The edge devices for the smart grid are distributed worldwide and controlled centrally by the vendor. Due to the evolving risk landscape for IIoT devices, the vendor integrated the security monitoring solution Rhebo IIoT Security with anomaly detection as agents on the edge devices. These agents monitor communication and processes on the edge devices locally and report anomalies in real time.
The agent also detects processes that indicate malfunctions or technical errors on the edge devices. During the monitoring, the Rhebo team noticed unusual behavior patterns in a regionally limited cluster of the tens of thousands of monitored smart grid edge devices. The security monitoring agent was repeatedly restarted at an unusually high frequency.
Endpoint Detection & Response
Containerized IIoT security monitoring
The operation of the security monitoring of Rhebo IIoT Security is provided as a managed service by the Rhebo support team. During the evaluation of various metrics, Rhebo noticed that the security monitoring agents on several dozen edge devices in the fleet were repeatedly restarting.
Together with the vendor, the specific devices were examined via the control platform of the edge devices. As it turned out, the trigger for the monitoring agent restarts was that the edge devices themselves were repeatedly restarted. As a result, the devices were not optimally available and usable for customers of the smart grid. These restarts weren't detected before on the control platform itself due to specific metric settings and a fleet of several tens of thousands of devices. They were lost in the noise.
Thanks to the security monitoring, the malfunctioning devices were detected and localized quickly. The vendor was able to examine the devices in a targeted manner and eliminate the error.
through continuous monitoring of the device communication.
through agent-based deployment directly on the edge devices.
with security monitoring as managed services by Rhebo.