Cybersecurity Solutions for the Semiconductor Industry: Moving from Default Trust to Zero Trust While Balancing Device Stability
July 20, 2021


Internal Network Security: Easily Overlooked Beneath Layers of Protection

 

 

Modern enterprises place a high priority on external network threats, leveraging hardened firewalls, antivirus software, and other solutions to prevent malicious attacks from infiltrating the corporate network. However, when the aforementioned risk originates from the inside, there is commonly a significant lack of awareness. The internal network possesses several characteristics that give internal threats an inherent advantage that external threats lack:

 

 

・Pre-existing Privileges: In the course of daily corporate operations, internal attackers have already acquired the necessary access permissions.

・Familiarity with Targets and Defenses: Internal attackers know exactly where critical data is stored and are familiar with the defense mechanisms established by the company.

 

 

If an organization faces an inside threat without detection or prevention mechanisms, the resulting damage becomes difficult to control. By establishing a "Zero Trust" cybersecurity management architecture, enterprises can achieve a seamless combined defense across both internal and external networks—meaning that whenever personnel or entities request access to work assets, their trustworthiness must be verified before any access permission is granted.

 

 

Major Cybersecurity Challenges Faced by the Semiconductor Industry

 

 

In response to technological trends such as the Internet of Things (IoT), Big Data, and AI, the government has been actively promoting smart manufacturing. However, this has also brought industrial control system (ICS/OT) cybersecurity threats to the surface. In January 2019, spearheaded by the SEMI Taiwan Technical Committee, the Fab & Equipment Information Security Task Force was officially established with the goal of driving relevant cybersecurity standards. The following lists the common cybersecurity challenges faced by the semiconductor industry:

 

 

 

 

 

Unclear Asset Count and Inability to Track Device Status

 

In today’s network environment, managing terminal devices in the OA (Office Automation) area is no longer enough; IoT devices scattered across various locations—such as surveillance cameras and badge readers—have also become a core focus of cybersecurity management. A common approach to endpoint management is installing an Agent on every machine to monitor device information and operational health.

 

 

However, the majority of IoT devices, BYOD (Bring Your Own Device) equipment, and guest devices cannot easily accommodate Agent installation. This creates a visibility blind spot, leaving organizations unable to effectively track asset attributes or the status of software and hardware across the environment. This not only complicates management but also leaves critical security vulnerabilities within the network environment.

 

 

 

 

Neglecting Guest Management Creates Cybersecurity Vulnerabilities

 

Government agencies accommodate numerous visitors, including foreign guests, citizens on official business, and outsourced contractors. These personnel frequently need network access. If management staff must manually grant access and configure permissions for each individual, it is not only time-consuming and labor-intensive but also fails to perform effective security checks on the connecting devices. Furthermore, network access permissions must be manually revoked once the relevant tasks are completed. Any oversight in these steps can easily introduce security vulnerabilities into the network environment, leading to cybersecurity incidents such as malware infiltration or data theft.

 

 

IPv6 Will Fully Replace IPv4: How Government Agencies Should Respond

 

Government agencies in Taiwan have fully transitioned to IPv6, and the civilian adoption rate of IPv6 has reached 6th place globally. This indicates that the number of users accessing networks via IPv6 will steadily increase over the next few years. In today's coexisting IPv4 and IPv6 environment, how to efficiently manage both protocols simultaneously has become an urgent problem that government agencies must address immediately.

 

 

 

Choosing the Right Cybersecurity Defense Under Legal Regulations

 

Under the "Cyber Security Management Act" and its sub-laws, relevant government agencies must achieve ISO 27001 certification or adopt the NIST CSF within the mandated timeframe. They are also required to implement GCB (Government Configuration Baseline) and review compliance with cyber security system protection baselines. Concurrently, the "Personal Data Protection Act" requires public agencies to adopt appropriate measures to prevent personal data from being stolen, altered, or damaged.

 

 

A stark example occurred in 2019, when the Ministry of Civil Service was infiltrated by a Trojan horse, resulting in the leak of 590,000 civil servants' personal records. The leaked data included the personal information of national security personnel, which not only put these individuals at risk but also posed a severe threat to national security.

 

 

Faced with limited cybersecurity budgets, establishing an Information Security Management System (ISMS) that complies with ISO 27001, or adopting the NIST CSF while simultaneously complying with other statutory regulations, presents a significant challenge for the relevant organizations.

 

 

Reducing Ransomware Incidents Through Internal Network Defense Deployment

 

With the rapid advancement of networking, vast amounts of confidential data are now stored digitally. This has led hackers to seek out vulnerable devices to infiltrate enterprise internal networks. Once inside, they deploy ransomware to encrypt files and block user access, demanding a ransom from victims to restore their files and access privileges.

 

 

 

 

How to Initiate VANS System Implementation to Comply with the Cyber Security Management Act

 

The Vulnerability Alert and Notification System (VANS), developed by the National Center for Cyber Security Technology (NCCST) under the Executive Yuan's National Cyber Security Program, matches software asset reports provided by various government agencies against the National Vulnerability Database (NVD, established by the U.S. National Institute of Standards and Technology - NIST). This process identifies cybersecurity vulnerabilities across agencies and instantly notifies the affected unit, allowing them to patch loopholes and eliminate cybersecurity risks at the earliest opportunity, thereby strengthening software asset management within the public sector.

 

Furthermore, the "Cyber Security Management Act" explicitly mandates the following required actions for government agencies across all levels: Grade A cyber security responsibility agencies must fully implement the VANS system by 2021, with Grade B and Grade C agencies required to follow suit by 2022.

 

 


 

 

UPAS NOC Core Value: A Zero Trust Security Architecture

 

What is "Zero Trust"?

 

All resources are treated as external resources, and continuous verification is performed to establish trust before granting required access privileges. Simply put, it means treating the internal network the same as an external network—shifting from the traditional mindset of "trust but verify" to "verify and never trust."

 

 

Therefore, when any personnel or entity requests access to operational assets, UPAS recommends adopting Zero Trust principles first. You must verify their trustworthiness before granting access permissions. Regarding how enterprises can optimize Zero Trust security, Gartner's 2020 cybersecurity report points out:

 

 

"To reduce cybersecurity risks, modern enterprises must establish a 'Zero Trust Network Architecture,' and to achieve this goal, a comprehensive NAC solution is indispensable." — Market Guide for Network Access Control, Gartner

 

 

By implementing the NAC mechanism, UPAS NOC tackles security starting with device visibility and control. It comprehensively optimizes asset inventory to discover all network-connected devices within the environment and effectively manages user access permissions. Furthermore, it inspects the installation and update status of software (such as antivirus and asset management software) and OS versions on each device to perform vulnerability patching. Finally, it analyzes device information and exports reports to provide continuous tracking and auditing.

 

 

 

UPAS NOC Solution

Effortless Implementation to Perfect Asset Inventory and IP Management Processes

 

 

As public sector services and systems digitalize, the outsourced service supply chain becomes increasingly complex. In the face of dynamic, ever-evolving attack patterns, the fundamental principles of security remain unchanged: basic internal network defense remains an indispensable component, as the ultimate target of attackers still resides within the internal network. Below is our optimized security experience solution addressing the major challenges mentioned above:

 

 

Comprehensive Asset Inventory and Complete Device Status Visibility

 

 

Research indicates that over 90% of IoT devices cannot support agent installations, making traditional device identification technologies difficult to leverage. Utilizing patented ARP technology, UPAS NOC automatically identifies nearly 30 types of connected device attributes in an agentless manner:

 

 

・OA Area: Computer equipment, mobile devices, printers, and IoT devices.

・Server Room Infrastructure: Virtual machines, servers, and other VM or network equipment components.

・Common Network Equipment: Routers, switches, firewalls, wireless access points (APs), and controllers.

 

 

Beyond asset inventory, compiling device metrics presents another major hurdle: tracking OS versions, ensuring antivirus software is up to date, verifying virus definitions, and monitoring software usage. If even one of these components lapses, it can jeopardize the security of the entire network environment.

 

 

UPAS NOC integrates with WSUS servers, various antivirus software, and asset management software databases. Combined with Tableau to generate visualized charts, it renders all device information crystal clear and readily accessible at a glance.

 

 

 

 

 

Automated Management of Guest Personnel Resolves Security Vulnerabilities

 

 

In practical internal network management, scenarios arise where external devices require temporary connection to the internet or specified time-bound access to the internal network, even though these devices do not belong to internal employees. Compared to rigorous and comprehensive external network defenses, guest devices that enter the internal network without being integrated into management and assigned specific access permissions can become high-risk security vulnerabilities. UPAS NOC offers the following solutions for guest personnel:

 

 

・Guest Internal Network Connection Authentication: Supports both on-site and pre-booked application methods. It automates guest identity auditing, grants corresponding permissions, and maintains complete records, thereby reducing the management burden.

