Opens in a new tab

Industrial Network & OT Cybersecurity Professional Workshop

ในยุคที่ภาคอุตสาหกรรมกำลังก้าวเข้าสู่ Smart Factory, Industry 4.0, Industrial IoT และ Connected Manufacturing ระบบ Operational Technology หรือ OT ไม่ได้เป็นระบบที่แยกตัวออกจากเครือข่ายภายนอกเช่นในอดีตอีกต่อไป อุปกรณ์สำคัญ เช่น PLC, HMI, SCADA, Engineering Workstation, Historian, Industrial Switch, Industrial Firewall และ IIoT Devices ถูกเชื่อมโยงเข้ากับระบบ IT, Cloud, Remote Access และเครือข่ายของผู้ให้บริการภายนอกมากขึ้นอย่างต่อเนื่อง

การเชื่อมต่อดังกล่าวช่วยเพิ่มประสิทธิภาพในการผลิต การบริหารจัดการ และการวิเคราะห์ข้อมูล แต่ในขณะเดียวกันก็ทำให้ Attack Surface ของระบบโรงงานขยายตัวอย่างมีนัยสำคัญ และทำให้ภัยคุกคามทาง Cybersecurity สามารถเคลื่อนที่จากระบบ IT เข้าสู่ระบบ OT และอุปกรณ์ควบคุมกระบวนการผลิตได้โดยตรง

ความเสียหายในระบบ OT แตกต่างจากระบบ IT ทั่วไปอย่างชัดเจน เพราะผลกระทบไม่ได้จำกัดอยู่เพียงข้อมูลสูญหาย ระบบ Server หยุดทำงาน หรือผู้ใช้งานไม่สามารถเข้าถึง Application ได้เท่านั้น แต่ Cyberattack อาจนำไปสู่ Production Downtime, Loss of View, Loss of Control, Unauthorized PLC Commands, PLC Logic Modification, SCADA Disruption, Equipment Damage ตลอดจนผลกระทบต่อความปลอดภัยของบุคลากรและกระบวนการผลิต

ด้วยเหตุนี้ การปกป้องระบบ Industrial Network ในปัจจุบันจึงไม่สามารถพึ่งพา Firewall หรือ Network Segmentation เพียงอย่างเดียว แต่จำเป็นต้องมองระบบแบบองค์รวม ตั้งแต่

จาก Enterprise IT สู่  OT DMZ ไปยัง SCADA สู่ Engineering Workstation ไปถึง HMI และไปยัง PLC สุดท้ายที่ Sensors / Actuators และ Physical Process

ผู้ดูแลระบบจึงจำเป็นต้องเข้าใจทั้ง Industrial Networking, OT Architecture, PLC/SCADA Communication, Network Segmentation, Industrial Protocol Security, Secure Remote Access, Monitoring, Threat Detection, Incident Response และ Cyber Resilience ไปพร้อมกัน

หลักสูตร Industrial Network & OT Cybersecurity Professional Workshop ได้รับการออกแบบขึ้นเพื่อเชื่อมช่องว่างระหว่างความรู้ด้าน Industrial Network และ Cybersecurity โดยมุ่งเน้นให้ผู้เข้าอบรมสามารถนำความรู้ไปประยุกต์ใช้กับระบบโรงงานและ Critical Infrastructure ได้จริง

ผู้เรียนจะไม่ได้เรียนเพียงว่า PLC, SCADA, Purdue Model, IEC 62443 หรือ OT Firewall คืออะไร แต่จะได้เรียนรู้ถึงวิธีการออกแบบ ป้องกัน ตรวจสอบ และรับมือกับภัยคุกคามที่เกิดขึ้นในสภาพแวดล้อม OT จริง เช่น

