Purdue Model for OT Network

IT Network မှာ OSI 7 Layers ရှိသလိုပဲ၊ OT Network မှာလည်း Layer တွေ ခွဲခြားသတ်မှတ်ပေးထားတဲ့ Purdue Model ဆိုတာ ရှိပါတယ်။

OT Network ကို စီမံခန့်ခွဲမယ့်သူ သို့မဟုတ် Security ပိုင်း လုပ်ဆောင်မယ့်သူဆိုရင် Purdue Model ကို သေချာ နားလည်ထားဖို့ လိုအပ်ပါတယ်။

Layer 0: Physical Process

ဒီ Level မှာ Sensors, Actuators, Motors, Valves, Pumps တွေ အလုပ်လုပ်ပါတယ်။

ဥပမာ - ရေသန့်စက်ရုံတစ်ခုမှာ ပိုးသတ်ဆေး ထည့်တဲ့ လုပ်ငန်းစဉ်အတွင်း ပိုးသတ်ဆေး ပမာဏကို တိုင်းပေးတဲ့ Sensors တွေနဲ့ သတ်မှတ်ပမာဏ ရောက်တဲ့အခါ ဆေးထည့်တာ ရပ်တန့်ဖို့ ထိန်းချုပ်ပေးတဲ့ Valves တွေ အလုပ်လုပ်တာမျိုး ဖြစ်ပါတယ်။

Layer 1: Basic Control

ဒီ အပိုင်းမှာ PLCs (Programmable Logic Controllers), RTUs (Remote Terminal Units), IEDs (Intelligent Electronic Devices) တွေ ရှိပြီး Layer 0 မှာ အလုပ်လုပ်နေတဲ့ Physical Equipment တွေကို တိုက်ရိုက် ထိန်းချုပ်ခိုင်းစေတာပါ။

ဥပမာ - Shopping Mall တွေက Lift တွေ၊ Escalator တွေရဲ့ အမြန်နှုန်းနဲ့ အတက်အဆင်း Logic တွေကို PLC ထဲမှာ ရေးသွင်းထားပြီး အလိုအလျောက် အလုပ်လုပ်စေတာမျိုး ဖြစ်ပါတယ်။

Layer 2: Area Control (Supervisory Control)

ဒီ Layer ကတော့ HMIs (Human Machine Interfaces), SCADA Software, Engineering Workstations, Control Rooms တွေနဲ့ စနစ်တစ်ခုလုံးကို စောင့်ကြည့်တာနဲ့ ထိန်းချုပ်တဲ့ နေရာပါ။

ဒီအပိုင်းမှာ လူ Operator က ဝင်ရောက်ကြည့်ရှုပြီး လိုအပ်သလို ထိန်းချုပ်မှုများ ပြုလုပ်ပေးနိုင်ပါတယ်။

ဥပမာ - Lift ၄ စင်း Run နေတဲ့ Mall တစ်ခုမှာ မနက် 9 နာရီကနေ 10 နာရီအတွင်း လူအတက် ပိုများတာကို Control Room (HMI/SCADA) ကနေ တွေ့ရှိရတယ် ဆိုပါစို့။ ဒါဆိုရင် Lift အတက်/အဆင်း Mode တွေကို ပြောင်းလဲဖို့ သို့မဟုတ် Lift Controller Program တွေကို Engineering Workstation ကနေ Program Logic ကို ပြင်တာမျိုးလုပ်တာပါ။

Layer 3: Site Manufacturing Operations and Control

ဒီ အပိုင်းမှာ MES (Manufacturing Execution Systems), Historian Servers, Domain Controllers, Patch Management Servers, OT Jump Hosts စတာတွေ ပါဝင်ပါတယ်။

ဒီ Layer က Layer 2 Control က နေ monitoring လုပ်နေတဲ့ နေရာတွေအားလုံးရဲ့  အခြေအနေတွေကို ပေါင်းစပ် စီမံခန့်ခွဲပေးတာ ဖြစ်ပါတယ်။ Layer 1 နဲ့ Layer 2 က ရလာတဲ့ Logging Data တွေ ၊ Process Data တွေကို Historian Server မှာ သိမ်းပြီး Operation Improvement နဲ့ Audit တွေအတွက် ပြန်လည် ဆန်းစစ်တာမျိုး ဆောင်ရွက်ပါတယ်။

Layer 4: Enterprise Business Planning and Logistics (Enterprise IT Zone)

ဒီ Layer ကတော့ Enterprise IT Network အဆင့် ဖြစ်သွားပြီး ERP (e.g., SAP), Mail Servers, Business Applications, Corporate PCs တွေ ပါဝင်လာပါပြီ။

Layer 5: Enterprise Network / External Zone (Cloud & Internet)

ဒီ အပိုင်းမှာ Cloud Infrastructure (AWS, Azure), Corporate WAN, Internet Boundary, Third-party/Vendor Portals စတာတွေ ပါဝင်ပြီး ရုံးခွဲများ၊ Vendors များနှင့် Partners တွေ နဲ့ ချိတ်ဆက်အလုပ်လုပ်တဲ့ Network Boundary ဖြစ်ပါတယ်။

ဒါတွေကတော့ Purdue Model ရဲ့ Layer အဆင့်ဆင့်ပဲ ဖြစ်ပါတယ်။

Layer 3 (OT) နဲ့ Layer 4 (IT) ကြားမှာ Physical Connection လုံးဝ မထားတဲ့ Air-Gapped Systems တွေ ရှိသလို၊ နောက်ပိုင်းမှာ Industrial DMZ (IDMZ) လို့ ခေါ်ကြတဲ့ Layer 3.5 ဆိုတာကို ထားလာကြပါတယ်။ ဘာကြောင့် ဒီလို သီးခြား ခွဲခြားထားရတာလဲ ဆိုတဲ့ OT Cybersecurity အကြောင်းအရာတွေကိုတော့ နောက် Post တွေမှာ ဆက်လက် ဝေမျှပေးသွားပါမယ်။


Post a Comment