industrial control systems (ICS). The analyst observes unusual Modbus/TCP traffic patterns, specifically a high volume of `Function Code 0x03 (Read Holding Registers)` requests originating from a previously unknown internal IP address (10.10.20.15) targeting multiple Programmable Logic Controllers (PLCs). The requests are not part of any scheduled maintenance or known operational procedures. Which of the following actions should the analyst take FIRST?
- ACapture full packet data for deeper analysis.
- BIsolate the source IP (10.10.20.15) from the network.
- CConfirm the legitimate purpose of the observed traffic with ICS/OT engineers.
- DInitiate a full incident response process.
Show answer & explanationAnswer & explanation
Correct answer: C. Confirm the legitimate purpose of the observed traffic with ICS/OT engineers.
In ICS/OT environments, unexpected but potentially benign activity can often be mistaken for malicious. Before taking drastic actions like isolation or full incident response, it's crucial to confirm with OT engineers if the observed traffic (e.g., `Read Holding Registers` from a new source) is part of a legitimate but undocumented process, a new sensor, or a diagnostic tool. Misinterpreting legitimate traffic in OT can cause operational disruptions that are often more severe than IT incidents.
Why the other options are wrong
- A. While capturing packet data is a valuable step for deeper analysis, it should ideally follow initial confirmation with engineers. If the activity is legitimate, further capture might be unnecessary. If it's malicious, the confirmation step helps contextualize the capture.
- B. Isolating the source IP without confirmation could disrupt legitimate ICS operations, which is highly undesirable in OT environments. This is a severe action to take without first confirming malicious intent.
- D. Initiating a full incident response process immediately without confirming the nature of the traffic is premature and could waste resources or cause unnecessary alarm. Confirmation is a critical first step in OT environments.
OT/ICS Security Considerations
Operational Technology (OT) and Industrial Control Systems (ICS) security prioritize safety, availability, and integrity over confidentiality. Incidents can have severe physical consequences, making careful validation of anomalies with operational teams a critical first step before disruptive security actions.
- Priorities: Safety > Availability > Integrity > Confidentiality.
- Impacts: Physical damage, environmental hazards, production loss.
- Verification: Always consult with OT engineers before acting on anomalies.
Memory trick: OT incidents require careful steps to avoid physical harm.