  • การออกแบบ Industrial Network ที่มีความมั่นคงและมี Redundancy
  • การแบ่ง Network ตาม Purdue Model และแนวคิด Zone & Conduit
  • การแยก PLC, HMI, SCADA และ Engineering Workstation ออกจากกันอย่างเหมาะสม
  • การควบคุมว่าอุปกรณ์ใดสามารถติดต่อ PLC ได้ และสามารถใช้ Protocol หรือ Command ใดได้บ้าง
  • การ Hardening PLC, SCADA Server, HMI และ Engineering Workstation
  • การตรวจจับ Unauthorized PLC Access และ Abnormal Industrial Protocol Traffic
  • การสร้าง OT Communication Baseline
  • การป้องกัน Lateral Movement จาก IT Network เข้าสู่ OT Network
  • การควบคุม Vendor Remote Access และ Maintenance Access
  • การใช้ Industrial Firewall และ Allow-List Security Policy
  • การตรวจสอบ Traffic ผ่าน SPAN / Mirror Port
  • การวิเคราะห์เหตุการณ์โดยอ้างอิง MITRE ATT&CK for ICS
  • การตอบสนองต่อ Cyber Incident โดยคำนึงถึง Safety และ Production Continuity
  • การ Backup และ Recover PLC Logic, SCADA Configuration และอุปกรณ์ Network ที่สำคัญ

จุดเด่นสำคัญของหลักสูตรคือการเรียนในรูปแบบ Professional Workshop ที่เน้นการลงมือปฏิบัติผ่าน Hands-on Labs และ Scenario ที่จำลองสถานการณ์ใกล้เคียงกับระบบจริง โดยผู้เรียนจะได้ฝึกตั้งแต่การสำรวจ Asset การออกแบบ Network การ Configure Industrial Switch และ Firewall การวิเคราะห์ Industrial Protocol ไปจนถึงการตรวจจับและรับมือกับเหตุการณ์ Cybersecurity ในระบบ OT

หลักสูตรนี้จึงไม่ได้มีเป้าหมายเพียงเพื่อให้ผู้เรียน “รู้จัก OT Cybersecurity” แต่ต้องการให้ผู้เรียนสามารถกลับไปยังองค์กรของตนเองแล้วตอบคำถามสำคัญได้ว่า

  • อุปกรณ์ใดใน OT Network ของเรามีความสำคัญที่สุด?
  • ใครสามารถเข้าถึง PLC และ SCADA ได้บ้าง?
  • Traffic แบบใดเป็นพฤติกรรมปกติ และแบบใดควรถูกตรวจสอบ?
  • หาก Engineering Workstation ถูกโจมตี ผู้โจมตีสามารถเดินทางไปถึง PLC ได้หรือไม่?
  • หาก PLC Logic ถูกเปลี่ยน เราจะตรวจพบและกู้คืนได้อย่างไร?
  • และหากเกิด Cyber Incident เราจะ Isolation ระบบอย่างไรโดยไม่ทำให้ Production หยุดหรือกระทบต่อ Safety?

เมื่อจบหลักสูตร ผู้เรียนจะมีมุมมองที่ครบถ้วนตั้งแต่ระดับ Network Infrastructure ไปจนถึง Control System Security และสามารถนำหลักการ Protect, Detect, Respond และ Recover ไปประยุกต์ใช้ในการเพิ่มความมั่นคงปลอดภัยให้กับ Industrial Network และ OT Environment ขององค์กรได้อย่างเป็นระบบ

รายละเอียดหลักสูตร

Part 1: Foundations of Industrial Networking and OT Systems

1. Introduction to Industrial Network and OT Environment

  • Operational Technology (OT)
  • Industrial Control System (ICS)
  • Supervisory Control and Data Acquisition (SCADA)
  • Distributed Control System (DCS)
  • Programmable Logic Controller (PLC)
  • Safety Instrumented System (SIS)
  • IT Security vs OT Security Priorities
  • Confidentiality, Integrity and Availability
  • Safety, Availability, Reliability and Determinism
  • Production downtime and operational impact
  • Equipment lifecycle differences
  • Deterministic communication
  • Real-time operation
  • High availability
  • Long equipment lifecycle
  • Legacy system considerations
  • Manufacturing  |  Energy  |  Utilities | Water treatment
  • Transportation  | Building automation  | Critical infrastructure