 

・Isolating Guests in Specific Network Segments: For guests who require internal network usage, UPAS NOC can segregate a dedicated guest network segment to restrict the data they can access. If a cybersecurity incident occurs within the guest segment, the damage can be contained within that specific segment, minimizing losses.

 

・Restricting Guest Access Permissions and Timeframes: Guests are automatically removed from the whitelist upon expiration. By controlling access permissions and expiration times, organizations can prevent security vulnerabilities caused by forgetting to manually revoke guest privileges.

 

 

 

 

Solve IP Management Challenges Through Comprehensive IPv6 Management

 

Common issues under a dual-stack infrastructure include the coexistence and clutter of IPv4 and IPv6 addresses. IP distribution and network segment management previously conducted using IPv4 must be reconfigured when transitioning to IPv6. Both scenarios create management complexities and increase the burden on relevant personnel. UPAS NOC provides the following IPv6 management functionalities:

 

 

・IPv6 Whitelist Control: Automatically incorporates compliant devices utilizing IPv6 addresses into the system's whitelist, authorizing their internal network access. It can also automatically generate a detailed manifest that explicitly outlines the usage status of each IP address.

 

・Automatic Distribution of IPv6 Addresses Imbued with IPv4 Suffixes: Seamlessly carries over previous network segmentation implementations. It eliminates the need for additional reconfigurations during protocol transition, thereby alleviating the workload of administrative personnel.

 

・Automated Generation of IPv4 to IPv6 Mapping Tables: Within a network environment running a dual-stack infrastructure, UPAS NOC can automatically generate a dual-protocol IP address mapping table, making the two types of IP addresses utilized by each endpoint clear at a single glance.

 

 

 

Assist Government Agencies in Establishing ISMS to Comply with Regulatory Requirements

 

 

・Statutory Compliance Support: Under the mandates of the Cyber Security Management Act, agencies are required to establish an Information Security Management System (ISMS) capable of passing ISO 27001 certification and reviewing cyber security system protection baselines. UPAS NOC satisfies multiple ISO 27001 control objectives and cyber security system protection baseline criteria, reducing the expenditures required to achieve certification.

 

・Streamlined GCB Implementation: The compliant deployment of Government Configuration Baselines (GCB) is often a major headache for administrators. Complex configurations combined with a massive fleet of computer equipment make the deployment process extremely tedious, leading to many potential failure points. UPAS NOC provides robust GPO features that help administrators understand the deployment status of GPOs and GCBs across domain devices, enabling them to pinpoint endpoint devices failing to comply with GCB and GPO baselines.

 

・Real-time Violation Alerts and Comprehensive System Trail Logs: These two features are crucial for personal data protection. When a device performs a violating action (such as cross-VLAN jumping or IP spoofing), real-time alerts can immediately block the violating device's network connectivity the moment the incident occurs, preventing the disaster from expanding. Meanwhile, comprehensive trail logs serve as the most powerful legal evidence after a cybersecurity incident has taken place.

 

・NIST CSF Framework Alignment: The NIST Cybersecurity Framework (CSF) has recently become a highly sought-after cybersecurity architecture. Compared to the tedious establishment and verification processes of ISO 27001, the CSF emphasizes progressive improvements to the cybersecurity system. According to the iThome 2020 Cyber Security Survey, more than 10% of government agencies are willing to implement the CSF framework, indicating that for budget-constrained government agencies, the CSF represents an excellent alternative. UPAS NOC aligns with multiple CSF controls, allowing organizations to flexibly purchase modules based on their specific needs and reduce implementation costs.

 

 

 

 

Constructing an Internal Network Defense Net to Reduce Ransomware Incidents

 

 

Most defense mindsets in the public sector stem from an antivirus perspective, leveraging cybersecurity solutions to intercept ransomware. However, if the installation and update status of this protective software are not closely reviewed, vulnerabilities will emerge in the overall defense effectiveness. Through defensive measures such as asset inventory and compliance inspection, UPAS NOC effectively achieves combined defense across internal and external networks, attaining an asset protection completion rate of over 98%.

 

 

・Asset Inventory: Leverages diverse technologies to identify and bring all network-connected devices in the environment under management, tightly controlling IP connection statuses within the internal network.

 

・Power Status Reports: Evaluates potential vulnerabilities based on device startup and shutdown states. For instance, devices that have not been rebooted for a long time (failing to apply OS Patches, which leaves device vulnerabilities unaddressed) or devices that have not been turned on for a long period (leaving antivirus software and virus definitions outdated).

