Centralized user management and network monitoring
Customer Challenge
The utility designed the next generation of its 132 kV transmission substations with cybersecurity from the ground up. The IT manager wanted to centrally manage users from a Security Operation Center and go beyond standard antivirus scanners to detect potential cybersecurity incidents.
GE's Solution
GE integrated the cybersecurity solution with the utility central user management system and implemented a network intrusion detection system (NIDS). The project scope included:
- Installation of a read-only user database replica in the substation (Read-Only Domain Controller, or RODC), synchronized with the utility's central Domain Controller
- Integration of GE's DS Agile substation automation system, Micom P40 protection relays and GE Reason switches with the RODC using LDAP and RADIUS
- Installation of a Nozomi Networks Guardian NIDS to monitor strategic points of the substation protection and control system network
Customer Benefits
- All users of the 15 substations are centrally managed therefore accesses can be quickly revoked from the central security center
- System operation is maintained when the management communication link is unavailable
- The network traffic is centrally monitored, alarming the security engineers in case of unexpected events such as connection of a new device or detection of a new type of communication protocols