2. Industrial Control System Components

  • Safety PLC  |  SIS
  • Emergency shutdown systems
  • Separation between control and safety systems
  • Asset inventory  |  Device identification  |  Criticality classification
  • Firmware and software inventory
  • Communication dependency
  • Critical controllers  |  Critical servers  |  Engineering systems
  • Safety-related assets  |  Legacy devices
  • Unsupported operating systems

3. Industrial Communication Fundamentals

  • Impact on production processes
  • Impact on control loops
  • Troubleshooting communication degradation
  • Normal communication baseline
  • Periodic communication
  • Client/server behavior
  • Controller polling behavior
  • Unexpected communication

4. Industrial Protocols and Protocol Security

  • Modbus RTU  / Modbus TCP / PROFINET / EtherNet/IP / DNP3
  • OPC UA / BACnet  /  MQTT
  • IEC 60870-5-104  /  IEC 61850
  • Legacy protocol security limitations  |  Protocols without authentication
  • Protocols without encryption  |  Read vs write operations
  • Control commands and process impact
  • Modbus Function Codes
  • Read Coil / Register  |  Write Coil / Register
  • Normal vs abnormal commands
  • Restricting write operations
  • Protocol allow-listing
  • Authentication  |  Certificate management
  • Encryption  |  Secure channel
  • User and application authentication
  • Authentication
  • TLS
  • Topic permissions
  • Broker security
  • Publish/Subscribe authorization
  • Protocol anomaly detection  |  Unexpected function codes
  • Unauthorized write operations  |  Unauthorized controller access
  • Abnormal communication frequency

5. Industrial Network Topologies

  • Star  / Ring  / Redundant Ring
  • Line  / Tree  Hybrid topology

5.2 Hierarchical Industrial Networks

5.3 Resiliency, Failover and Recovery Time

5.4 Single Point of Failure Analysis

6. OT Network Design Principles

6.1 Purdue Model / ISA-95 Overview

6.2 Purdue Levels 0–5

6.3 OT Cell / Area Zone Design

6.4 Industrial DMZ

6.5 Separation Between Enterprise IT and Plant Floor Network

6.6 Separation of Safety and Control Networks

6.7 North-South and East-West OT Traffic

6.8 Secure Architecture for Connected Factory

  • IT Network
  • OT Network
  • Industrial DMZ
  • SCADA Zone
  • Engineering Zone
  • PLC/Controller Zone
  • Safety Zone
  • IIoT Zone
  • Vendor Remote Access Zone

Part 2: Industrial Switch Installation, Configuration and Resilient Design

7. Introduction to Industrial Switch

  • DIN rail
  • Temperature tolerance
  • Vibration
  • EMC
  • Industrial power requirements

7.3 Managed vs Unmanaged Industrial Switch

7.4 Layer 2 / Layer 3 Capability

7.5 PoE and Non-PoE Industrial Workloads

8. Physical Installation of Industrial Switch

8.1 Cabinet and Panel Installation

8.2 DIN Rail Installation

9. Initial Configuration and Secure Management

  • HTTPS
  • SSH
  • Disable insecure services
  • Console access policy
  • Individual administrator accounts
  • Role-based access
  • Password policy
  • AAA
  • TACACS+
  • RADIUS

10. VLAN and Segmentation for OT

10.1 VLAN Concepts for Industrial Environments

10.2 Segmentation by Cell / Area / Line / Process

10.3 Access Ports and Trunk Ports

10.4 Separation of

  • PLC  |  HMI  |  SCADA  |  Engineering Workstation
  • CCTV  |  IIoT  |  Wireless  |  Management

