|
ArcSight Playing Critical Role in the
LOGIIC Consortium Aimed at Improving
the Security of Oil and Gas Critical
Infrastructure
ArcSight Providing the
Industry’s First and Only Fully Tested
ESM Solution to Manage Sensitive
Information Critical to Protecting Oil
and Gas IT Networks
CUPERTINO, Calif. – September
28, 2006 – ArcSight, Inc., a
global leader in Enterprise Security
Management (ESM) software, today
announced it is the first vendor to
successfully integrate its solution
with Process Control System security
technology to improve safety measures
for oil and gas critical
infrastructure protection. The
integration was performed as part of
the LOGIIC Correlation Project, a
collaborative project between the
Department of Homeland Security and
private industry to help protect oil
and gas operations from cyber security
threats, such as viruses, worms and
cyber terrorism.
The integrated solution leverages
ArcSight’s cutting edge ESM technology
and represents the first test of this
type to deliver an expertly developed,
fully tested solution that enables the
integration and centralization of
security information from vulnerable
points of entry within oil and gas IT
and process control networks. The
solution then correlates this
information to detect, prioritize, and
alert about cyber attacks in progress.
Oil and gas companies have
recognized that their computerized
process control systems need to be
carefully protected against cyber
security threats. Because of increased
automation and the introduction of new
computer and communications technology
to control production, transportation
and processing of natural gas and
petroleum products, new security
technologies are required to guarantee
the security and safety of this
critical infrastructure. To address
these challenges, the LOGIIC
Consortium is leveraging ArcSight’s
advanced correlation engine to
integrate multiple oil and gas IT and
process control networks to provide
users with an increased level of
visibility into the security pipeline.
"Cyber attacks are of particular
concern for the highly automated oil
and gas industry, where malicious
system manipulation could cause
catastrophic losses in terms of human
lives, the environment and the
economy," said Ulf Lindqvist, program
director at SRI International.
"ArcSight’s ESM solution was
installed in Sandia National
Laboratory’s Center for Control
Systems Security where researchers
simulated security vulnerabilities in
the system," said Ben Cook, research
coordinator at Sandia National Labs.
"We developed a number of
vulnerability scenarios to test the
monitoring solution proposed in LOGIIC,
which relies on an ESM platform to
integrate security and other system
events into a comprehensive, real-time
picture of adversarial actions."
"ArcSight’s enterprise security
management system was selected to play
a significant role in this critical
initiative to help ensure the safety
of the oil and gas critical
infrastructure," said Steve Sommer,
SVP of marketing and business
development at ArcSight. "As part of
this industry-government initiative,
ArcSight demonstrated that it was able
to integrate with the Process Control
System infrastructure, identify the
most complex attacks and enable
security staff to quickly respond to
these threats."
The LOGIIC Correlation Project
working group was comprised of experts
in homeland security, oil and gas,
security research, security technology
and process control technology.
- Government: U.S. Department of
Homeland Security, Science and
Technology Directorate
- Oil and Gas Industry: Chevron,
CITGO, BP and Ergon Refining
- Research: Sandia National
Laboratories, SRI International and
Adventium Labs
- Security Vendors: ArcSight,
3Com, and Symantec Corporation
- Process Control Technology
Vendors: Honeywell, OMNI Flow
Computers and Telvent
About the LOGIIC Consortium
The LOGIIC (Linking the
Oil and Gas Industry to Improve Cyber
Security) Consortium is a model
example of a partnership between
Government and Industry that is
committed to combining resources to
define and advance the security of the
Oil and Gas Industry. More information
can be found at the
LOGIIC website.
About ArcSight
ArcSight, a leader in Enterprise
Security Management, provides
solutions that serve as the mission
control center for real-time threat
management, compliance reporting and
automated network response. By
comprehensively collecting, analyzing
and managing security data, ArcSight
solutions centrally manage and
mitigate information risk for
security, insider threat and
compliance. ArcSight's customer base
includes leading global enterprises,
government agencies and MSSPs.
###
Contact Information:
Erin O’Keeffe
Horn Group for ArcSight
415-905-4005
eokeeffe@horngroup.com
For more information on ArcSight
news, please contact: pr@arcsight.com
|