 

・Device Compliance Inspection: Audits multiple security check items for devices entering the network, such as the installation and update rates of OS versions, antivirus software/virus definitions, and asset management software.

 

・Data Traffic Monitoring: Controls the network usage behavior of endpoint devices. It provides network traffic information and generates relevant bandwidth and traffic reports.

 

・AD Account Management: Records Active Directory (AD) login and logout times to manage idle devices on the internal network or devices utilizing RDP (Remote Desktop Protocol) connections, thereby reducing the opportunities for hacker attacks.

 

・Configuration Behavior Inspection: Provides real-time alerts for abnormal configuration behavior, such as the installation of unauthorized software, modifications to GPO policies, or enabling folder sharing with administrative/maximum privileges.

 

 

 

Analyzing Defense Measures from a Hacker's Mindset—Read More:

Defending Against Ransomware (Part 2): How Does UPAS Stop Ransomware from Causing Harm?

 

 

Highly Adaptive Advanced VANS Implementation Solutions

 

 

Through comprehensive asset inventory, UPAS NOC achieves a software asset inventory coverage rate of over 98%. Tailored to differing customer needs, we provide two distinct VANS system solutions:

 

 


 

 

Scenario A: Third-Party Systems Already Purchased to Assist in VANS Implementation

 

 

No Extra UPAS Agent Installation Required

 

 

If you have already purchased a third-party asset management system and completed the deployment of that vendor's agent—enabling you to convert software assets into CPE formats and upload them to the VANS system—UPAS NOC offers an advanced solution to completely eliminate remaining security vulnerabilities.

 

 

Because the industry average for agent deployment and update rates hovers at only 80%, software asset inventories frequently end up incomplete. This causes critical vulnerabilities to go unnoticed, exposing organizations to high cybersecurity risks. The root cause of these issues lies in the fact that most third-party vendors rely directly on AD servers to push out agents; failures in these push deliveries or inherent device deployment barriers leave such endpoint devices completely uninventoried.

 

 

Utilizing patented ARP packet analysis technology, UPAS NOC dramatically enhances the visibility of devices within the environment, effortlessly inventorying all connected endpoint devices. On this highly visible foundation, the UPAS NOC SIM (Security Integration Module) interfaces directly with your asset management software database. By cross-referencing a comprehensive monitoring list, it seamlessly flags missing or outdated device agents without a single omission. For non-compliant devices, a highly secure network blocking mechanism is used to compel immediate vulnerability patching.

 

 

Our advanced solution ensures that the asset management system brings all endpoint devices under management without requiring the installation of an extra UPAS Agent. It guarantees a thorough software asset inventory for VANS uploads, effectively neutralizing cybersecurity risks through more comprehensive software vulnerability tracking.

 

 

Scenario B: No Third-Party VANS-Capable Systems Purchased Yet

 

 

UPAS Agent Installation Required

 

 

Built upon a foundation of comprehensive endpoint discovery, the UPAS NOC PM (Patch Management) Module goes a step further to inventory all software assets. It automatically generates software master lists in CPE format and enables one-click uploads to VANS, making it easy to meet public sector compliance mandates under the Cyber Security Management Act while ensuring no endpoint software vulnerability is overlooked.

 

 

This module requires the installation of a UPAS Agent on endpoint devices. Beyond assisting public sector units with VANS implementation, it performs a multitude of compliance checks—including tracking endpoint Windows build versions, antivirus statuses, mandatory software, prohibited software, and license counts. Non-compliant devices are then compelled to patch their vulnerabilities via UPAS NOC's access control features.

 

 

 

 

Developing a Defensible Network with Effortless Maintenance and Management

 

 

To achieve its ideal outcomes, a network security architecture must undergo ongoing deployment, management, and maintenance processes involving users across multiple dimensions. Therefore, "enforcing security" should never be a one-sided, unidirectional mandate. If maintaining the ideal state of a security policy requires various users to constantly stay tense while running complex, tedious workflows, it will eventually become a hidden liability within the defense network itself.

 

 

 

 

UPAS NOC has never stopped optimizing the security experience. Our core advantage lies in deploying a high-coverage defense network without requiring agent installations, thereby enhancing visibility and effectively applying management policies. Our non-802.1X technology provides exceptional adaptability and simplicity, eliminating the risks and administrative pressure associated with reconfiguring network environments or upgrading software and hardware.

 

 

Click to download UPAS NOC Public Sector Industry Solution

Please contact us to receive the most suitable industry solution and consultation for your needs.

 

BACK TO LIST