10.5 Inter-VLAN Communication Design

10.6   Security Risks of Flat OT Networks

10.7   Micro-Segmentation Concepts for OT

11.   Industrial Network Resiliency

11.1   STP / RSTP / MSTP

11.2   Ring Redundancy Protocols

11.3   MRP / ERPS / Proprietary Ring Protocols

11.4   Link Aggregation and Uplink Redundancy

11.5   Fast Convergence Requirements

11.6   Failover and Recovery Testing

12.   Industrial Switch Security Hardening

12.1   Disable Unused Ports

12.2   Port Security

12.3   BPDU Guard / Root Guard

12.4   Storm Control

12.5   MAC Control and Access Restrictions

12.6   AAA / TACACS+ / RADIUS in OT

12.7   Management Plane Protection

12.8   Configuration Change Monitoring

12.9   Logging and Security Auditing

Part 3: PLC, HMI and SCADA Cybersecurity

13.   PLC Cybersecurity

  • PLC architecture
  • PLC operating modes
  • RUN / STOP / PROGRAM modes
  • PLC logic and process control
  • PLC communication interfaces
  • Default credentials
  • Unauthorized programming access
  • Unrestricted engineering access
  • Insecure industrial protocols
  • Unauthorized logic modification
  • Firmware vulnerabilities
  • Uncontrolled remote access
  • Physical access risk
  • Protecting PLC project files
  • Controller access control
  • Engineering authentication
  • Change authorization
  • Logic change monitoring
  • Configuration integrity
  • Restricting source systems permitted to communicate with PLC
  • Allow-list communication model
  • Restricting programming protocols
  • Restricting write commands
  • Protecting controller management interfaces
  • PLC configuration backup
  • Logic/program backup
  • Version management
  • Offline backup
  • Golden PLC configuration
  • Restore verification
  • Detect unauthorized PLC access
  • Detect unexpected programming activity
  • Detect abnormal write commands
  • Detect controller mode changes
  • Detect new communication sources

14. HMI Cybersecurity

  • Shared accounts
  • Legacy operating systems
  • Malware
  • Unauthorized software
  • USB/removable media
  • Remote desktop exposure
  • Account management
  • Least privilege
  • Application allow-listing concept
  • Disable unnecessary services
  • Host firewall
  • USB control
  • Patch management strategy
  • Expected communication baseline
  • Restricting HMI access
  • Preventing unauthorized HMI systems

15. SCADA Cybersecurity

  • SCADA server
  • HMI
  • Historian
  • Engineering workstation
  • OPC server
  • Database
  • Communication gateway
  • OS hardening
  • User and administrator separation
  • Service reduction
  • Application control
  • Firewall policy
  • Patch management
  • Anti-malware / EDR considerations
  • Authentication
  • Role-Based Access Control
  • Operator privileges
  • Engineer privileges
  • Administrator privileges
  • Audit logs
  • Configuration change tracking
  • SCADA-to-PLC policy
  • SCADA-to-Historian policy
  • Engineering-to-PLC policy
  • IT-to-SCADA restrictions

15.5 SCADA Availability Protection

  • Server redundancy  |  Network redundancy
  • Backup  |  Recovery
  • Configuration replication
  • Availability monitoring

16. Engineering Workstation Security

17. OT Endpoint and Server Hardening

  • SCADA Server
  • HMI
  • Historian
  • Engineering Workstation
  • OPC Server

17.2 Account Security

17.3 Least Privilege

17.4 Host Firewall

17.5 Endpoint Protection

17.6 Application Allow-Listing

17.7 Patch and Vulnerability Management

17.8 USB / Removable Media Security

17.9 Secure Backup

17.10 Legacy Windows and Unsupported Systems

  • Compensating controls
  • Isolation
  • Network restriction
  • Application control
  • Monitoring

Part 4: OT Firewall, Zone-Based Security and Secure Access Design

18. OT Cybersecurity Fundamentals

18.1 IT Threats vs OT Threats

18.2 Ransomware Impact on Manufacturing

18.3 Unauthorized Remote Access

18.4 Lateral Movement in Industrial Environments

18.5 Malware Entering Through Engineering Workstations

18.6 USB-Based Threats

18.7 Compromised Vendor Access

18.10 Cyber-to-Physical Impact

  • Loss of control
  • Loss of view
  • Process manipulation
  • Production shutdown
  • Equipment damage
  • Safety consequences

