Crucial To Deployment

Ethernet switch technology plays key role in NERC CIP perimeter security requirements

Common sense—and the North American Electric Reliability Council’s cyber security standards (NERC CIP) for North America—suggests that security in power stations is of utmost importance. With the growth of IP-based network applications throughout the power industry, power plants have increased their ability to control and monitor both central utility operations and remote installations. NERC identifies security concerns and lists out a set of requirements for minimum security in the industry.

Physical security, as defined by NERC CIP, has an IP component to it. The standards-based flexibility of IP-compatible products provides the bestknown solution for the security and surveillance of power plants.

At one nuclear power plant, thermal imaging infrared cameras are installed around the physical perimeter of the facility to provide state-of-the-art threat detection and assessment capability. The plant is protected by a FLIR thermal fence, which provides a full-integrated perimeter alert system.

The perimeter protection solution incorporates both thermal security cameras and the FLIR sensors manager control and management software to create a full virtual fence solution, capable of protecting critical infrastructure sites.

Underlying Network Support

In order to connect the virtual fence with staff in the plant and at central operations, Ethernet switches that can operate reliably under the harsh conditions at the plant were required. Because the perimeter security is integrated with a single ring-based network within the facility, which is required to securely manage a variety of functions, the switches need a variety of port types to support various equipment requirements.

Externally located switches that connect to components of the thermal fence needed to be hardened to withstand harsh temperatures (-40 to 85 degrees C). In addition, they needed to be outfitted with sealed cases that would protect against rain, dirt and other contaminants. While some designers attempt to use commercial switches with elaborate protection schemes or dramatically reduced MTBF expectations, industrially hardened switches—in this case, Magnum 6K field switches—solve the problem with a sealed, convectioncooled model that features an advanced thermal design that allows the case to serve as a heat sink.

Magnum switches offer unique portconfiguration capabilities that provide the highest level of flexibility in specifying port types. The outdoor units are specified with a number of managed PoE ports that enable both data and power to run over a single cable to support the cameras.

Video Data Management

Managing a high volume of security data from the videos requires sophisticated data management capabilities, such as IGMP Snooping and IGMP-L2, because of the high bandwidth requirements of a video surveillance system. For efficiency, it is important to develop a way to selectively manage IP video multicast traffic. The common approach uses the standard Internet Group Management Protocol (IGMP), which requires routers in addition to switches. GarrettCom’s IGMP-L2 is a switchbased system that simplifies the network and eliminates wasted bandwidth consumption while still permitting large numbers of multicast data streams to be efficiently handled with video feeds delivered to suit each viewing user’s needs.

Ring Topology

The switches are organized into interlocking ring configurations that provide rapid fault recovery to meet the plant’s needs for highest reliability. The switches offer fast link recovery using RSTP-2004.

The network topology requires a full range of fiber and copper port options, as well as a variety of bandwidths. Switch capabilities range from server room switches with up to 32 ports and gigabit bandwidth support for fiber backbones to smaller field switches that can support connectivity to the security system components and intelligent electronic devices (IED) within the plant. VLANs are used to provide secure communication tunnels. Secure switch management software can provide an extra level of reliability including functionality, such as SSH and SSL access, Secure FTP connections for large file transfers, software downloads, configuration files, scripts, support for up to 256 VLANs, Modbus protocol support over TCP/IP, TACACS and RADIUS server authentication, and the ability to have external events (Syslog) put into the switch’s Event Log to correlate with local security events.

The use of IP for power utility perimeter security—and, in fact, for all utility networking—adds a new level of flexibility and bandwidth. Although there is concern among some in the industry that IP provides a new level of risk of cyber attack, it is clear that even NERC recognizes that the benefits of the increased functionality outweigh the concerns. Careful and insightful development of security infrastructure can provide security systems that are not only effective today but are futureproof and scalable to meet future needs.

This article originally appeared in the March 2012 issue of Security Today.

Featured

  • AI Is Now the Leading Cybersecurity Concern for Security, IT Leaders

    Arctic Wolf recently published findings from its State of Cybersecurity: 2025 Trends Report, offering insights from a global survey of more than 1,200 senior IT and cybersecurity decision-makers across 15 countries. Conducted by Sapio Research, the report captures the realities, risks, and readiness strategies shaping the modern security landscape. Read Now

  • Analysis of AI Tools Shows 85 Percent Have Been Breached

    AI tools are becoming essential to modern work, but their fast, unmonitored adoption is creating a new kind of security risk. Recent surveys reveal a clear trend – employees are rapidly adopting consumer-facing AI tools without employer approval, IT oversight, or any clear security policies. According to Cybernews Business Digital Index, nearly 90% of analyzed AI tools have been exposed to data breaches, putting businesses at severe risk. Read Now

  • Software Vulnerabilities Surged 61 Percent in 2024, According to New Report

    Action1, a provider of autonomous endpoint management (AEM) solutions, today released its 2025 Software Vulnerability Ratings Report, revealing a 61% year-over-year surge in discovered software vulnerabilities and a 96% spike in exploited vulnerabilities throughout 2024, amid an increasingly aggressive threat landscape. Read Now

  • Motorola Solutions Named Official Safety Technology Supplier of the Ryder Cup through 2027

    Motorola Solutions has today been named the Official Safety Technology Supplier of the 2025 and 2027 Ryder Cup, professional golf’s renowned biennial team competition between the United States and Europe. Read Now

  • Evolving Cybersecurity Strategies

    Organizations are increasingly turning their attention to human-focused security approaches, as two out of three (68%) cybersecurity incidents involve people. Threat actors are shifting from targeting networks and systems to hacking humans via social engineering methods, living off human errors as their most prevalent attack vector. Whether manipulated or not, human cyber behavior is leveraged to gain backdoor access into systems. This mainly results from a lack of employee training and awareness about evolving attack techniques employed by malign actors. Read Now

New Products

  • Luma x20

    Luma x20

    Snap One has announced its popular Luma x20 family of surveillance products now offers even greater security and privacy for home and business owners across the globe by giving them full control over integrators’ system access to view live and recorded video. According to Snap One Product Manager Derek Webb, the new “customer handoff” feature provides enhanced user control after initial installation, allowing the owners to have total privacy while also making it easy to reinstate integrator access when maintenance or assistance is required. This new feature is now available to all Luma x20 users globally. “The Luma x20 family of surveillance solutions provides excellent image and audio capture, and with the new customer handoff feature, it now offers absolute privacy for camera feeds and recordings,” Webb said. “With notifications and integrator access controlled through the powerful OvrC remote system management platform, it’s easy for integrators to give their clients full control of their footage and then to get temporary access from the client for any troubleshooting needs.”

  • QCS7230 System-on-Chip (SoC)

    QCS7230 System-on-Chip (SoC)

    The latest Qualcomm® Vision Intelligence Platform offers next-generation smart camera IoT solutions to improve safety and security across enterprises, cities and spaces. The Vision Intelligence Platform was expanded in March 2022 with the introduction of the QCS7230 System-on-Chip (SoC), which delivers superior artificial intelligence (AI) inferencing at the edge.

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening.