Ingress network connections
In this section, we will be looking at ingress network connections. Ingress network connections are network connections coming into the industrial zone from outside of the industrial zone, such as the enterprise zone or the internet. Ingress connections into the industrial network should be closely monitored and scrutinized for malicious activities or suspicious characteristics such as questionable source IP addresses, unusual services, or the use of unusual ports for the communication protocols used in connections.
Mayhem from the internet
A type of ingress connection that should be downright blocked is connections directly from the internet. In no situation is it advisable to have a public system directly connect to a system on the industrial network. Furthermore, seeing connections that originate from the internet and going into the ICS environment should be considered malicious.
We should start our threat hunting investigations by looking into...