19. Standards and Frameworks for OT Security

19.1 IEC 62443 Overview

19.2 NIST Cybersecurity Framework

19.3 NIST SP 800-82

19.4 Defense-in-Depth for Industrial Systems

19.6 Cybersecurity Risk Assessment for OT

20. OT Zone and Conduit Design

  • Control Zone
  • Safety Zone
  • Supervisory Zone
  • Engineering Zone
  • Enterprise Zone

20.4 OT DMZ Architecture

20.5 Secure Remote Access Architecture

20.6 Jump Server and Engineering Access Control

20.7 Vendor Access Zone

21. Industrial Firewall / OT Firewall Implementation

  • PLC
  • HMI
  • SCADA
  • Historian
  • Engineering Workstation
  • IT Network

21.6 OT Allow-List Security Model

21.7 Industrial Protocol-Aware Security

21.8 Restricting Industrial Commands

21.9 Logging, Alerting and Event Correlation

22. GUI / Policy Workshop for OT Firewall

22.1 Configure Interface Zones

22.2 Configure Address and Service Objects

22.3 Configure Allow Policies for Critical Traffic Only

22.4 Restrict Engineering Workstation Access

22.5 Restrict SCADA Server Access to PLC

22.6 Block Unauthorized IT-to-OT Communication

22.7 Control PLC Programming Traffic

22.8 NAT vs No-NAT in OT

22.9 Policy Validation

22.10 Firewall Troubleshooting

23. Secure Remote Access to OT Systems

23.1 VPN for Vendors and Maintenance Teams

23.2 MFA for Remote Access

23.3 Bastion / Jump Host

23.4 Session Recording

23.5 Time-Based Access

23.6 Approval-Based Access

23.7 Third-Party Access Governance

23.8 Emergency Remote Access

23.9 Disabling Access After Maintenance

Part 5: OT Monitoring, Threat Detection and Incident Response

24. OT Monitoring and Visibility

24.1 Network Visibility in Industrial Environments

24.2 SPAN / Mirror Port for OT Monitoring

24.3 IDS/IPS for ICS Traffic

24.4 Passive Monitoring vs Active Scanning

24.5 Syslog / NetFlow / SNMP / OT Telemetry

24.6 Passive Asset Discovery

24.7 Asset Communication Mapping

24.8 OT Network Baseline

25. OT Threat Detection

25.1 Baseline Normal OT Traffic

25.2 Detect Abnormal Command Patterns

25.3 Unauthorized Modbus Function Codes

26. OT Incident Response

27. SCADA Incident Handling

28. OT Backup, Recovery and Cyber Resilience

29. OT Vulnerability and Security Assessment

Part 6: End-to-End Industrial Security Architecture Workshop

30. End-to-End Industrial Security Architecture

Hands-on Labs

Module A: Industrial Network Foundations

Lab 1: OT/ICS Asset Discovery and Purdue Model Mapping: สำรวจอุปกรณ์และจัดประเภท PLC, HMI, SCADA, Engineering Workstation และอุปกรณ์ Network ตาม Purdue Model

Lab 2: Industrial Protocol Traffic Analysis: วิเคราะห์ Traffic ของ Modbus TCP และ EtherNet/IP

Lab 3: Factory Network Topology Design: สร้าง Network Topology จาก Factory Scenario

Lab 4: OT Segmentation Design: ออกแบบ Segmentation สำหรับ Production Line 1 และ Production Line 2

Module B: Industrial Switch Security

Lab 5: Industrial Switch Initial Setup

Lab 6: Secure Management Configuration: ตั้งค่า Management IP, Management VLAN, SSH/HTTPS และ NTP

Lab 7: PLC/HMI/SCADA VLAN Segmentation: สร้าง VLAN แยก PLC, HMI, SCADA และ Engineering Workstation

Lab 8: Access and Trunk Port Configuration

Lab 9: Industrial Network Failover: ทดสอบ STP / Ring Redundancy และ Recovery Time

Lab 10: Link Redundancy and Uplink Protection

Lab 11: SNMP, Syslog and Monitoring Integration

Lab 12: Industrial Switch Hardening: ใช้ Port Security, Storm Control, BPDU Guard และปิด Unused Ports

Module C: PLC / SCADA Cybersecurity Labs

Lab 13: PLC Security Baseline Assessment: ตรวจสอบ PLC จำลองในด้านต่อไปนี้

  • Network accessibility
  • Management access
  • Industrial protocolEngineering accessAuthentication
  • Backup status
  • สร้าง PLC Security Baseline

Lab 14: Modbus TCP Security Analysis: ใช้ Packet Capture วิเคราะห์ ดังนี้

  • Read request
  • Write request
  • Function CodeSource / Destination
  • Normal vs abnormal communication

ผู้เรียนต้องระบุว่า communication ใดควรได้รับอนุญาตและ communication ใดควรถูก Block

Lab 15: PLC Communication Allow-Listing: สร้าง Security Policy ให้เฉพาะเช่น

  • Authorized HMI
  • Authorized SCADA
  • Authorized Engineering Workstation

ให้สามารถติดต่อ PLC ได้ และทดสอบว่า Unauthorized Workstation ไม่สามารถเข้าถึง Controller ได้

Lab 16: Detect Unauthorized PLC Command: จำลองคำสั่ง Industrial Protocol ภายใน Lab ที่แตกต่างจาก Normal Baseline และตรวจจับดังนี้

  • Unexpected source
  • Unexpected function
  • Unexpected write operation

โดยไม่เปลี่ยนแปลง Physical Process จริง

Lab 17: SCADA Server Hardening: ตรวจสอบและปรับปรุงในเรื่องดังต่อไปนี้

  • User account
  • Administrator privilege
  • Host firewallUnnecessary servicesRemote accessLogging
  • Backup configuration

Lab 18: Engineering Workstation Hardening: โดยการตั้งค่า

  • Restricted administrator access
  • USB control
  • Host firewallInternet restrictionEngineering-to-PLC access
  • Logging

Lab 19: PLC Logic and Configuration Backup: โดยการสร้าง

  • PLC Program Backup
  • Configuration Backup
  • Version Identification
  • Golden Configuration

และจำลองกระบวนการ Restore Verification

Lab 20: SCADA-to-PLC Security Policy: โดยกำหนดว่า

  • ใครสามารถ Read
  • ใครสามารถ Write
  • ใครสามารถ Program PLCใครสามารถ Monitor
  • Communication ใดต้องถูก Block

Module D: OT Firewall and Secure Access Labs

Lab 21: OT Firewall Initial Setup

Lab 22: Routed Mode vs Transparent Mode Demonstration

Lab 23: Zone-Based OT Security Policy: สร้าง:   IT Zone  |  OT DMZ  |  SCADA Zone  |  Engineering Zone  |  PLC Zone

Lab 24: Authorized SCADA-to-PLC Communication: สร้าง Allow-List Policy สำหรับ Critical Industrial Traffic เท่านั้น

Lab 25: Block Unauthorized IT-to-OT Access: จำลองเครื่องจาก IT Network พยายามเข้าถึง OT Zone และตรวจสอบ Firewall Log

Lab 26: Controlled Engineering Access: กำหนด Engineering Workstation ให้สามารถเข้าถึง PLC ได้เฉพาะ Service และช่วงเวลาที่กำหนด

Lab 27:  Secure Vendor Remote Access: สร้าง Scenario และจำกัดสิทธิ์ตามหลัก Least Privilege

Lab 28: OT Firewall Logging and Policy Troubleshooting: โดยการวิเคราะห์ ดังต่อไปนี้

  • Allowed traffic
  • Denied traffic
  • Incorrect policyUnexpected communication
  • Industrial protocol traffic

Module E: OT Monitoring, Detection and Incident Response

Lab 29: Passive OT Monitoring with Mirror Port: ใช้ SPAN / Mirror Port ส่ง Traffic ไปยัง Monitoring Station โดยไม่กระทบ Production Network และสร้าง Communication Map

PLC ↔ HMI ↔ SCADA ↔ Engineering Workstation

Lab 30: OT Cybersecurity Incident Response